SV-226480r603265_rule
V-226480
SRG-OS-000062
GEN001060
CAT II
10
Update /etc/default/su and set SYSLOG=YES.
Ensure /etc/syslog.conf is configured to log auth.crit messages to capture all failed su attempts.
Check the following log files to determine if access to the root account is being logged. Try to su - and enter an incorrect password.
# more /var/adm/sulog
If root login accounts are not being logged, this is a finding.
V-226480
False
GEN001060
Check the following log files to determine if access to the root account is being logged. Try to su - and enter an incorrect password.
# more /var/adm/sulog
If root login accounts are not being logged, this is a finding.
M
4060