Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


RHEL su logging

Posted on 2013-01-24
Medium Priority
Last Modified: 2013-02-01
My system has RHEL 3,4,5. If 2 users su to another account at the same time, how do I log activities of each user after su? Does audit.log log this scenario? This is needed to provide traceability and accountability for the system security.
Question by:Elyutah
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
LVL 31

Expert Comment

ID: 38816493
Check the log


Users should use sudo to su to other users.  Sudo keeps logs for any  commands issued.  However for RHEL3 sudo is too old and will not log very well.

Author Comment

ID: 38816552
/var/log/secure only logs when the users su to another account, but not commands issued by them after they become another user.

Author Comment

ID: 38816602
The problem with using sudo su is that X11 being disabled. The users need to bring up a GUI to run the system.
Docker-Compose to Simplify Multi-Container Builds

Our veteran DevOps Author takes you through how to build a multi-container environment, managed with a single utility in order to simplify your deployments.

LVL 31

Expert Comment

ID: 38816862
GUI control will be based on your desktop.  What kind of desktop do you have?

Sudo will still work really good with GUI.  You said the users need to execute commands, they don't need to get to the GUI of other users.  In their GUI command prompt, they can still issue commands using sudo for some other user.  They do not need to login as another user.  All the commands will thus be logged.  Making sense?
LVL 79

Expert Comment

ID: 38817507
What reason would an Admin need to run commands as another user (presumably not elevated rights)?
Could you provide the scenario you are dealing with?

how is the user who will be running those commands interfaces with the system?
i.e. the user using GUI to login, then opens a terminal/xterm window
runs sudo/su and then would like a graphical command sent back to the desktop?
You could use xhost + or set DISPLAY to redirect the SUDO/SU GUI back to the desktop
export DISPLAY=localhost:0.0

Author Comment

ID: 38828561
Here is the scenario: the original system used a group account (ga) who a matlab license is granted. We are required to eliminate the ga by implementing individual user accounts. However, the matlab license is not going to be updated until later. In the mean time, the users need to switch to the ga and bring up a console GUI to run tasks required matlab.  We are approved to use 'su' but need to provide traceability. Other tasks can be done within the individual user accounts.
LVL 79

Accepted Solution

arnold earned 1500 total points
ID: 38829471
Sudo is the tool to use with those users only have su - ga as the only permitted command
Run this command from an xterm and it should preserve the DISPAY .

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I am a long time windows user and for me it is normal to have spaces in directory and file names. Changing to Linux I found myself frustrated when I moved my windows data over to my new Linux computer. The problem occurs when at the command line.…
Introduction We as admins face situation where we need to redirect websites to another. This may be required as a part of an upgrade keeping the old URL but website should be served from new URL. This document would brief you on different ways ca…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question