ในไฟล์ /var/log/secure
จะพบบรรทัดนี้เยอะมาก
Sep 30 08:58:46 ns1 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 30 08:58:46 ns1 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 30 08:58:47 ns1 sudo: pam_unix(sudo:session): session closed for user root
Sep 30 08:58:47 ns1 sudo: pam_unix(sudo:session): session closed for user root
แก้โดย
nano /etc/pam.d/sudo
#%PAM-1.0
auth include system-auth
account include system-auth
password include system-auth
session [success=done default=ignore] pam_succeed_if.so quiet uid = 0 user = root
session optional pam_keyinit.so revoke
session required pam_limits.so
session include system-auth
กด
30 ก.ย. 62