Chapter 3. Administrative Basics
82
• The age limit for the corresponding file is reached. The corresponding log file is equal to or older
than the interval specified by the
rolloverInterval
configuration parameter. The default value
for this parameter is 2592000 seconds (every thirty days).
When a log file is rotated, the old file is named using the name of the file with an appended time
stamp. The appended time stamp is an integer that indicates the date and time the corresponding
active log file was rotated. The date and time have the forms YYYYMMDD (year, month, day) and
HHMMSS (hour, minute, second).
Log files, especially the audit log file, contain critical information. Periodically archive rotated log files
to some archive media. Log files are archived by copying the entire
/logs
directory to an archive
medium.
NOTE
The Certificate System does not provide any tool or utility for archiving log files.
The Certificate System provides a command-line utility,
signtool
, that signs log files before archiving
them as a means of tamper detection. For details, see
Section 3.9.10, “Signing Log Files”
.
Signing log files is an alternative to the signed audit logs feature. Signed audit logs creates audit logs
that are automatically signed; using
signtool
manually signs archived logs. See
Section 3.9.1.6,
“Signed Audit Log”
for details about signed audit logs.
By default, rotated log files are not deleted.
3.9.6. Configuring Logs in the Console
This procedure describes how to configure system, transaction, and audit logs.
To configure logs for a Certificate System instance:
1. Open the Console.
2. In the navigation tree of the
Configuration
tab, select
Log
.
The
Log Event Listener Management
tab lists the currently configured listeners.
3. To create a new log instance, click
Add
, and select a module plug-in from the list in the
Select
Log Event Listener Plug-in Implementation
window.
To delete a log instance, select a listener to delete in the
Log Event Listener
list. Click
Delete
.
To modify an existing log instance, select a listener to modify in the
Log Event Listener
list. Click
Edit/View
.
4. Change the fields in the
Log Event Listener Editor
window.
•
Log Event Listener ID
. The unique name that identifies the listener. The names can have
any combination of letters (aA to zZ), digits (0 to 9), an underscore (_), and a hyphen (-), but it
cannot contain other characters or spaces.
•
type
. The type of log file. Set
transaction
to create a listener that records audit logs. For error
and system logs, select
system
.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...