
Signing Log Files
85
•
Filename
. Select the log file to view. Choose
Current
to view the currently active system log
file.
5. Click
Refresh
.
The table displays the system log entries. The entries are in reverse chronological order, with the
most current entry placed at the top. Use the scroll arrows on the right edge of the panel to scroll
through the log entries.
Each entry has the following information shown:
•
Source
. The component or resource that logged the message.
•
Level
. The severity of the corresponding entry; see
Table 3.9, “Log Levels and Corresponding
Log Messages”
for more information.
•
Date
. The date on which the entry was logged.
•
Time
. The time at which the entry was logged.
•
Details
. A brief description of the log.
6. To view a full entry, double-click it, or select the entry, and click
View
.
3.9.10. Signing Log Files
The Certificate System can digitally sign log files before they are archived or distributed for audit
purposes. This feature allows files to be checked for tampering.
This is an alternative to the signed audit logs feature. The signed audit log feature creates audit logs
that are automatically signed; this tool manually signs archived logs. See
Section 3.9.1.6, “Signed
Audit Log”
for details about signed audit logs.
For signing log files, use a command-line utility called the Signing Tool (
signtool
). For details about
this utility, see
http://www.mozilla.org/projects/security/pki/nss/tools/
.
The utility uses information in the certificate, key, and security module databases of the subsystem
instance.
To sign the log directories, use the following command with the appropriate information:
signtool -d
secdb_dir
-k
cert_nickname
-Z
output input
•
secdb_dir
specifies the path to the directory that contains the certificate, key, and security module
databases for the CA.
•
cert_nickname
specifies the nickname of the certificate to use for signing.
•
output
specifies the name of the JAR file (a signed zip file).
•
input
specifies the path to the directory that contains the log files.
Summary of Contents for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Page 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 144: ...124 ...
Page 160: ...140 ...
Page 208: ...188 ...
Page 210: ...190 ...
Page 256: ...236 ...
Page 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Page 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Page 362: ...342 ...
Page 376: ...356 ...
Page 436: ...416 ...
Page 490: ...470 ...
Page 504: ...484 ...