GEN003660 - The system must log authentication informational data - 'auth.*'

Information

Monitoring and recording successful and unsuccessful logins assists in tracking unauthorized access to the system.

Solution

Edit /etc/syslog.conf and add local log destinations for auth.* or both auth.notice and auth.info.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2d., CAT|II, CCI|CCI-000126, Rule-ID|SV-12505r2_rule, STIG-ID|GEN003660, Vuln-ID|V-12004

Plugin: Unix

Control ID: 0a076459f30c832b110306325448ddbe5de14e112363f81d757b65a4bf1d08d5