[Pkg-shadow-devel] Bug#192849: marked as done ([ALEXANDER] login: failed logins are not being reported)

Debian Bug Tracking System owner@bugs.debian.org
Tue, 05 Jul 2005 16:48:44 -0700


Your message dated Tue, 05 Jul 2005 16:02:31 -0400
with message-id <E1Dptcl-00069U-00@newraff.debian.org>
and subject line Bug#192849: fixed in shadow 1:4.0.3-36
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 10 May 2003 23:52:18 +0000
>From jeff@bsrd.net Sat May 10 18:52:16 2003
Return-path: <jeff@bsrd.net>
Received: from (l1.bsrd.net) [66.153.99.12] (qmailr)
	by master.debian.org with smtp (Exim 3.12 1 (Debian))
	id 19Ee8V-0005DM-00; Sat, 10 May 2003 18:52:15 -0500
Received: (qmail 27314 invoked by uid 1001); 10 May 2003 23:52:11 -0000
Message-ID: <20030510235211.27313.qmail@l1.bsrd.net>
From: Jeff Sheinberg <jeff@bsrd.net>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: login: failed logins are not being reported
X-Mailer: reportbug 1.50
Date: Sat, 10 May 2003 19:52:11 -0400
X-Debbugs-CC: Jeff Sheinberg <jeff@bsrd.net>
Delivered-To: submit@bugs.debian.org
X-Spam-Status: No, hits=-14.8 required=4.0
	tests=BAYES_01,HAS_PACKAGE,SIGNATURE_LONG_SPARSE,X_DEBBUGS_CC
	autolearn=ham version=2.53-bugs.debian.org_2003_05_09
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 2.53-bugs.debian.org_2003_05_09 (1.174.2.15-2003-03-30-exp)

Package: login
Version: 1:4.0.3-8
Severity: normal
Tags: security

Hi,

I have noticed that since about 1 - 2 months, login no longer
reports failed logins when one logs in.

It seems that login is no longer entering failed logins into the
/var/log/faillog file, however, it appears that /var/log/bmtp *is*
being maintained corrrectly.

Here is some information about the state of my system,

    $ faillog -u jss

    $ lastb jss
    jss                                    Sat May 10 08:15 - 08:15  (00:00)

    btmp begins Fri May  9 08:07:11 2003

    $ ls -l /var/log/faillog* /var/log/btmp*
    -rw-rw-r--    1 root     utmp          768 May 10 08:15 /var/log/btmp
    -rw-rw-r--    1 root     utmp          384 Apr  1 13:49 /var/log/btmp.1
    -rw-r-----    1 root     adm             0 May  4 14:23 /var/log/faillog
    -rw-r-----    1 root     adm          2424 Apr  1 17:00 /var/log/faillog.1

    $ grep -i fail -C 3 /etc/login.defs
    #MAIL_FILE      .mail

    #
    # Delay in seconds before being allowed another attempt after a login failure
    #
    FAIL_DELAY              3

    #
    # Enable logging and display of /var/log/faillog login failure info.
    #
    FAILLOG_ENAB            yes

    #
    # Enable display of unknown usernames when login failures are recorded.
    #
    LOG_UNKFAIL_ENAB        no

    #
    # Enable logging of successful logins
    --
    #TTYTYPE_FILE   /etc/ttytype

    #
    # If defined, login failures will be logged here in a utmp format.
    # last, when invoked as lastb, will read /var/log/btmp, so...
    #
    FTMP_FILE       /var/log/btmp

    $ rcsdiff -b -d -p -t -u -r1.1 /etc/login.defs
    ===================================================================
    RCS file: /etc/RCS/login.defs,v
    retrieving revision 1.1
    diff -b -d -p -t -u -r1.1 /etc/login.defs
    --- /etc/login.defs     2003-03-09 17:38:54-05  1.1
    +++ /etc/login.defs     2002-08-11 20:23:00-04
    @@ -56,7 +56,7 @@ LOG_UNKFAIL_ENAB      no
     #
     # Enable logging of successful logins
     #
    -LOG_OK_LOGINS           no
    +LOG_OK_LOGINS           yes

     #
     # Enable setting of ulimit, umask, and niceness from passwd gecos field.
    @@ -73,7 +73,7 @@ SYSLOG_SG_ENAB                yes
     #
     # If defined, all su activity is logged to this file.
     #
    -#SULOG_FILE     /var/log/sulog
    +SULOG_FILE      /var/log/sulog

     #
     # If defined, file which maps tty line to TERM environment parameter.
    @@ -132,7 +132,7 @@ ENV_HZ              HZ=100
     #
     # (they are minimal, add the rest in the shell startup files)
     ENV_SUPATH      PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/bin/X11:/usr/local/sbin:/usr/local/bin
    -ENV_PATH        PATH=/usr/local/bin:/usr/bin:/bin:/usr/bin/X11:/usr/games
    +ENV_PATH        PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/bin/X11:/usr/games

     #
     # Terminal permissions

     
Thanks,
-- 
Jeff Sheinberg



-- System Information

Debian Release: testing/sarge
Architecture: i386
Kernel: Linux l1.bsrd.net 2.4.19-1 #1 Sat Aug 24 17:01:11 EDT 2002 i586
Locale: LANG=C, LC_CTYPE=C

Versions of packages login depends on:
ii  libc6                         2.3.1-16   GNU C Library: Shared libraries an
ii  libpam-modules                0.76-9     Pluggable Authentication Modules f
ii  libpam0g                      0.76-9     Pluggable Authentication Modules l




---------------------------------------
Received: (at 192849-close) by bugs.debian.org; 5 Jul 2005 20:09:33 +0000
>From katie@ftp-master.debian.org Tue Jul 05 13:09:33 2005
Return-path: <katie@ftp-master.debian.org>
Received: from newraff.debian.org [208.185.25.31] (mail)
	by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 1DptjY-0003Cq-00; Tue, 05 Jul 2005 13:09:33 -0700
Received: from katie by newraff.debian.org with local (Exim 3.35 1 (Debian))
	id 1Dptcl-00069U-00; Tue, 05 Jul 2005 16:02:31 -0400
From: Christian Perrier <bubulle@debian.org>
To: 192849-close@bugs.debian.org
X-Katie: $Revision: 1.56 $
Subject: Bug#192849: fixed in shadow 1:4.0.3-36
Message-Id: <E1Dptcl-00069U-00@newraff.debian.org>
Sender: Archive Administrator <katie@ftp-master.debian.org>
Date: Tue, 05 Jul 2005 16:02:31 -0400
Delivered-To: 192849-close@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER 
	autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 
X-CrossAssassin-Score: 2

Source: shadow
Source-Version: 1:4.0.3-36

We believe that the bug you reported is fixed in the latest version of
shadow, which is due to be installed in the Debian FTP archive:

login_4.0.3-36_i386.deb
  to pool/main/s/shadow/login_4.0.3-36_i386.deb
passwd_4.0.3-36_i386.deb
  to pool/main/s/shadow/passwd_4.0.3-36_i386.deb
shadow_4.0.3-36.diff.gz
  to pool/main/s/shadow/shadow_4.0.3-36.diff.gz
shadow_4.0.3-36.dsc
  to pool/main/s/shadow/shadow_4.0.3-36.dsc



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 192849@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christian Perrier <bubulle@debian.org> (supplier of updated shadow package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Mon, 20 Jun 2005 23:37:56 +0300
Source: shadow
Binary: login passwd
Architecture: source i386
Version: 1:4.0.3-36
Distribution: unstable
Urgency: low
Maintainer: Shadow package maintainers <pkg-shadow-devel@lists.alioth.debian.org>
Changed-By: Christian Perrier <bubulle@debian.org>
Description: 
 login      - system login tools
 passwd     - change and administer password and group data
Closes: 75181 78961 87301 109279 192849 219321 244754 245332 248150 256732 261490 266281 269583 276419 286258 286616 287410 288106 288827 290842 298060 298773 304350 309408 312428 312429 312430 312431 312471 314303 314407 314423 314539 314727 315362 315372 315375 315378 315391 315407 315426 315429 315434 315483 315567 315727 315767 315783 315809 315812 315840 315972 316026
Changes: 
 shadow (1:4.0.3-36) unstable; urgency=low
 .
   * Debian specific programs fixes:
     - Re-enable logging and displaying failures on login when login is
       compiled with PAM and when FAILLOG_ENAB is set to yes. And create the
       faillog file if it does not exist on postinst (as on Woody).
       Closes: #192849
     - do not localize login's syslog messages.
   * Debian packaging fixes:
     - Fix FTBFS with new dpkg 1.13 and use a correct dpkg-architecture
       invocation. Closes: #314407
     - Add a comment about potential sensitive information exposure
       when LOG_UNKFAIL_ENAB is set in login.defs
       Closes: #298773
     - Remove limits.5 and limits.conf.5 man pages which do not
       reflect the way we deal with limits in Debian
       Closes: #288106, #244754
     - debian/login.defs:
       - Make SU_PATH and PATH consistent with the values used in /etc/profile
         Closes: #286616
       - Comment the UMASK setting which is more confusing than useful
         as it only affects console logins. Better use pam_umask instead
         Closes: #314539, #248150
       - Add a comment about "appropriate" values for umask
         Closes: #269583
       - Correct the assertion about the variable defined by QMAIL_DIR
         which is MAILDIR, not MAIL
         Closes: #109279
       - Move the PASS_MAX_LEN variable at the end of login.defs as this
         is obsoleted when using PAM
         Closes: #87301
     - debian/passwd.config:
       - Re-enable the password confirmation question at critical priority
         Closes: #304350
       - Do no prompt again for the login name when the two passwords don't
         match while creating a new user
         Closes: #245332
     - debian/add-shell.sh, debian/remove-shell.sh, debian/shadowconfig.sh,
       debian/passwd.config, debian/passwd.postinst:
       - checked for bashisms, replaced "#!/bin/bash" with "#!/bin/sh",
         Closes: #315767
       - replaced "test XXX -a YYY" XSI:isms with "test XXX && test YYY",
         for rationale see:
         http://www.opengroup.org/onlinepubs/009695399/utilities/test.html
       - replaced all unneeded "egrep"s with basic "grep"s
         Closes: #256732
     - debian/rules:
       Remove the setuid bit on login
       Closes: #298060
     - debian/passwd.templates:
       Templates rewrite to shorten them down a little and make them DTSG
       compliant. Give more details about what the user's full name is used
       for.
       Closes: #287410
     - Updated to Standards: 3.6.2 (checked)
   * Debconf translation updates:
     - Estonian added. Closes: #312471
     - Basque updated. Closes: #314303
     - Malagasy updated. Closes: #290842
     - Punjabi updated. Closes: #315372
     - Danish updated. Closes: #315378
     - Polish updated. Closes: #315391
     - Japanese updated. Closes: #315407
     - Brazilian Portuguese updated. Closes: #315426
     - Czech updated. Closes: #315429
     - Spanish updated. Closes: #315434
     - Lithuanian updated. Closes: #315483
     - Galician updated. Closes: #315362
     - Portuguese updated. Closes: #315375
     - Simplified Chinese updated. Closes: #315567
     - French updated
     - Ukrainian updated. Closes: #315727
     - Welsh updated. Closes: #315809
     - Slovak updated. Closes: #315812
     - Romanian updated. Closes: #315783
     - Finnish updated. Closes: #315972
     - Catalan updated. Closes: #316026
   * Man pages translation updates:
     - Remove the too outdated Korean translation of newgrp.1
       which doesn't even mention sg
       Closes: #261490
   * Man pages correction for Debian specific issues:
     - 402_usermod.8-system-users-range-286258:
       Document the system user range from 0 to 999 in Debian
       Closes: #286258
   * Upstream bugs not fixed in upstream releases or CVS:
     - 423_su_pass_args_without_concatenation
       Thanks to Helmut Waitzmann.
       Closes: #276419
       * pass the argument to the shell or command without concatenation
         before the call to exec.
       * If no command is provided, the arguments after the username are for
         the shell, no -c has to be appended.
     - 008_su_ignore_SIGINT
       * Also ignore SIGQUIT in su to avoid defeating the delay.
         The gain in security is very minor.
         Closes: #288827
     - 424_pwck.8_quiet_option
       pwck(8): document the -q option. Closes: #309408
     - 425_lastlog_8_sparse
       lastlog(8): Document that lastlog is a sparse file, and don't need to be
       rotated. Closes: #219321
     - 426_grpck_group-gshadow_members_consistency
       * (grpck) warn for inconsistencies between members in /etc/group and gshadow
         Closes: #75181
       * (pwck and grpck) warn and propose a fix for entries present in the
         regular /etc/group or /etc/passwd files and not in shadow/gshadow.
     - 427_chage_expiry_0
       Fix chage display in the case of null expiry fields (do not display
       Never, but 01 Jan 1970)
       Closes: #78961
   * Upstream bugs already fixed in upstream releases or CVS:
     - Corrected typos in chfn.1. Closes: #312428
     - Corrected typos in gshadow.5. Closes: #312429
     - Corrected typos in shadow.5. Closes: #312430
     - Corrected typos in grpck.8. Closes: #312431
     - Added patch (356th) for su to propagate SIGSTOP up and SIGCONT down.
       Added similar patch (357th) for newgrp. Both changes only affect
       operation with CLOSE_SESSION set to yes (in /etc/login.defs).
       Closes: #314727
   * Translation updates:
     - debian/patches/010_more-i18ned-messages
       - More messages are translatable. We will deal with the translation
         updates after syncing with upstream.
         Closes: #266281
     - debian/patches/114_eu:
       - Basque translation update. Closes: #314423
     - debian/patches/132_vi.dpatch:
       - Vietnamese translation update. Closes: #315840
Files: 
 2b951dfb5a5258b06dbf4cc9c1c10a9b 843 base required shadow_4.0.3-36.dsc
 c282dd24f1a680566120ef684f5c0386 1405333 base required shadow_4.0.3-36.diff.gz
 c3e579b2641ed0587fa4d8a2fb00e56c 504416 base required passwd_4.0.3-36_i386.deb
 9608524e0d057f7cbe832b35bde32f2e 590616 base required login_4.0.3-36_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFCyuJO1OXtrMAUPS0RAh8zAKCdD/46/ukzdT+o7jJwPZYJ/ZnP2QCeImF4
ZIx948C5htLynLJrbekYXn4=
=Mslh
-----END PGP SIGNATURE-----