![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 267](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697267.webp)
Logs
Chapter
7
Administrative Basics
267
•
When current logs are read from CMS console—the server retrieves the latest
log when it is queried for current logs.
If you configure the server for unbuffered logging, the server flushes out messages
as they are generated to the log files. Because the server performs an I/O operation
(writing to the log file) each time a message is generated, configuring the server for
unbuffered logging decreases performance.
Log File Rotation
Log files are rotated when either of the following occur:
•
The size limit for the corresponding file is reached—the size of the
corresponding log file is equal to or greater than the value specified by the
maxFileSize
configuration parameter. The default value for this parameter is
100 KB.
•
The age limit for the corresponding file is reached—the corresponding log file
is equal to or older than the interval specified by the
rolloverInterval
configuration parameter. The default value for this parameter is 2592000
seconds (every hour).
When a log file is rotated, the old file is named using the name of the file with an
appended time stamp. The appended time stamp is an integer that indicates the
date and time the corresponding active log file was rotated. The date and time have
the forms YYYYMMDD (Year, Month, Day) and
HHmmSS
(Hour, Minute, Second), in
that order.
Log files, especially the audit log file, contain critical information. So it is good
practice to periodically archive rotated log files to some archive media. You can
archive log files by copying the entire
log
directory to your archive media.
CMS does not provide any tool or utility for archiving log files. Use the tools or
utilities that your operating system provides for archiving.
CMS does, however, provide a command-line utility, called
signtool
, that allows
you to sign log files before archiving them. This gives you a means of tamper
detection. For details, see “Signing Log Files” on page 273.
Note that signing log files is an alternative to the signed audit logs feature. Signed
audit logs allows you to create audit logs that are automatically signed, whereas
this process describes how to manually sign archived logs. See “Signed Audit
Log,” on page 263 for details about signed audit logs.
By default, rotated log files are not deleted.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...