Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PAM Audit System error is still an open issue #564

Closed
uCatu opened this issue Aug 30, 2020 · 2 comments
Closed

PAM Audit System error is still an open issue #564

uCatu opened this issue Aug 30, 2020 · 2 comments

Comments

@uCatu
Copy link

uCatu commented Aug 30, 2020

Using version v0.11 released on Aug 16, 2018, when deployed on OCP recieving following errors for any user manipulation command - for example su

su 432891 - [meta sequenceId="7"] PAM audit_log_acct_message() failed: Operation not permitted
su 432891 - [meta sequenceId="8"] pam_authenticate: System error

The issue was fixed at Jul 8, 2016, but than removed aug 1, 2017 v0.10.0 after wrong conclusion that it's not needed (see changelog: Evaluate if fix_pam_bug is still needed #404)

The workaround of rebuilding PAM with audit disabled is working for me - but it's too heavy and not clean / secured enough.

Another workaround is to use, setuser instead of su in my code - but it doesn't solve 3rd party code like syslog, stats & cron the relies heavily on su

@samip5 samip5 added the defect label Sep 2, 2021
@github-actions
Copy link

This Issue has been automatically marked as "stale" because it has not had recent activity (for 15 days). It will be closed if no further activity occurs. Thanks for the feedback.

@github-actions github-actions bot added the Stale label Sep 18, 2021
@github-actions
Copy link

Due to the lack of activity in the last 5 days since it was marked as "stale", we proceed to close this Issue. Do not hesitate to reopen it later if necessary.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants