Somewhat OT: Is Full Command Logging Possible?

Paul Schmehl pschmehl_lists at tx.rr.com
Thu Dec 6 20:20:23 UTC 2012


--On December 6, 2012 1:19:00 PM -0600 Tim Daneliuk <tundra at tundraware.com> 
wrote:
>
> I understand this.  Even the organization in question understands
> this.  They are not trying to *prevent* any kind of access.  All
> they're trying to do *log* it.  Why?  To meet some obscure
> compliance requirement they have to adhere to in order to
> remain in business.
>
> <rant>
> I know all of this is silly but that's our future when you
> let Our Fine Government regulate pretty much anything.
> </rant>
>

I sent this last night, but for some reason it never showed up.

/usr/ports/security/sudoscript

I believe this will meet your requirements.

-- 
Paul Schmehl, Senior Infosec Analyst
As if it wasn't already obvious, my opinions
are my own and not those of my employer.
*******************************************
"It is as useless to argue with those who have
renounced the use of reason as to administer
medication to the dead." Thomas Jefferson
"There are some ideas so wrong that only a very
intelligent person could believe in them." George Orwell



More information about the freebsd-questions mailing list