Apr 26 08:17:44 prd-ubuntu1804-docker-8c-8g-35271 passwd[1002]: password for 'ubuntu' changed by 'root' Apr 26 08:17:44 prd-ubuntu1804-docker-8c-8g-35271 systemd-logind[1060]: Watching system buttons on /dev/input/event0 (Power Button) Apr 26 08:17:44 prd-ubuntu1804-docker-8c-8g-35271 systemd-logind[1060]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Apr 26 08:17:44 prd-ubuntu1804-docker-8c-8g-35271 systemd-logind[1060]: New seat seat0. Apr 26 08:17:44 prd-ubuntu1804-docker-8c-8g-35271 sshd[1129]: Server listening on 0.0.0.0 port 22. Apr 26 08:17:44 prd-ubuntu1804-docker-8c-8g-35271 sshd[1129]: Server listening on :: port 22. Apr 26 08:17:46 prd-ubuntu1804-docker-8c-8g-35271 sshd[1459]: Did not receive identification string from 10.30.104.4 port 39632 Apr 26 08:17:54 prd-ubuntu1804-docker-8c-8g-35271 sshd[1491]: Invalid user jenkins from 10.30.104.4 port 39642 Apr 26 08:17:54 prd-ubuntu1804-docker-8c-8g-35271 sshd[1491]: Received disconnect from 10.30.104.4 port 39642:11: Closed due to user request. [preauth] Apr 26 08:17:54 prd-ubuntu1804-docker-8c-8g-35271 sshd[1491]: Disconnected from invalid user jenkins 10.30.104.4 port 39642 [preauth] Apr 26 08:17:56 prd-ubuntu1804-docker-8c-8g-35271 sshd[1495]: Invalid user jenkins from 10.30.104.4 port 39656 Apr 26 08:17:56 prd-ubuntu1804-docker-8c-8g-35271 sshd[1495]: Received disconnect from 10.30.104.4 port 39656:11: Closed due to user request. [preauth] Apr 26 08:17:56 prd-ubuntu1804-docker-8c-8g-35271 sshd[1495]: Disconnected from invalid user jenkins 10.30.104.4 port 39656 [preauth] Apr 26 08:17:58 prd-ubuntu1804-docker-8c-8g-35271 sshd[1497]: Invalid user jenkins from 10.30.104.4 port 39664 Apr 26 08:17:58 prd-ubuntu1804-docker-8c-8g-35271 sshd[1497]: Received disconnect from 10.30.104.4 port 39664:11: Closed due to user request. [preauth] Apr 26 08:17:58 prd-ubuntu1804-docker-8c-8g-35271 sshd[1497]: Disconnected from invalid user jenkins 10.30.104.4 port 39664 [preauth] Apr 26 08:18:00 prd-ubuntu1804-docker-8c-8g-35271 sshd[1499]: Invalid user jenkins from 10.30.104.4 port 39670 Apr 26 08:18:00 prd-ubuntu1804-docker-8c-8g-35271 sshd[1499]: Received disconnect from 10.30.104.4 port 39670:11: Closed due to user request. [preauth] Apr 26 08:18:00 prd-ubuntu1804-docker-8c-8g-35271 sshd[1499]: Disconnected from invalid user jenkins 10.30.104.4 port 39670 [preauth] Apr 26 08:18:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[1502]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 26 08:18:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[1502]: pam_unix(cron:session): session closed for user root Apr 26 08:18:02 prd-ubuntu1804-docker-8c-8g-35271 sshd[1728]: Invalid user jenkins from 10.30.104.4 port 39680 Apr 26 08:18:02 prd-ubuntu1804-docker-8c-8g-35271 sshd[1728]: Received disconnect from 10.30.104.4 port 39680:11: Closed due to user request. [preauth] Apr 26 08:18:02 prd-ubuntu1804-docker-8c-8g-35271 sshd[1728]: Disconnected from invalid user jenkins 10.30.104.4 port 39680 [preauth] Apr 26 08:18:04 prd-ubuntu1804-docker-8c-8g-35271 sshd[1793]: Invalid user jenkins from 10.30.104.4 port 39684 Apr 26 08:18:04 prd-ubuntu1804-docker-8c-8g-35271 sshd[1793]: Received disconnect from 10.30.104.4 port 39684:11: Closed due to user request. [preauth] Apr 26 08:18:04 prd-ubuntu1804-docker-8c-8g-35271 sshd[1793]: Disconnected from invalid user jenkins 10.30.104.4 port 39684 [preauth] Apr 26 08:18:07 prd-ubuntu1804-docker-8c-8g-35271 sshd[1797]: Invalid user jenkins from 10.30.104.4 port 39686 Apr 26 08:18:07 prd-ubuntu1804-docker-8c-8g-35271 sshd[1797]: Received disconnect from 10.30.104.4 port 39686:11: Closed due to user request. [preauth] Apr 26 08:18:07 prd-ubuntu1804-docker-8c-8g-35271 sshd[1797]: Disconnected from invalid user jenkins 10.30.104.4 port 39686 [preauth] Apr 26 08:18:09 prd-ubuntu1804-docker-8c-8g-35271 sshd[1805]: Invalid user jenkins from 10.30.104.4 port 39692 Apr 26 08:18:09 prd-ubuntu1804-docker-8c-8g-35271 sshd[1805]: Received disconnect from 10.30.104.4 port 39692:11: Closed due to user request. [preauth] Apr 26 08:18:09 prd-ubuntu1804-docker-8c-8g-35271 sshd[1805]: Disconnected from invalid user jenkins 10.30.104.4 port 39692 [preauth] Apr 26 08:18:11 prd-ubuntu1804-docker-8c-8g-35271 sshd[1807]: Invalid user jenkins from 10.30.104.4 port 39694 Apr 26 08:18:11 prd-ubuntu1804-docker-8c-8g-35271 sshd[1807]: Received disconnect from 10.30.104.4 port 39694:11: Closed due to user request. [preauth] Apr 26 08:18:11 prd-ubuntu1804-docker-8c-8g-35271 sshd[1807]: Disconnected from invalid user jenkins 10.30.104.4 port 39694 [preauth] Apr 26 08:18:12 prd-ubuntu1804-docker-8c-8g-35271 useradd[1827]: new group: name=jenkins, GID=1001 Apr 26 08:18:12 prd-ubuntu1804-docker-8c-8g-35271 useradd[1827]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Apr 26 08:18:12 prd-ubuntu1804-docker-8c-8g-35271 usermod[1834]: add 'jenkins' to group 'docker' Apr 26 08:18:12 prd-ubuntu1804-docker-8c-8g-35271 usermod[1834]: add 'jenkins' to shadow group 'docker' Apr 26 08:18:13 prd-ubuntu1804-docker-8c-8g-35271 sshd[1895]: Accepted publickey for jenkins from 10.30.104.4 port 39698 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Apr 26 08:18:13 prd-ubuntu1804-docker-8c-8g-35271 sshd[1895]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Apr 26 08:18:13 prd-ubuntu1804-docker-8c-8g-35271 systemd-logind[1060]: New session 2 of user jenkins. Apr 26 08:18:13 prd-ubuntu1804-docker-8c-8g-35271 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Apr 26 08:19:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[2660]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 26 08:19:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[2660]: pam_unix(cron:session): session closed for user root Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/bin/java java /usr/lib/jvm/java-17-openjdk-amd64/bin/java 1 Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session closed for user root Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/bin/javac javac /usr/lib/jvm/java-17-openjdk-amd64/bin/javac 1 Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session closed for user root Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/lib/jvm/java-openjdk java_sdk_openjdk /usr/lib/jvm/java-17-openjdk-amd64 1 Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session closed for user root Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set java /usr/lib/jvm/java-17-openjdk-amd64/bin/java Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session closed for user root Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set javac /usr/lib/jvm/java-17-openjdk-amd64/bin/javac Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session closed for user root Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set java_sdk_openjdk /usr/lib/jvm/java-17-openjdk-amd64 Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Apr 26 08:19:34 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session closed for user root Apr 26 08:20:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[2852]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 26 08:20:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[2852]: pam_unix(cron:session): session closed for user root Apr 26 08:20:07 prd-ubuntu1804-docker-8c-8g-35271 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/usr/bin/apt-get -y -qq install libxml2-utils Apr 26 08:20:07 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Apr 26 08:20:07 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session closed for user root Apr 26 08:21:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[4279]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 26 08:21:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[4279]: pam_unix(cron:session): session closed for user root Apr 26 08:22:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[7502]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 26 08:22:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[7502]: pam_unix(cron:session): session closed for user root Apr 26 08:23:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[7698]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 26 08:23:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[7698]: pam_unix(cron:session): session closed for user root Apr 26 08:24:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[7972]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 26 08:24:01 prd-ubuntu1804-docker-8c-8g-35271 CRON[7972]: pam_unix(cron:session): session closed for user root Apr 26 08:24:57 prd-ubuntu1804-docker-8c-8g-35271 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-master-project-csit-pap ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Apr 26 08:24:57 prd-ubuntu1804-docker-8c-8g-35271 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)