Successful SSH login attempts are not logged in /var/log/messages in Authentication Manager prior to 8.4
Originally Published: 2019-11-27
Last Modified: 2026-05-27
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1.x, 8.2.x, 8.3.x
Issue
Cause
Resolution
To enable logging of successful SSH logins apply the following changes:
- Log On to the Appliance Operating System with SSH
- Change to root using the following command:
sudo su -
- Edit the file /etc/pam.d/common-session using the following command:
vim /etc/pam.d/common-session
- Press i to enter Insert mode.
- Add the following line to the end of the file:
session required pam_warn.so
- Press ESC to exit Insert mode.
- Save and exit by typing :wq!
- Repeat steps 1 - 7 on each RSA Authentication Manager instance, whether it is a primary or a replica, to log successful SSH authentication attempts for the instance.
Related Articles
SecurID Access: Repeated LDAP Bind Errors logged 121Number of Views Windows desktop machine does not display last logged in user ID with RSA Authentication Agent 7.x for Microsoft Windows 73Number of Views SA connection issue with smcupdate failing when performing yum check-update 9Number of Views How to su as root to a user account protected by securid without getting Passcode prompted. 32Number of Views What is 'AFX fulfillment state V' that is sometimes seen in the AFX log in RSA Identity Governance & Lifecycle? 290Number of Views
Trending Articles
Artifacts to gather in RSA Identity Governance & Lifecycle How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle How to Download and Reinstall the AFX Server Archive in RSA Governance & Lifecycle
Don't see what you're looking for?