最近在Linux日志中发现有如下信息:
vi /var/log/messages
type=CRYPTO_KEY_USER msg=audit(1448528863.866:163): user pid=7735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=df:d3:ff:1f:0b:11:d7:ce:e6:00:be:28:cc:4a:16:40 direction=? spid=7735 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success'
type=CRYPTO_KEY_USER msg=audit(1448528863.873:164): user pid=7735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=60:ec:35:76:1e:f2:1e:6e:0c:3b:62:52:78:23:38:4c direction=? spid=7735 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success'
type=USER_END msg=audit(1448528864.026:165): user p