{
    "mode": "man",
    "parameter": "pam_tty_audit",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/pam_tty_audit/8/json",
    "generated": "2026-10-04T21:13:36Z",
    "synopsis": "pamttyaudit.so [disable=patterns] [enable=patterns]",
    "sections": {
        "NAME": {
            "content": "pamttyaudit - Enable or disable TTY auditing for specified users\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "pamttyaudit.so [disable=patterns] [enable=patterns]\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "The pamttyaudit PAM module is used to enable or disable TTY auditing. By default, the\nkernel does not audit input on any TTY.\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "disable=patterns\nFor each user matching patterns, disable TTY auditing. This overrides any previous enable\noption matching the same user name on the command line. See NOTES for further description\nof patterns.\n\nenable=patterns\nFor each user matching patterns, enable TTY auditing. This overrides any previous disable\noption matching the same user name on the command line. See NOTES for further description\nof patterns.\n\nopenonly\nSet the TTY audit flag when opening the session, but do not restore it when closing the\nsession. Using this option is necessary for some services that don't fork() to run the\nauthenticated session, such as sudo.\n\nlogpasswd\nLog keystrokes when ECHO mode is off but ICANON mode is active. This is the mode in which\nthe tty is placed during password entry. By default, passwords are not logged. This\noption may not be available on older kernels (3.9?).\n",
            "subsections": []
        },
        "MODULE TYPES PROVIDED": {
            "content": "Only the session type is supported.\n",
            "subsections": []
        },
        "RETURN VALUES": {
            "content": "PAMSESSIONERR\nError reading or modifying the TTY audit flag. See the system log for more details.\n\nPAMSUCCESS\nSuccess.\n",
            "subsections": []
        },
        "NOTES": {
            "content": "When TTY auditing is enabled, it is inherited by all processes started by that user. In\nparticular, daemons restarted by a user will still have TTY auditing enabled, and audit TTY\ninput even by other users unless auditing for these users is explicitly disabled. Therefore,\nit is recommended to use disable=* as the first option for most daemons using PAM.\n\nTo view the data that was logged by the kernel to audit use the command aureport --tty.\n\nThe patterns are comma separated lists of glob patterns or ranges of uids. A range is\nspecified as minuid:maxuid where one of these values can be empty. If minuid is empty only\nuser with the uid maxuid will be matched. If maxuid is empty users with the uid greater\nthan or equal to minuid will be matched.\n\nPlease note that passwords in some circumstances may be logged by TTY auditing even if the\nlogpasswd is not used. For example, all input to an ssh session will be logged - even if\nthere is a password being typed into some software running at the remote host because only\nthe local TTY state affects the local TTY auditing.\n",
            "subsections": []
        },
        "EXAMPLES": {
            "content": "Audit all administrative actions.\n\nsession   required pamttyaudit.so disable=* enable=root\n\n\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "aureport(8), pam.conf(5), pam.d(5), pam(7)\n",
            "subsections": []
        },
        "AUTHOR": {
            "content": "pamttyaudit was written by Miloslav Trmač <mitr@redhat.com>. The logpasswd option was\nadded by Richard Guy Briggs <rgb@redhat.com>.\n\nLinux-PAM                                    05/07/2023                             PAMTTYAUDIT(8)",
            "subsections": []
        }
    },
    "summary": "pamttyaudit - Enable or disable TTY auditing for specified users",
    "flags": [],
    "examples": [
        "Audit all administrative actions.",
        "session   required pamttyaudit.so disable=* enable=root"
    ],
    "see_also": [
        {
            "name": "aureport",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/aureport/8/json"
        },
        {
            "name": "pam.conf",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/pam.conf/5/json"
        },
        {
            "name": "pam.d",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/pam.d/5/json"
        },
        {
            "name": "pam",
            "section": "7",
            "url": "https://www.chedong.com/phpMan.php/man/pam/7/json"
        }
    ]
}