From HP-UX 11.31 Security Technical Implementation Guide
Part of GEN004460
Associated with IA controls: ECSC-1
Associated with: CCI-000126
If informational and more severe SMTP service messages are not logged, malicious activity on the system may go unnoticed.
The syslog.conf file critical mail logging option line will typically appear as one of the following examples: mail.crit /var/adm/messages mail.* /var/adm/messages *.* /var/adm/messages *.crit /var/adm/messages Check the syslog configuration file for mail.crit logging configuration. # cat /etc/syslog.conf | tr '\011' ' ' | tr -s ' ' | sed -e 's/^[ \t]*//' | grep -v "^#" | egrep -i "mail.crit|mail.\*|\*.crit|\*.\*" If syslog is not configured to log critical sendmail messages, this is a finding.
Edit the syslog.conf file and add a configuration line specifying an appropriate destination for critical "mail" syslogs, for example: mail.crit /var/adm/messages mail.* /var/adm/messages *.* /var/adm/messages *.crit /var/adm/messages
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer