1 |
Hello folks, |
2 |
|
3 |
I'm using the latest stable x86 versions of Denyhosts, Openssh and PAM as |
4 |
pulled off the portage tree, and am having a little bit of trouble getting |
5 |
Denyhosts to play nice with the messages PAM is throwing into auth.log. I've |
6 |
tried google for it, and threw the question to the Denyhosts mailing list, |
7 |
but neither has turned up any possible assistance. The logs I'm trying to |
8 |
parse are demonstrated below: |
9 |
Nov 20 22:21:03 nova sshd[31328]: pam_unix(sshd:auth): authentication |
10 |
failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=222.233.br |
11 |
oadband9.iol.cz user=root |
12 |
|
13 |
Nov 20 22:21:06 nova sshd[31326]: error: PAM: Authentication failure for |
14 |
root from 222.233.broadband9.iol.cz |
15 |
|
16 |
It's happening with more than just the root user, so I've set up my |
17 |
userdef_regex's to read as follows: |
18 |
USERDEF_FAILED_ENTRY_REGEX=error: PAM: authentication failure for |
19 |
(?P<invalid>invalid user |illegal user )?(?P<user>.*?) from |
20 |
?(?P<host>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}) |
21 |
|
22 |
USERDEF_FAILED_ENTRY_REGEX=pam_unix(sshd:auth): authentication failure; |
23 |
logname= uid=0 euid=0 tty=ssh ruser= rhost=(?P<host>\S+) user=(?P<user>\S+) |
24 |
|
25 |
|
26 |
If anyone can give me a hand figuring out where it is I broke something, |
27 |
that would be greatly appreciated. As I said, I'm not sure how on-topic it |
28 |
is for this particular list, but I'm getting nowhere with the avenues that |
29 |
would probably be more appropriate. |
30 |
|
31 |
Thanks in advance, |
32 |
James |