From e31dd6c7d0faa7a06d3ebd50a0b6957b9f822d15 Mon Sep 17 00:00:00 2001 From: Tomas Mraz Date: Wed, 7 Aug 2019 18:13:57 +0200 Subject: pam_tty_audit: Manual page clarification about password logging * modules/pam_tty_audit/pam_tty_audit.8.xml: Explanation why passwords can be sometimes logged even when the option is not set. --- modules/pam_tty_audit/pam_tty_audit.8.xml | 7 +++++++ 1 file changed, 7 insertions(+) (limited to 'modules/pam_tty_audit/pam_tty_audit.8.xml') diff --git a/modules/pam_tty_audit/pam_tty_audit.8.xml b/modules/pam_tty_audit/pam_tty_audit.8.xml index 59a3406d..e346c689 100644 --- a/modules/pam_tty_audit/pam_tty_audit.8.xml +++ b/modules/pam_tty_audit/pam_tty_audit.8.xml @@ -149,6 +149,13 @@ greater than or equal to min_uid will be matched. + + Please note that passwords in some circumstances may be logged by TTY auditing + even if the is not used. For example, all input to + an ssh session will be logged - even if there is a password being typed into + some software running at the remote host because only the local TTY state + affects the local TTY auditing. + -- cgit v1.2.3