Hi,
The examples found in the audit documentation mention that to work it is assumed that no direct root login is allowed.
This very sensible and not a big problem except for console access.
What would be the best way to monitor what is done through this access ?
Would you recommend to forbid root access even in console ?
Philippe