Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 161230 - gdm create spurious audit entries
Summary: gdm create spurious audit entries
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 4
Classification: Red Hat
Component: gdm
Version: 4.0
Hardware: All
OS: Linux
high
medium
Target Milestone: ---
: ---
Assignee: Ray Strode [halfline]
QA Contact: Mike McLean
URL:
Whiteboard:
Depends On:
Blocks: 156322 159338
TreeView+ depends on / blocked
 
Reported: 2005-06-21 15:48 UTC by Steve Grubb
Modified: 2007-11-30 22:07 UTC (History)
1 user (show)

Fixed In Version: RHBA-2005-644
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2005-10-05 15:32:59 UTC


Attachments (Terms of Use)
Proposed patch (deleted)
2005-06-21 16:53 UTC, Tomas Mraz
no flags Details | Diff


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2005:644 qe-ready SHIPPED_LIVE gdm bug fix update 2005-10-05 04:00:00 UTC

Description Steve Grubb 2005-06-21 15:48:59 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.8) Gecko/20050513 Fedora/1.0.4-1.3.1 Firefox/1.0.4

Description of problem:
Testing has shown that there is a spurious audit message being generated by gdm:

type=USER_ERR msg=audit(06/21/05 09:44:32.699:783952) : user pid=2155 uid=root 
auid=unknown(4294967295) msg='PAM bad_ident: user=? exe="/usr/bin/gdm-binary" (hostname=?, addr=?, terminal=? result=User not known to the underlying authentication module)'

This causes the audit system to log what could be interpretted as "suspicious" events.


Version-Release number of selected component (if applicable):


How reproducible:
Always

Steps to Reproduce:
1. install audit package
2. reboot into run level 5
3. ausearch -i -x gdm
  

Actual Results:  Among other things you will find a USER_ERR message with no PAM_USER.

Additional info:

Comment 1 Tomas Mraz 2005-06-21 16:53:00 UTC
Created attachment 115763 [details]
Proposed patch

This patch simply disables the checking call to pam which is not necessary when
gdm is part of the distribution and not manually installed from sources by
user.

Comment 6 Red Hat Bugzilla 2005-10-05 15:32:59 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2005-644.html



Note You need to log in before you can comment on or make changes to this bug.