Managing Auditing
The following sections describe the SSH server auditing functions and the configuration parameters that you can use to modify SSH auditing functions. For more information about the configuration parameters, see Appendix B. When auditing is enabled for the specified authentication method, the SSH server performs the following functions depending on the type of login and whether the login attempt is successful. When an interactive login is successful:
When a remote command execution is successful, no updates are made to the user's SYSUAF record; thus:
If the user's password has expired but the user is not forced to change it before logging in, a warning message is displayed and the pwd_expired flag in the user's SYSUAF record is not set. When the login or remote command execution fails:
You can include the following options in the server configuration file (TCPIP$SSHD_CONFIG.) to control auditing functions.
You can include the following options in the client configuration file (TCPIP$SSH_CONFIG.) to control auditing functions.
The configuration parameters are described in Appendix B. |