From Canonical Ubuntu 16.04 Security Technical Implementation Guide
Part of SRG-OS-000032-GPOS-00013
Associated with: CCI-000067
Remote access services, such as those providing remote access to network devices and information systems, which lack automated monitoring capabilities, increase risk and make remote user access management difficult at best.
Verify that the Ubuntu operating system monitors all remote access methods. Check that remote access methods are being logged by running the following command: # grep -E '(auth.*|authpriv.*|daemon.*)' /etc/rsyslog.d/50-default.conf auth,authpriv.* /var/log/auth.log daemon.notice /var/log/messages If "auth.*", "authpriv.*" or "daemon.*" are not configured to be logged, this is a finding.
Configure the Ubuntu operating system to monitor all remote access methods by adding the following lines to the "/etc/rsyslog.d/50-default.conf" file: auth.*,authpriv.* /var/log/secure daemon.notice /var/log/messages The "rsyslog" service must be restarted for the changes to take effect. To restart the "rsyslog" service, run the following command: # sudo systemctl restart rsyslog.service
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer