On Thursday, July 8, 2021 6:53:12 PM EDT warron.french wrote: > Please, can you tell me what audit rule you are using that generates such > records about root's (*or any other account's) password change?* In this case its hardwired into pam. -Stev