Hi
The auditd rules for PCI reads :
## 10.2.2 Log administrative action. To meet this, you need to enable tty
## logging. The pam config below should be placed into su and sudo pam stacks.
## session required pam_tty_audit.so disable=* enable=root
I have noticed that nothing happened unless I add in /etc/pam.d/sshd
session required pam_tty_audit.so enable=*
At which point I get
Should it be done that way ?
Did I miss something ?
Philippe