GEN003660 - The system must log authentication informational data - syslog authpriv.*

Information

Monitoring and recording successful and unsuccessful logins assists in tracking unauthorized access to the system.

Solution

Edit /etc/syslog.conf or /etc/rsyslog.conf and add local log destinations for 'authpriv.*', 'authpriv.debug' or 'authpriv.info'.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2d., CAT|II, CCI|CCI-000126, Group-ID|V-12004, Rule-ID|SV-37404r2_rule, STIG-ID|GEN003660, Vuln-ID|V-12004

Plugin: Unix

Control ID: d35150ed2499b2fa4136af5cc05b62e4ccbd090f44bc3820f9451580eb27f41a