Signed Audit Log
87
NOTE
The audit logs for a TPS subsystem cannot be signed.
A log is set to a signed audit log by setting the
logSigning
parameter to
enable
and providing the
nickname of the certificate used to sign the log.
When a log is set as a signed audit log, only a user with auditor privileges can access and view the
log. Auditors can use the
AuditVerify
tool to verify that signed audit logs have not been tampered
with.
If there is not a dedicated certificate to sign audit logs, the subsystem signing certificate can be used
to sign logs. To do this for a Certificate Manager, specify
caSigningCert cert-
CA_instance
name
as the value in the
signedAuditCertNickname
parameter. For other systems, specify the
appropriate signing certificate.
Which events are recorded in the log are configured by adding or deleting the event type from the
value of the events parameter.
Table 3.11, “Signed Audit Log Events”
lists the loggable events. To add
an event, add the logging event to the list; to delete an event, remove it from the list. Log events are
separated by commas with no spaces.
Logging Event
Type of Log Messages Generated
AUDIT_LOG_STARTUP
The start of the subsystem, and thus the start of
the audit function.
AUDIT_LOG_SHUTDOWN
The shutdown of the subsystem, and thus the
shutdown of the audit function.
ROLE_ASSUME
A user assuming a role. A user assumes a
role after passing through authentication and
authorization systems. Only the default roles of
administrator, auditor, and agent are tracked.
Custom roles are not tracked.
CONFIG_CERT_PROFILE
A change is made to the configuration settings
for the certificate profile framework.
CONFIG_CRL_PROFILE
A change is made to the configuration settings
for the CRL framework, such as to the
extensions, frequency, and CRL format.
CONFIG_OCSP_PROFILE
A change is made to the configuration settings
for the OCSP.
CONFIG_AUTH
A change is made to the configuration settings
for the authentication framework.
CONFIG_ROLE
A change is made to the configuration settings
for roles, including changes made to users or
groups.
CONFIG_ACL
A change is made to the configuration settings
for the ACL framework.
CONFIG_SIGNED_AUDIT
A change is made to the configuration settings
for the signed audit feature.
Summary of Contents for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Page 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 144: ...124 ...
Page 160: ...140 ...
Page 208: ...188 ...
Page 210: ...190 ...
Page 256: ...236 ...
Page 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Page 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Page 362: ...342 ...
Page 376: ...356 ...
Page 436: ...416 ...
Page 490: ...470 ...
Page 504: ...484 ...