From d60d790be5d9d2213d177e22c12c5625a313ac2e Mon Sep 17 00:00:00 2001 From: Darren 'Tadgy' Austin Date: Mon, 30 Mar 2026 14:55:51 +0000 Subject: [PATCH] Don't log cronjob start/stop in /var/log/auth. --- .gitattributesdb | 3 +++ etc/pam.d/common-session-noninteractive | 29 +++++++++++++++++++++++++ 2 files changed, 32 insertions(+) create mode 100644 etc/pam.d/common-session-noninteractive diff --git a/.gitattributesdb b/.gitattributesdb index cc3626e..7b0060a 100644 --- a/.gitattributesdb +++ b/.gitattributesdb @@ -402,6 +402,9 @@ ZXRj 1774881279.806906802 1771501908.000000000 root:root 0755 - - cGFtLmQ= - - ZXRjL3BhbS5kLy5naXRpZ25vcmU= 1774714455.970711834 1774714433.803076074 root:root 0644 - - ZXRj 1774881279.806906802 1771501908.000000000 root:root 0755 - - +cGFtLmQ= - - +ZXRjL3BhbS5kL2NvbW1vbi1zZXNzaW9uLW5vbmludGVyYWN0aXZl 1774714594.472436072 1771520438.036467174 root:root 0644 - - +ZXRj 1774881279.806906802 1771501908.000000000 root:root 0755 - - ZXRjL3Bhc3N3ZA== 1773951229.999182951 1773951229.999182951 root:root 0644 - - ZXRj 1774881279.806906802 1771501908.000000000 root:root 0755 - - cGhw - - diff --git a/etc/pam.d/common-session-noninteractive b/etc/pam.d/common-session-noninteractive new file mode 100644 index 0000000..50f685e --- /dev/null +++ b/etc/pam.d/common-session-noninteractive @@ -0,0 +1,29 @@ +# +# /etc/pam.d/common-session-noninteractive - session-related modules +# common to all non-interactive services +# +# This file is included from other service-specific PAM config files, +# and should contain a list of modules that define tasks to be performed +# at the start and end of all non-interactive sessions. +# +# As of pam 1.0.1-6, this file is managed by pam-auth-update by default. +# To take advantage of this, it is recommended that you configure any +# local modules either before or after the default block, and use +# pam-auth-update to manage selection of other modules. See +# pam-auth-update(8) for details. + +# here are the per-package modules (the "Primary" block) +session [default=1] pam_permit.so +# here's the fallback if no module succeeds +session requisite pam_deny.so +# prime the stack with a positive return value if there isn't one already; +# this avoids us returning an error just because nothing sets a success code +# since the modules above will each just jump around +session required pam_permit.so +# reset the umask for new sessions +session optional pam_umask.so +# Silence cron job messages in the authpriv log. +session [success=1 default=ignore] pam_succeed_if.so service in cron quiet use_uid +# and here are more per-package modules (the "Additional" block) +session required pam_unix.so +# end of pam-auth-update config