Skip to main content
Question

Query occurrence of password modification on account

  • June 11, 2015
  • 1 reply
  • 1 view

Forum|alt.badge.img+7

We've had some internal security audits recently and it has been requested that we log password modifications to all local accounts on our macs. is there a way to fetch this from a log somewhere?

1 reply

Forum|alt.badge.img+7
  • Author
  • Valued Contributor
  • June 11, 2015

Just in case anyone else needs to do this... The closest I got to this was by looking at /var/log/accountpolicy.log
It show something like this.. PasswordChangeAllowed completed: record "bobbydigital", result: Success (0)

There doesn't seem to be much of anything else I can do besides modify /etc/pam.d/passwd and somehow make it generate a more detailed log for when a local account password gets changed. Hopefully this is not what the mandaters mandate.