-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
sid 5300 incorrectly alerts on OS X #604
Comments
Can you provide a log sample? |
Sure. su[734]: in pam_sm_authenticate(): authentication succeeded Which in turn generates the following alert: Rule: 5301 fired (level 5) -> "User missed the password to change UID (user id)." Apr 30 11:19:09 test-mac su[734]: in pam_sm_acct_mgmt(): OpenDirectory - Membership cache TTL set to 1800. |
…elated OS X log messages. I don't see a log sample that this might be correctly used for, so remove it.
Thanks for the correction. I was hesitant to submit a pull request in case "-" was alerting for logs on older systems. |
It could be, but I don't have any evidence that it does. I can only work On Fri, May 8, 2015 at 12:04 PM, Mike Downey [email protected]
|
I've noticed sid 5300 alerting for successful authentication when the "Open Directory - Membership cache TTL..." log is generated. This is being triggered due to " - " being matched in the rule.
The text was updated successfully, but these errors were encountered: