Hi people.

I was reading some sun documents and I found the way to log root commands
after the user changed to root by "sudo su -" or just "su -" with the root

Resuming my problem, I needed to log all the commands that the users typed
as admin privileges. The solution is to use SUDO so the admin users do not
need know the root password by using the "sudo su -" command and to log what
they did after this command I have tested BSM (Basic Security Module) that
comes with solaris operating system.

You can get more information how to set this in the URLs above:

BSM is really cool :)

Thanks to all.

The problem you are presenting is one of culture -
that is the culture of UNIX administration. The law
MUST be laid down such that:

"thou shall not do 'sudo su -' nor shall thou do 'sudo

Now it's always been a cop-out of a UNIX admin that "I
can't do such-and-such command using sudo" ect. This
is because the UNIX admin has gotten complacent in
their usage/knowledge of UNIX regular expression.
There's ALWAYS a way to do ANY command via sudo so it
gets logged! You've just got to change the culture.
Make it an ISO requirement! In doing so, it is now a
"business rule" and there are now penalties for not
following the ISO documentation ...

and so on, and so on ... It won't be an easy task, but
it is one worth pursuing!

FWIW, take with a grain of salt.

The soapbox has been back to the masses .. :-)

