Dec 15 23:10:21 prd-ubuntu1804-docker-8c-8g-5381 passwd[976]: password for 'ubuntu' changed by 'root' Dec 15 23:10:21 prd-ubuntu1804-docker-8c-8g-5381 systemd-logind[1081]: Watching system buttons on /dev/input/event0 (Power Button) Dec 15 23:10:21 prd-ubuntu1804-docker-8c-8g-5381 systemd-logind[1081]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Dec 15 23:10:21 prd-ubuntu1804-docker-8c-8g-5381 systemd-logind[1081]: New seat seat0. Dec 15 23:10:21 prd-ubuntu1804-docker-8c-8g-5381 sshd[1098]: Server listening on 0.0.0.0 port 22. Dec 15 23:10:21 prd-ubuntu1804-docker-8c-8g-5381 sshd[1098]: Server listening on :: port 22. Dec 15 23:10:24 prd-ubuntu1804-docker-8c-8g-5381 sshd[1422]: Did not receive identification string from 10.30.104.4 port 50472 Dec 15 23:10:31 prd-ubuntu1804-docker-8c-8g-5381 sshd[1447]: Invalid user jenkins from 10.30.104.4 port 50476 Dec 15 23:10:31 prd-ubuntu1804-docker-8c-8g-5381 sshd[1447]: Received disconnect from 10.30.104.4 port 50476:11: Closed due to user request. [preauth] Dec 15 23:10:31 prd-ubuntu1804-docker-8c-8g-5381 sshd[1447]: Disconnected from invalid user jenkins 10.30.104.4 port 50476 [preauth] Dec 15 23:10:33 prd-ubuntu1804-docker-8c-8g-5381 sshd[1451]: Invalid user jenkins from 10.30.104.4 port 50478 Dec 15 23:10:34 prd-ubuntu1804-docker-8c-8g-5381 sshd[1451]: Received disconnect from 10.30.104.4 port 50478:11: Closed due to user request. [preauth] Dec 15 23:10:34 prd-ubuntu1804-docker-8c-8g-5381 sshd[1451]: Disconnected from invalid user jenkins 10.30.104.4 port 50478 [preauth] Dec 15 23:10:36 prd-ubuntu1804-docker-8c-8g-5381 sshd[1453]: Invalid user jenkins from 10.30.104.4 port 50480 Dec 15 23:10:36 prd-ubuntu1804-docker-8c-8g-5381 sshd[1453]: Received disconnect from 10.30.104.4 port 50480:11: Closed due to user request. [preauth] Dec 15 23:10:36 prd-ubuntu1804-docker-8c-8g-5381 sshd[1453]: Disconnected from invalid user jenkins 10.30.104.4 port 50480 [preauth] Dec 15 23:10:38 prd-ubuntu1804-docker-8c-8g-5381 sshd[1455]: Invalid user jenkins from 10.30.104.4 port 50482 Dec 15 23:10:38 prd-ubuntu1804-docker-8c-8g-5381 sshd[1455]: Received disconnect from 10.30.104.4 port 50482:11: Closed due to user request. [preauth] Dec 15 23:10:38 prd-ubuntu1804-docker-8c-8g-5381 sshd[1455]: Disconnected from invalid user jenkins 10.30.104.4 port 50482 [preauth] Dec 15 23:10:40 prd-ubuntu1804-docker-8c-8g-5381 sshd[1678]: Invalid user jenkins from 10.30.104.4 port 50484 Dec 15 23:10:40 prd-ubuntu1804-docker-8c-8g-5381 sshd[1678]: Received disconnect from 10.30.104.4 port 50484:11: Closed due to user request. [preauth] Dec 15 23:10:40 prd-ubuntu1804-docker-8c-8g-5381 sshd[1678]: Disconnected from invalid user jenkins 10.30.104.4 port 50484 [preauth] Dec 15 23:10:42 prd-ubuntu1804-docker-8c-8g-5381 sshd[1724]: Invalid user jenkins from 10.30.104.4 port 50488 Dec 15 23:10:42 prd-ubuntu1804-docker-8c-8g-5381 sshd[1724]: Received disconnect from 10.30.104.4 port 50488:11: Closed due to user request. [preauth] Dec 15 23:10:42 prd-ubuntu1804-docker-8c-8g-5381 sshd[1724]: Disconnected from invalid user jenkins 10.30.104.4 port 50488 [preauth] Dec 15 23:10:44 prd-ubuntu1804-docker-8c-8g-5381 sshd[1726]: Invalid user jenkins from 10.30.104.4 port 50490 Dec 15 23:10:44 prd-ubuntu1804-docker-8c-8g-5381 sshd[1726]: Received disconnect from 10.30.104.4 port 50490:11: Closed due to user request. [preauth] Dec 15 23:10:44 prd-ubuntu1804-docker-8c-8g-5381 sshd[1726]: Disconnected from invalid user jenkins 10.30.104.4 port 50490 [preauth] Dec 15 23:10:46 prd-ubuntu1804-docker-8c-8g-5381 sshd[1733]: Invalid user jenkins from 10.30.104.4 port 50498 Dec 15 23:10:46 prd-ubuntu1804-docker-8c-8g-5381 sshd[1733]: Received disconnect from 10.30.104.4 port 50498:11: Closed due to user request. [preauth] Dec 15 23:10:46 prd-ubuntu1804-docker-8c-8g-5381 sshd[1733]: Disconnected from invalid user jenkins 10.30.104.4 port 50498 [preauth] Dec 15 23:10:48 prd-ubuntu1804-docker-8c-8g-5381 useradd[1753]: new group: name=jenkins, GID=1001 Dec 15 23:10:48 prd-ubuntu1804-docker-8c-8g-5381 useradd[1753]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Dec 15 23:10:48 prd-ubuntu1804-docker-8c-8g-5381 usermod[1760]: add 'jenkins' to group 'docker' Dec 15 23:10:48 prd-ubuntu1804-docker-8c-8g-5381 usermod[1760]: add 'jenkins' to shadow group 'docker' Dec 15 23:10:49 prd-ubuntu1804-docker-8c-8g-5381 sshd[1790]: Accepted publickey for jenkins from 10.30.104.4 port 50500 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Dec 15 23:10:49 prd-ubuntu1804-docker-8c-8g-5381 sshd[1790]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Dec 15 23:10:49 prd-ubuntu1804-docker-8c-8g-5381 systemd-logind[1081]: New session 1 of user jenkins. Dec 15 23:10:49 prd-ubuntu1804-docker-8c-8g-5381 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Dec 15 23:11:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[2365]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 15 23:11:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[2365]: pam_unix(cron:session): session closed for user root Dec 15 23:12:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[2640]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 15 23:12:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[2640]: pam_unix(cron:session): session closed for user root Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/bin/java java /usr/lib/jvm/java-17-openjdk-amd64/bin/java 1 Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session closed for user root Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/bin/javac javac /usr/lib/jvm/java-17-openjdk-amd64/bin/javac 1 Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session closed for user root Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/lib/jvm/java-openjdk java_sdk_openjdk /usr/lib/jvm/java-17-openjdk-amd64 1 Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session closed for user root Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set java /usr/lib/jvm/java-17-openjdk-amd64/bin/java Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session closed for user root Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set javac /usr/lib/jvm/java-17-openjdk-amd64/bin/javac Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session closed for user root Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set java_sdk_openjdk /usr/lib/jvm/java-17-openjdk-amd64 Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 15 23:12:09 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session closed for user root Dec 15 23:12:39 prd-ubuntu1804-docker-8c-8g-5381 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/apt-get -y -qq install libxml2-utils Dec 15 23:12:39 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Dec 15 23:12:40 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session closed for user root Dec 15 23:13:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[3639]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 15 23:13:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[3639]: pam_unix(cron:session): session closed for user root Dec 15 23:14:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[6585]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 15 23:14:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[6585]: pam_unix(cron:session): session closed for user root Dec 15 23:15:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[6881]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 15 23:15:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[6881]: pam_unix(cron:session): session closed for user root Dec 15 23:16:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[7265]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 15 23:16:01 prd-ubuntu1804-docker-8c-8g-5381 CRON[7265]: pam_unix(cron:session): session closed for user root Dec 15 23:16:50 prd-ubuntu1804-docker-8c-8g-5381 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Dec 15 23:16:50 prd-ubuntu1804-docker-8c-8g-5381 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)