Re: src/etc/periodic/security/800.loginfail

From: Dmitry Pryanishnikov <dmitry_at_atlantis.dp.ua>
Date: Fri, 17 Mar 2006 03:07:54 +0200 (EET)
Hello!

On Thu, 16 Mar 2006, Garance A Drosehn wrote:
> But that's the problem, once you start down the road of
> matching "everything which might be useful", you open up
> a lot of questions as to which messages *are* interesting,
> and how they should be displayed in the security-email
> message.  After all, *everything* in the authlog file is
> expected to be interesting in one way or another.  Do we
> want to copy the entire file into the security email?  I
> doubt it...

  I understand current intent as "to report login failures",
and I think that refused by the sshd connection attempts
could be treated as such. OTOH, SSH.COM's sshd2 isn't the part
of the base OS, that's why I'm not sure whether such an addition
is "politically correct" (I'm sure it's useful though).

Sincerely, Dmitry
-- 
Atlantis ISP, System Administrator
e-mail:  dmitry_at_atlantis.dp.ua
nic-hdl: LYNX-RIPE
Received on Fri Mar 17 2006 - 00:07:57 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:38:53 UTC