suex
suex copied to clipboard
Auditing is missing
suex
is missing an audit feature that'll give sysadmins insights into suex
usage.
For example:
- User was denied execution
- User tried to run a specific command many times during a specific timeframe
- User edited the configuration file
I believe that this information can be sent using rsyslog
.
Things to point out:
- This file can be read by anyone, but only the root user can edit it
- Default configuration is important in this case