Subject: Re: insecurity report wtmpx and wtmp incorrect gid...
From: Steven M. Bellovin <>
Date: 02/24/2006 08:30:21
>Thanks, Water...
>This is, indeed, what is going on... my wtmp and wtmpx are group name=wheel
>And I agree that they should (as specified by /etc/mtree/special) be 
>group name=utmp
>The problem is that when I set them to group name=utmp, something, in my 
>machine, sets them back to group name=wheel
>What I need to identify is what is it that does this change so that I 
>can prevent it from happening again.

You have to change /etc/newsyslog.conf

		--Steven M. Bellovin,