<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SU / logging in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774972#M262005</link>
    <description>Welcome to the wonderful world of account access logging. It's a mess. As you've discovered, su logins are not recorded in wtmp so will not show up in last's output. The only place such logins are recorded in sulog and/or syslog, depending on the configuration.</description>
    <pubDate>Thu, 20 Apr 2006 12:23:02 GMT</pubDate>
    <dc:creator>Jeff_Traigle</dc:creator>
    <dc:date>2006-04-20T12:23:02Z</dc:date>
    <item>
      <title>SU / logging</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774970#M262003</link>
      <description>When a user logs in as themselves, that is a personal user account, we make them 'su' to oracle or other special user accounts. Problem is , when they su to oracle or other accounts, they end up getting reported as a dormant account because they have not logged onto the system in 'x' amount of days. Anyone know why this is happening? The audit keeps hitting oracle and other accounts as 'dormant'.&lt;BR /&gt;&lt;BR /&gt;Do accounts not show up in the last log if they are initiated by 'su' ???</description>
      <pubDate>Thu, 20 Apr 2006 12:13:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774970#M262003</guid>
      <dc:creator>Nobody's Hero</dc:creator>
      <dc:date>2006-04-20T12:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: SU / logging</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774971#M262004</link>
      <description>Hi Robert:&lt;BR /&gt;&lt;BR /&gt;No, 'su' activity is not logged in '/var/adm/wtmp'.  Rather, the switch is shown in '/var/adm/sulog'.  This makes "sense" since to perform a (s)witch-(u)ser you must already be logged on.&lt;BR /&gt;&lt;BR /&gt;You can tell the success (+) or failure (-) from the 'sulog' with the positive/negative notation recorded for the action.&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Thu, 20 Apr 2006 12:19:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774971#M262004</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2006-04-20T12:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: SU / logging</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774972#M262005</link>
      <description>Welcome to the wonderful world of account access logging. It's a mess. As you've discovered, su logins are not recorded in wtmp so will not show up in last's output. The only place such logins are recorded in sulog and/or syslog, depending on the configuration.</description>
      <pubDate>Thu, 20 Apr 2006 12:23:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774972#M262005</guid>
      <dc:creator>Jeff_Traigle</dc:creator>
      <dc:date>2006-04-20T12:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: SU / logging</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774973#M262006</link>
      <description>Shalom Robert,&lt;BR /&gt;&lt;BR /&gt;Seems reasonable that with last -R output and the sulog you can write a short awk script and have a very good idea what is going on.&lt;BR /&gt;&lt;BR /&gt;oracle and other accounts may be dormant if the dba's never log on. Your startup scripts will only leave evidence in the sulog.&lt;BR /&gt;&lt;BR /&gt;su - oracle -c &lt;STARTUP script=""&gt;&lt;/STARTUP&gt;run by root. Did Orale log in? not as afar as wtmp is concerned.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 20 Apr 2006 13:16:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774973#M262006</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-04-20T13:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: SU / logging</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774974#M262007</link>
      <description>If this is a trusted system it might be better to write a script to run through the users doing a getprpw on each user.  The slogint field will reflect a sucessful login date event for a su.  Of course, this means that root has to be the one to be getting the login dates for the auditors, but at least this can refute the "dormant account" claim.</description>
      <pubDate>Fri, 21 Apr 2006 05:36:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-logging/m-p/3774974#M262007</guid>
      <dc:creator>Tom Henning</dc:creator>
      <dc:date>2006-04-21T05:36:47Z</dc:date>
    </item>
  </channel>
</rss>

