Jamie L. Penman-Smithson
2005-Jul-17 13:00 UTC
[Logcheck-devel] Bug#318500: logcheck-database: rules for openssh-krb5
On Fri, 2005-07-15 at 14:02 -0700, Russ Allbery wrote:> For support of openssh-krb5, please add the following rule to > rulefiles/linux/ignore.d.server/ssh: > > ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ sshd\[[0-9]+\]: Authorized to [^[:space:]]+, krb5 principal [^[:space:]]+ \(krb5_kuserok\)$ > > and add gssapi-with-mic to the list of authentication alternatives in > the first rule in that file. Thanks!Could you provide the log messages that this matches? Thanks, -j -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: This is a digitally signed message part Url : http://lists.alioth.debian.org/pipermail/logcheck-devel/attachments/20050717/037d2324/attachment.pgp
Russ Allbery
2005-Jul-17 17:34 UTC
[Logcheck-devel] Bug#318500: logcheck-database: rules for openssh-krb5
Jamie L Penman-Smithson <jamie at silverdream.org> writes:> On Fri, 2005-07-15 at 14:02 -0700, Russ Allbery wrote:>> For support of openssh-krb5, please add the following rule to >> rulefiles/linux/ignore.d.server/ssh: >> >> ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ sshd\[[0-9]+\]: Authorized to [^[:space:]]+, krb5 principal [^[:space:]]+ \(krb5_kuserok\)$ >> >> and add gssapi-with-mic to the list of authentication alternatives in >> the first rule in that file. Thanks!> Could you provide the log messages that this matches?Sure thing. System Events =-=-=-=-=-=-Jul 16 12:00:02 lothlorien sshd[7653]: Authorized to eagle, krb5 principal rra at stanford.edu (krb5_kuserok) Jul 16 12:00:02 lothlorien sshd[7653]: Accepted gssapi-with-mic for eagle from 171.64.19.147 port 48828 ssh2 -- Russ Allbery (rra at stanford.edu) <http://www.eyrie.org/~eagle/>
Jamie L. Penman-Smithson
2005-Jul-17 19:11 UTC
[Logcheck-devel] Bug#318500: logcheck-database: rules for openssh-krb5
package logcheck-database tags 318500 pending thanks On Fri, 2005-07-15 at 14:02 -0700, Russ Allbery wrote:> For support of openssh-krb5, please add the following rule to > rulefiles/linux/ignore.d.server/ssh: > > ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ sshd\[[0-9]+\]: Authorized to [^[:space:]]+, krb5 principal [^[:space:]]+ \(krb5_kuserok\)$ > > and add gssapi-with-mic to the list of authentication alternatives in > the first rule in that file. Thanks!I've made these changes in CVS, they'll be in the next release. Thanks for your bug report, -j -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: This is a digitally signed message part Url : http://lists.alioth.debian.org/pipermail/logcheck-devel/attachments/20050717/afe63c4e/attachment.pgp
Debian Bug Tracking System
2005-Jul-18 10:44 UTC
[Logcheck-devel] Processed: Re: Bug#318500: logcheck-database: rules for openssh-krb5
Processing commands for control at bugs.debian.org:> package logcheck-databaseIgnoring bugs not assigned to: logcheck-database> tags 318500 pendingBug#318500: logcheck-database: rules for openssh-krb5 Tags were: patch Tags added: pending> thanksStopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrator, Debian Bugs database)