
Originally Posted by
DeepDayze
If the attacker has *already* gained root access, he/she will most certainly delete the log(s) on the local machine to cover up the intrusion. However if the logs are stored on a remote logging server there is a copy of the logs there as well, and will be useful in reconstructing the intrusion as long as THAT machine isn't also compromised.
If the log is opened append only, the file cannot be altered except truncated or deleted
This key signing thing isn't really worth it IMO, if attacker already has root powers