Dec 11 15:39:43 prd-ubuntu1804-docker-8c-8g-4249 passwd[999]: password for 'ubuntu' changed by 'root' Dec 11 15:39:43 prd-ubuntu1804-docker-8c-8g-4249 systemd-logind[1095]: Watching system buttons on /dev/input/event0 (Power Button) Dec 11 15:39:43 prd-ubuntu1804-docker-8c-8g-4249 systemd-logind[1095]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Dec 11 15:39:43 prd-ubuntu1804-docker-8c-8g-4249 systemd-logind[1095]: New seat seat0. Dec 11 15:39:43 prd-ubuntu1804-docker-8c-8g-4249 sshd[1125]: Server listening on 0.0.0.0 port 22. Dec 11 15:39:43 prd-ubuntu1804-docker-8c-8g-4249 sshd[1125]: Server listening on :: port 22. Dec 11 15:39:44 prd-ubuntu1804-docker-8c-8g-4249 sshd[1455]: Did not receive identification string from 10.30.104.4 port 58094 Dec 11 15:39:52 prd-ubuntu1804-docker-8c-8g-4249 sshd[1487]: Invalid user jenkins from 10.30.104.4 port 58098 Dec 11 15:39:52 prd-ubuntu1804-docker-8c-8g-4249 sshd[1487]: Received disconnect from 10.30.104.4 port 58098:11: Closed due to user request. [preauth] Dec 11 15:39:52 prd-ubuntu1804-docker-8c-8g-4249 sshd[1487]: Disconnected from invalid user jenkins 10.30.104.4 port 58098 [preauth] Dec 11 15:39:54 prd-ubuntu1804-docker-8c-8g-4249 sshd[1491]: Invalid user jenkins from 10.30.104.4 port 58322 Dec 11 15:39:54 prd-ubuntu1804-docker-8c-8g-4249 sshd[1491]: Received disconnect from 10.30.104.4 port 58322:11: Closed due to user request. [preauth] Dec 11 15:39:54 prd-ubuntu1804-docker-8c-8g-4249 sshd[1491]: Disconnected from invalid user jenkins 10.30.104.4 port 58322 [preauth] Dec 11 15:39:56 prd-ubuntu1804-docker-8c-8g-4249 sshd[1493]: Invalid user jenkins from 10.30.104.4 port 58466 Dec 11 15:39:56 prd-ubuntu1804-docker-8c-8g-4249 sshd[1493]: Received disconnect from 10.30.104.4 port 58466:11: Closed due to user request. [preauth] Dec 11 15:39:56 prd-ubuntu1804-docker-8c-8g-4249 sshd[1493]: Disconnected from invalid user jenkins 10.30.104.4 port 58466 [preauth] Dec 11 15:39:58 prd-ubuntu1804-docker-8c-8g-4249 sshd[1495]: Invalid user jenkins from 10.30.104.4 port 58468 Dec 11 15:39:58 prd-ubuntu1804-docker-8c-8g-4249 sshd[1495]: Received disconnect from 10.30.104.4 port 58468:11: Closed due to user request. [preauth] Dec 11 15:39:58 prd-ubuntu1804-docker-8c-8g-4249 sshd[1495]: Disconnected from invalid user jenkins 10.30.104.4 port 58468 [preauth] Dec 11 15:40:00 prd-ubuntu1804-docker-8c-8g-4249 sshd[1507]: Invalid user jenkins from 10.30.104.4 port 58470 Dec 11 15:40:00 prd-ubuntu1804-docker-8c-8g-4249 sshd[1507]: Received disconnect from 10.30.104.4 port 58470:11: Closed due to user request. [preauth] Dec 11 15:40:00 prd-ubuntu1804-docker-8c-8g-4249 sshd[1507]: Disconnected from invalid user jenkins 10.30.104.4 port 58470 [preauth] Dec 11 15:40:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[1655]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 11 15:40:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[1655]: pam_unix(cron:session): session closed for user root Dec 11 15:40:02 prd-ubuntu1804-docker-8c-8g-4249 sshd[1726]: Invalid user jenkins from 10.30.104.4 port 58482 Dec 11 15:40:02 prd-ubuntu1804-docker-8c-8g-4249 sshd[1726]: Received disconnect from 10.30.104.4 port 58482:11: Closed due to user request. [preauth] Dec 11 15:40:02 prd-ubuntu1804-docker-8c-8g-4249 sshd[1726]: Disconnected from invalid user jenkins 10.30.104.4 port 58482 [preauth] Dec 11 15:40:04 prd-ubuntu1804-docker-8c-8g-4249 sshd[1752]: Invalid user jenkins from 10.30.104.4 port 58486 Dec 11 15:40:04 prd-ubuntu1804-docker-8c-8g-4249 sshd[1752]: Received disconnect from 10.30.104.4 port 58486:11: Closed due to user request. [preauth] Dec 11 15:40:04 prd-ubuntu1804-docker-8c-8g-4249 sshd[1752]: Disconnected from invalid user jenkins 10.30.104.4 port 58486 [preauth] Dec 11 15:40:06 prd-ubuntu1804-docker-8c-8g-4249 sshd[1773]: Invalid user jenkins from 10.30.104.4 port 58490 Dec 11 15:40:07 prd-ubuntu1804-docker-8c-8g-4249 sshd[1773]: Received disconnect from 10.30.104.4 port 58490:11: Closed due to user request. [preauth] Dec 11 15:40:07 prd-ubuntu1804-docker-8c-8g-4249 sshd[1773]: Disconnected from invalid user jenkins 10.30.104.4 port 58490 [preauth] Dec 11 15:40:09 prd-ubuntu1804-docker-8c-8g-4249 sshd[1782]: Invalid user jenkins from 10.30.104.4 port 58494 Dec 11 15:40:09 prd-ubuntu1804-docker-8c-8g-4249 sshd[1782]: Received disconnect from 10.30.104.4 port 58494:11: Closed due to user request. [preauth] Dec 11 15:40:09 prd-ubuntu1804-docker-8c-8g-4249 sshd[1782]: Disconnected from invalid user jenkins 10.30.104.4 port 58494 [preauth] Dec 11 15:40:11 prd-ubuntu1804-docker-8c-8g-4249 sshd[1801]: Invalid user jenkins from 10.30.104.4 port 58496 Dec 11 15:40:11 prd-ubuntu1804-docker-8c-8g-4249 sshd[1801]: Received disconnect from 10.30.104.4 port 58496:11: Closed due to user request. [preauth] Dec 11 15:40:11 prd-ubuntu1804-docker-8c-8g-4249 sshd[1801]: Disconnected from invalid user jenkins 10.30.104.4 port 58496 [preauth] Dec 11 15:40:13 prd-ubuntu1804-docker-8c-8g-4249 sshd[1803]: Invalid user jenkins from 10.30.104.4 port 58504 Dec 11 15:40:13 prd-ubuntu1804-docker-8c-8g-4249 sshd[1803]: Received disconnect from 10.30.104.4 port 58504:11: Closed due to user request. [preauth] Dec 11 15:40:13 prd-ubuntu1804-docker-8c-8g-4249 sshd[1803]: Disconnected from invalid user jenkins 10.30.104.4 port 58504 [preauth] Dec 11 15:40:15 prd-ubuntu1804-docker-8c-8g-4249 sshd[1825]: Invalid user jenkins from 10.30.104.4 port 58506 Dec 11 15:40:15 prd-ubuntu1804-docker-8c-8g-4249 sshd[1825]: Received disconnect from 10.30.104.4 port 58506:11: Closed due to user request. [preauth] Dec 11 15:40:15 prd-ubuntu1804-docker-8c-8g-4249 sshd[1825]: Disconnected from invalid user jenkins 10.30.104.4 port 58506 [preauth] Dec 11 15:40:16 prd-ubuntu1804-docker-8c-8g-4249 useradd[1845]: new group: name=jenkins, GID=1001 Dec 11 15:40:16 prd-ubuntu1804-docker-8c-8g-4249 useradd[1845]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Dec 11 15:40:16 prd-ubuntu1804-docker-8c-8g-4249 usermod[1852]: add 'jenkins' to group 'docker' Dec 11 15:40:16 prd-ubuntu1804-docker-8c-8g-4249 usermod[1852]: add 'jenkins' to shadow group 'docker' Dec 11 15:40:17 prd-ubuntu1804-docker-8c-8g-4249 sshd[1913]: Accepted publickey for jenkins from 10.30.104.4 port 58508 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Dec 11 15:40:17 prd-ubuntu1804-docker-8c-8g-4249 sshd[1913]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Dec 11 15:40:17 prd-ubuntu1804-docker-8c-8g-4249 systemd-logind[1095]: New session 2 of user jenkins. Dec 11 15:40:17 prd-ubuntu1804-docker-8c-8g-4249 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Dec 11 15:41:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[2652]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 11 15:41:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[2652]: pam_unix(cron:session): session closed for user root Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/bin/java java /usr/lib/jvm/java-17-openjdk-amd64/bin/java 1 Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session closed for user root Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/bin/javac javac /usr/lib/jvm/java-17-openjdk-amd64/bin/javac 1 Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session closed for user root Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/lib/jvm/java-openjdk java_sdk_openjdk /usr/lib/jvm/java-17-openjdk-amd64 1 Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session closed for user root Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set java /usr/lib/jvm/java-17-openjdk-amd64/bin/java Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session closed for user root Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set javac /usr/lib/jvm/java-17-openjdk-amd64/bin/javac Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session closed for user root Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set java_sdk_openjdk /usr/lib/jvm/java-17-openjdk-amd64 Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 11 15:41:45 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session closed for user root Dec 11 15:42:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[2808]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 11 15:42:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[2808]: pam_unix(cron:session): session closed for user root Dec 11 15:42:18 prd-ubuntu1804-docker-8c-8g-4249 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/apt-get -y -qq install libxml2-utils Dec 11 15:42:18 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 11 15:42:18 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session closed for user root Dec 11 15:43:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[4097]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 11 15:43:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[4097]: pam_unix(cron:session): session closed for user root Dec 11 15:44:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[6711]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 11 15:44:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[6711]: pam_unix(cron:session): session closed for user root Dec 11 15:45:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[6943]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 11 15:45:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[6943]: pam_unix(cron:session): session closed for user root Dec 11 15:46:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[7394]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 11 15:46:01 prd-ubuntu1804-docker-8c-8g-4249 CRON[7394]: pam_unix(cron:session): session closed for user root Dec 11 15:46:43 prd-ubuntu1804-docker-8c-8g-4249 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Dec 11 15:46:43 prd-ubuntu1804-docker-8c-8g-4249 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)