Chapter 3. Administrative Basics
90
Logging Event
Type of Log Messages Generated
CERT_STATUS_CHANGE_REQUEST_PROCESSED
Shows when a certificate status change is
processed.
AUTHZ_SUCCESS
Shows when a user is successfully processed by
the authorization servlets.
AUTHZ_FAIL
Shows when a user is not successfully
processed by the authorization servlets.
INTER_BOUNDARY
Records stat transfer between different
subsystems.
AUTH_FAIL
Shows when a user does not successfully
authenticate.
AUTH_SUCCESS
Shows when a user successfully authenticates.
CERT_PROFILE_APPROVAL
Shows when a certificate profile sent by an
administrator is approved by an agent.
PROOF_OF_POSSESSION
Shows when proof of possession is checked
during certificate enrollment.
CRL_RETRIEVAL
Shows when a CRL is retrieved by the OCSP.
CRL_VALIDATION
Shows when a CRL is retrieved and the
validation process occurs.
CMC_SIGNED_REQUEST_SIG_VERIFY
Used when CMC (agent pre-signed) certificate
requests or revocation requests are submitted
and the signature is verified.
AUDIT_LOG_SIGNING
Shows when the audit buffer is signed and
flushed to disk.
Table 3.11. Signed Audit Log Events
3.9.13.1. Setting up Signed Audit Logs
To set up signed audit logs:
1. Set up the
caAuditCert
certificate profile. See
Section 13.3, “Setting up Certificate Profiles”
for
information about setting up certificate profiles.
2. Approve the
caAuditCert
certificate profile by approving it in the agent services interface.
If the request for this certificate is received in the end-entities page of a Certificate Manager,
enable the
caAuditCert
profile in that Certificate Manager.
3. Use the Certificate Setup Wizard to obtain a certificate request for the private keys and certificates
that will be used to sign the log files. When running the wizard, specify that the request is of the
type
Other
.
4. Submit the PKCS#10 request generated to the
Manual Log Signing Certificate Enrollment
form
in the end-entities page of the Certificate Manager that will issue the certificate.
5. Set the signed audit log . Follow the procedure in the section
Section 3.9.6, “Configuring
Logs in the Console”
. Specify the nickname of the log in the previous step as the value of the
signedAuditCertNickname
parameter, and set the events that will be logged in the events
parameter.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...