Oct 5 01:11:30 prd-ubuntu1804-docker-8c-8g-74482 passwd[969]: password for 'ubuntu' changed by 'root' Oct 5 01:11:31 prd-ubuntu1804-docker-8c-8g-74482 systemd-logind[1091]: Watching system buttons on /dev/input/event0 (Power Button) Oct 5 01:11:31 prd-ubuntu1804-docker-8c-8g-74482 systemd-logind[1091]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Oct 5 01:11:31 prd-ubuntu1804-docker-8c-8g-74482 systemd-logind[1091]: New seat seat0. Oct 5 01:11:31 prd-ubuntu1804-docker-8c-8g-74482 sshd[1128]: Server listening on 0.0.0.0 port 22. Oct 5 01:11:31 prd-ubuntu1804-docker-8c-8g-74482 sshd[1128]: Server listening on :: port 22. Oct 5 01:11:34 prd-ubuntu1804-docker-8c-8g-74482 sshd[1407]: Did not receive identification string from 10.30.104.4 port 50910 Oct 5 01:11:37 prd-ubuntu1804-docker-8c-8g-74482 sshd[1435]: Invalid user jenkins from 10.30.104.4 port 50914 Oct 5 01:11:37 prd-ubuntu1804-docker-8c-8g-74482 sshd[1435]: Received disconnect from 10.30.104.4 port 50914:11: Closed due to user request. [preauth] Oct 5 01:11:37 prd-ubuntu1804-docker-8c-8g-74482 sshd[1435]: Disconnected from invalid user jenkins 10.30.104.4 port 50914 [preauth] Oct 5 01:11:39 prd-ubuntu1804-docker-8c-8g-74482 sshd[1439]: Invalid user jenkins from 10.30.104.4 port 50918 Oct 5 01:11:39 prd-ubuntu1804-docker-8c-8g-74482 sshd[1439]: Received disconnect from 10.30.104.4 port 50918:11: Closed due to user request. [preauth] Oct 5 01:11:39 prd-ubuntu1804-docker-8c-8g-74482 sshd[1439]: Disconnected from invalid user jenkins 10.30.104.4 port 50918 [preauth] Oct 5 01:11:41 prd-ubuntu1804-docker-8c-8g-74482 sshd[1441]: Invalid user jenkins from 10.30.104.4 port 50922 Oct 5 01:11:41 prd-ubuntu1804-docker-8c-8g-74482 sshd[1441]: Received disconnect from 10.30.104.4 port 50922:11: Closed due to user request. [preauth] Oct 5 01:11:41 prd-ubuntu1804-docker-8c-8g-74482 sshd[1441]: Disconnected from invalid user jenkins 10.30.104.4 port 50922 [preauth] Oct 5 01:11:43 prd-ubuntu1804-docker-8c-8g-74482 sshd[1443]: Invalid user jenkins from 10.30.104.4 port 50926 Oct 5 01:11:43 prd-ubuntu1804-docker-8c-8g-74482 sshd[1443]: Received disconnect from 10.30.104.4 port 50926:11: Closed due to user request. [preauth] Oct 5 01:11:43 prd-ubuntu1804-docker-8c-8g-74482 sshd[1443]: Disconnected from invalid user jenkins 10.30.104.4 port 50926 [preauth] Oct 5 01:11:45 prd-ubuntu1804-docker-8c-8g-74482 sshd[1445]: Invalid user jenkins from 10.30.104.4 port 50930 Oct 5 01:11:45 prd-ubuntu1804-docker-8c-8g-74482 sshd[1445]: Received disconnect from 10.30.104.4 port 50930:11: Closed due to user request. [preauth] Oct 5 01:11:45 prd-ubuntu1804-docker-8c-8g-74482 sshd[1445]: Disconnected from invalid user jenkins 10.30.104.4 port 50930 [preauth] Oct 5 01:11:47 prd-ubuntu1804-docker-8c-8g-74482 sshd[1447]: Invalid user jenkins from 10.30.104.4 port 50934 Oct 5 01:11:47 prd-ubuntu1804-docker-8c-8g-74482 sshd[1447]: Received disconnect from 10.30.104.4 port 50934:11: Closed due to user request. [preauth] Oct 5 01:11:47 prd-ubuntu1804-docker-8c-8g-74482 sshd[1447]: Disconnected from invalid user jenkins 10.30.104.4 port 50934 [preauth] Oct 5 01:11:49 prd-ubuntu1804-docker-8c-8g-74482 sshd[1654]: Invalid user jenkins from 10.30.104.4 port 50938 Oct 5 01:11:49 prd-ubuntu1804-docker-8c-8g-74482 sshd[1654]: Received disconnect from 10.30.104.4 port 50938:11: Closed due to user request. [preauth] Oct 5 01:11:49 prd-ubuntu1804-docker-8c-8g-74482 sshd[1654]: Disconnected from invalid user jenkins 10.30.104.4 port 50938 [preauth] Oct 5 01:11:52 prd-ubuntu1804-docker-8c-8g-74482 sshd[1708]: Invalid user jenkins from 10.30.104.4 port 50940 Oct 5 01:11:52 prd-ubuntu1804-docker-8c-8g-74482 sshd[1708]: Received disconnect from 10.30.104.4 port 50940:11: Closed due to user request. [preauth] Oct 5 01:11:52 prd-ubuntu1804-docker-8c-8g-74482 sshd[1708]: Disconnected from invalid user jenkins 10.30.104.4 port 50940 [preauth] Oct 5 01:11:54 prd-ubuntu1804-docker-8c-8g-74482 sshd[1712]: Invalid user jenkins from 10.30.104.4 port 50942 Oct 5 01:11:54 prd-ubuntu1804-docker-8c-8g-74482 sshd[1712]: Received disconnect from 10.30.104.4 port 50942:11: Closed due to user request. [preauth] Oct 5 01:11:54 prd-ubuntu1804-docker-8c-8g-74482 sshd[1712]: Disconnected from invalid user jenkins 10.30.104.4 port 50942 [preauth] Oct 5 01:11:56 prd-ubuntu1804-docker-8c-8g-74482 sshd[1722]: Invalid user jenkins from 10.30.104.4 port 50944 Oct 5 01:11:56 prd-ubuntu1804-docker-8c-8g-74482 sshd[1722]: Received disconnect from 10.30.104.4 port 50944:11: Closed due to user request. [preauth] Oct 5 01:11:56 prd-ubuntu1804-docker-8c-8g-74482 sshd[1722]: Disconnected from invalid user jenkins 10.30.104.4 port 50944 [preauth] Oct 5 01:11:58 prd-ubuntu1804-docker-8c-8g-74482 sshd[1724]: Invalid user jenkins from 10.30.104.4 port 50952 Oct 5 01:11:58 prd-ubuntu1804-docker-8c-8g-74482 sshd[1724]: Received disconnect from 10.30.104.4 port 50952:11: Closed due to user request. [preauth] Oct 5 01:11:58 prd-ubuntu1804-docker-8c-8g-74482 sshd[1724]: Disconnected from invalid user jenkins 10.30.104.4 port 50952 [preauth] Oct 5 01:12:00 prd-ubuntu1804-docker-8c-8g-74482 sshd[1726]: Invalid user jenkins from 10.30.104.4 port 50954 Oct 5 01:12:00 prd-ubuntu1804-docker-8c-8g-74482 sshd[1726]: Received disconnect from 10.30.104.4 port 50954:11: Closed due to user request. [preauth] Oct 5 01:12:00 prd-ubuntu1804-docker-8c-8g-74482 sshd[1726]: Disconnected from invalid user jenkins 10.30.104.4 port 50954 [preauth] Oct 5 01:12:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[1729]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 01:12:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[1729]: pam_unix(cron:session): session closed for user root Oct 5 01:12:02 prd-ubuntu1804-docker-8c-8g-74482 useradd[1775]: new group: name=jenkins, GID=1001 Oct 5 01:12:02 prd-ubuntu1804-docker-8c-8g-74482 useradd[1775]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Oct 5 01:12:02 prd-ubuntu1804-docker-8c-8g-74482 usermod[1782]: add 'jenkins' to group 'docker' Oct 5 01:12:02 prd-ubuntu1804-docker-8c-8g-74482 usermod[1782]: add 'jenkins' to shadow group 'docker' Oct 5 01:12:03 prd-ubuntu1804-docker-8c-8g-74482 sshd[1812]: Accepted publickey for jenkins from 10.30.104.4 port 50958 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Oct 5 01:12:03 prd-ubuntu1804-docker-8c-8g-74482 sshd[1812]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Oct 5 01:12:03 prd-ubuntu1804-docker-8c-8g-74482 systemd-logind[1091]: New session 2 of user jenkins. Oct 5 01:12:03 prd-ubuntu1804-docker-8c-8g-74482 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Oct 5 01:13:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[2607]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 01:13:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[2607]: pam_unix(cron:session): session closed for user root Oct 5 01:13:16 prd-ubuntu1804-docker-8c-8g-74482 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/bin/java java /usr/lib/jvm/java-17-openjdk-amd64/bin/java 1 Oct 5 01:13:16 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 5 01:13:16 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session closed for user root Oct 5 01:13:16 prd-ubuntu1804-docker-8c-8g-74482 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/bin/javac javac /usr/lib/jvm/java-17-openjdk-amd64/bin/javac 1 Oct 5 01:13:16 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 5 01:13:16 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session closed for user root Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/lib/jvm/java-openjdk java_sdk_openjdk /usr/lib/jvm/java-17-openjdk-amd64 1 Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session closed for user root Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set java /usr/lib/jvm/java-17-openjdk-amd64/bin/java Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session closed for user root Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set javac /usr/lib/jvm/java-17-openjdk-amd64/bin/javac Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session closed for user root Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set java_sdk_openjdk /usr/lib/jvm/java-17-openjdk-amd64 Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 5 01:13:17 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session closed for user root Oct 5 01:13:52 prd-ubuntu1804-docker-8c-8g-74482 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/apt-get -y -qq install libxml2-utils Oct 5 01:13:52 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 5 01:13:52 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session closed for user root Oct 5 01:14:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[3234]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 01:14:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[3234]: pam_unix(cron:session): session closed for user root Oct 5 01:15:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[5207]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 01:15:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[5207]: pam_unix(cron:session): session closed for user root Oct 5 01:16:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[6905]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 01:16:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[6905]: pam_unix(cron:session): session closed for user root Oct 5 01:17:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[7331]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 01:17:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[7332]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 01:17:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[7331]: pam_unix(cron:session): session closed for user root Oct 5 01:17:01 prd-ubuntu1804-docker-8c-8g-74482 CRON[7332]: pam_unix(cron:session): session closed for user root Oct 5 01:17:45 prd-ubuntu1804-docker-8c-8g-74482 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Oct 5 01:17:45 prd-ubuntu1804-docker-8c-8g-74482 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)