Oct 15 01:11:26 prd-ubuntu1804-docker-8c-8g-76802 passwd[997]: password for 'ubuntu' changed by 'root' Oct 15 01:11:26 prd-ubuntu1804-docker-8c-8g-76802 systemd-logind[1080]: Watching system buttons on /dev/input/event0 (Power Button) Oct 15 01:11:26 prd-ubuntu1804-docker-8c-8g-76802 systemd-logind[1080]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Oct 15 01:11:26 prd-ubuntu1804-docker-8c-8g-76802 systemd-logind[1080]: New seat seat0. Oct 15 01:11:26 prd-ubuntu1804-docker-8c-8g-76802 sshd[1191]: Server listening on 0.0.0.0 port 22. Oct 15 01:11:26 prd-ubuntu1804-docker-8c-8g-76802 sshd[1191]: Server listening on :: port 22. Oct 15 01:11:28 prd-ubuntu1804-docker-8c-8g-76802 sshd[1481]: Did not receive identification string from 10.30.104.4 port 40706 Oct 15 01:11:36 prd-ubuntu1804-docker-8c-8g-76802 sshd[1515]: Invalid user jenkins from 10.30.104.4 port 40708 Oct 15 01:11:36 prd-ubuntu1804-docker-8c-8g-76802 sshd[1515]: Received disconnect from 10.30.104.4 port 40708:11: Closed due to user request. [preauth] Oct 15 01:11:36 prd-ubuntu1804-docker-8c-8g-76802 sshd[1515]: Disconnected from invalid user jenkins 10.30.104.4 port 40708 [preauth] Oct 15 01:11:39 prd-ubuntu1804-docker-8c-8g-76802 sshd[1519]: Invalid user jenkins from 10.30.104.4 port 40712 Oct 15 01:11:39 prd-ubuntu1804-docker-8c-8g-76802 sshd[1519]: Received disconnect from 10.30.104.4 port 40712:11: Closed due to user request. [preauth] Oct 15 01:11:39 prd-ubuntu1804-docker-8c-8g-76802 sshd[1519]: Disconnected from invalid user jenkins 10.30.104.4 port 40712 [preauth] Oct 15 01:11:41 prd-ubuntu1804-docker-8c-8g-76802 sshd[1521]: Invalid user jenkins from 10.30.104.4 port 40714 Oct 15 01:11:41 prd-ubuntu1804-docker-8c-8g-76802 sshd[1521]: Received disconnect from 10.30.104.4 port 40714:11: Closed due to user request. [preauth] Oct 15 01:11:41 prd-ubuntu1804-docker-8c-8g-76802 sshd[1521]: Disconnected from invalid user jenkins 10.30.104.4 port 40714 [preauth] Oct 15 01:11:43 prd-ubuntu1804-docker-8c-8g-76802 sshd[1545]: Invalid user jenkins from 10.30.104.4 port 40716 Oct 15 01:11:43 prd-ubuntu1804-docker-8c-8g-76802 sshd[1545]: Received disconnect from 10.30.104.4 port 40716:11: Closed due to user request. [preauth] Oct 15 01:11:43 prd-ubuntu1804-docker-8c-8g-76802 sshd[1545]: Disconnected from invalid user jenkins 10.30.104.4 port 40716 [preauth] Oct 15 01:11:46 prd-ubuntu1804-docker-8c-8g-76802 sshd[1778]: Invalid user jenkins from 10.30.104.4 port 40718 Oct 15 01:11:46 prd-ubuntu1804-docker-8c-8g-76802 sshd[1778]: Received disconnect from 10.30.104.4 port 40718:11: Closed due to user request. [preauth] Oct 15 01:11:46 prd-ubuntu1804-docker-8c-8g-76802 sshd[1778]: Disconnected from invalid user jenkins 10.30.104.4 port 40718 [preauth] Oct 15 01:11:48 prd-ubuntu1804-docker-8c-8g-76802 sshd[1789]: Invalid user jenkins from 10.30.104.4 port 40720 Oct 15 01:11:48 prd-ubuntu1804-docker-8c-8g-76802 sshd[1789]: Received disconnect from 10.30.104.4 port 40720:11: Closed due to user request. [preauth] Oct 15 01:11:48 prd-ubuntu1804-docker-8c-8g-76802 sshd[1789]: Disconnected from invalid user jenkins 10.30.104.4 port 40720 [preauth] Oct 15 01:11:50 prd-ubuntu1804-docker-8c-8g-76802 sshd[1797]: Invalid user jenkins from 10.30.104.4 port 40728 Oct 15 01:11:51 prd-ubuntu1804-docker-8c-8g-76802 sshd[1797]: Received disconnect from 10.30.104.4 port 40728:11: Closed due to user request. [preauth] Oct 15 01:11:51 prd-ubuntu1804-docker-8c-8g-76802 sshd[1797]: Disconnected from invalid user jenkins 10.30.104.4 port 40728 [preauth] Oct 15 01:11:52 prd-ubuntu1804-docker-8c-8g-76802 useradd[1817]: new group: name=jenkins, GID=1001 Oct 15 01:11:52 prd-ubuntu1804-docker-8c-8g-76802 useradd[1817]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Oct 15 01:11:52 prd-ubuntu1804-docker-8c-8g-76802 usermod[1824]: add 'jenkins' to group 'docker' Oct 15 01:11:52 prd-ubuntu1804-docker-8c-8g-76802 usermod[1824]: add 'jenkins' to shadow group 'docker' Oct 15 01:11:53 prd-ubuntu1804-docker-8c-8g-76802 sshd[1861]: Accepted publickey for jenkins from 10.30.104.4 port 40732 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Oct 15 01:11:53 prd-ubuntu1804-docker-8c-8g-76802 sshd[1861]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Oct 15 01:11:53 prd-ubuntu1804-docker-8c-8g-76802 systemd-logind[1080]: New session 1 of user jenkins. Oct 15 01:11:53 prd-ubuntu1804-docker-8c-8g-76802 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Oct 15 01:12:01 prd-ubuntu1804-docker-8c-8g-76802 CRON[2163]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 15 01:12:01 prd-ubuntu1804-docker-8c-8g-76802 CRON[2163]: pam_unix(cron:session): session closed for user root Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/bin/java java /usr/lib/jvm/java-17-openjdk-amd64/bin/java 1 Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session closed for user root Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/bin/javac javac /usr/lib/jvm/java-17-openjdk-amd64/bin/javac 1 Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session closed for user root Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --install /usr/lib/jvm/java-openjdk java_sdk_openjdk /usr/lib/jvm/java-17-openjdk-amd64 1 Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session closed for user root Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set java /usr/lib/jvm/java-17-openjdk-amd64/bin/java Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session closed for user root Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set javac /usr/lib/jvm/java-17-openjdk-amd64/bin/javac Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session closed for user root Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/update-alternatives --set java_sdk_openjdk /usr/lib/jvm/java-17-openjdk-amd64 Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session closed for user root Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 CRON[2729]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 15 01:13:01 prd-ubuntu1804-docker-8c-8g-76802 CRON[2729]: pam_unix(cron:session): session closed for user root Oct 15 01:13:34 prd-ubuntu1804-docker-8c-8g-76802 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/usr/bin/apt-get -y -qq install libxml2-utils Oct 15 01:13:34 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Oct 15 01:13:34 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session closed for user root Oct 15 01:14:01 prd-ubuntu1804-docker-8c-8g-76802 CRON[3737]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 15 01:14:01 prd-ubuntu1804-docker-8c-8g-76802 CRON[3737]: pam_unix(cron:session): session closed for user root Oct 15 01:15:01 prd-ubuntu1804-docker-8c-8g-76802 CRON[6730]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 15 01:15:01 prd-ubuntu1804-docker-8c-8g-76802 CRON[6730]: pam_unix(cron:session): session closed for user root Oct 15 01:16:01 prd-ubuntu1804-docker-8c-8g-76802 CRON[6906]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 15 01:16:01 prd-ubuntu1804-docker-8c-8g-76802 CRON[6906]: pam_unix(cron:session): session closed for user root Oct 15 01:17:02 prd-ubuntu1804-docker-8c-8g-76802 CRON[7861]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 15 01:17:02 prd-ubuntu1804-docker-8c-8g-76802 CRON[7860]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 15 01:17:02 prd-ubuntu1804-docker-8c-8g-76802 CRON[7860]: pam_unix(cron:session): session closed for user root Oct 15 01:17:02 prd-ubuntu1804-docker-8c-8g-76802 CRON[7861]: pam_unix(cron:session): session closed for user root Oct 15 01:17:15 prd-ubuntu1804-docker-8c-8g-76802 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/policy-pap-montreal-project-csit-pap ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Oct 15 01:17:15 prd-ubuntu1804-docker-8c-8g-76802 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)