sshd time in /var/log/secure

Richard Mayhew RichardM at nashuamobile.com
Tue Apr 3 14:38:45 UTC 2007


_________________________________________________________________

Nashua Mobile (PTY) LTD Electronic Mail Notice: Click Here 
or send an email to emailnotice at nashuamobile.com
_________________________________________________________________
Hi,

I can back you up on that, I'm receiving the same double entries in my
secure log file on each SSHD login.

Regards
Richard

-----Original Message-----
From: redhat-sysadmin-list-bounces at redhat.com
[mailto:redhat-sysadmin-list-bounces at redhat.com] On Behalf Of Richard
Riley
Sent: 03 April 2007 05:48 AM
To: redhat-sysadmin-list at redhat.com
Subject: sshd time in /var/log/secure

It appears that since I updated my machines with the new tzdata, ssh
logins are logged with two entries in the /var/log/secure file.  One
appears to be UTC while the other is correct local time.  This is
consistent with both RHEL ES3 and ES4.  I have applied subsequent tzdata
and openssh updates and rebooted the machines and still get the double
entries.  I can find no instances in any other log files.

Mar  6 16:11:08 admin4 sshd[16822]: Accepted password for rriley from
::ffff:172.29.1.193 port 1557 ssh2
Mar  6 11:11:08 admin4 sshd[16821]: Accepted password for rriley from
::ffff:172.29.1.193 port 1557 ssh2

Mar  6 17:12:15 admin4 sshd[21665]: Accepted password for rriley from
::ffff:172.29.1.196 port 4418 ssh2
Mar  6 12:12:15 admin4 sshd[21664]: Accepted password for rriley from
::ffff:172.29.1.196 port 4418 ssh2

Apr  3 03:24:42 admin4 sshd[12422]: Accepted password for rriley from
172.30.3.131 port 3502 ssh2
Apr  2 23:24:42 admin4 sshd[12421]: Accepted password for rriley from
172.30.3.131 port 3502 ssh2


Richard Riley
IT System Administrator



--
redhat-sysadmin-list mailing list
redhat-sysadmin-list at redhat.com
https://www.redhat.com/mailman/listinfo/redhat-sysadmin-list




More information about the redhat-sysadmin-list mailing list