- 论坛徽章:
- 0
|
回复 10# jerryjzm
非常感谢你的回答,不好意思,今天才回
[root@redhat1 ~]# more /etc/syslog.conf | grep -v "#"
authpriv.none;cron.none /var/log/messages
authpriv.* /var/log/secure
mail.* -/var/log/maillog
cron.* /var/log/cron
*.emerg *
uucp,news.crit /var/log/spooler
local7.* /var/log/boot.log
*.info;mail.none;local1.none;local3.none;local4.none;local5.none /var/log/messages
local1.debug /var/log/wcltoday.log
local2.* /var/log/RHCS.log
[root@redhat1 ~]# more /etc/pam.d/sshd
#%PAM-1.0
auth required pam_stack.so service=system-auth
auth required pam_nologin.so
account required pam_stack.so service=system-auth
password required pam_stack.so service=system-auth
session required pam_stack.so service=system-auth
session required pam_loginuid.so
messages log就是楼上的那些log
secure log
Mar 15 14:39:51 redhat1 sshd[5566]: Accepted password for kavte from ::ffff:192.168.1.1 port 1026 ssh2
你所说的“手动登陆”你用putty等工具远程ssh,
还是在机器上连接键盘显示器登陆?
远程登录的,用工具
如果是远程,那你的机器的ip是192.168.1.1吗? 连接rhel服务器用的是test用户吗?
嗯,但是user是 kavte
Mar 11 14:06:05 redhat1 sshd(pam_unix)[23188]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=192.168.1.1 user=kavte |
|