Signed Audit Log
Chapter
7
Administrative Basics
277
Deleting a Log Module
You can delete unwanted log plug-in modules using the CMS console. Before
deleting a module, be sure to delete all the listeners that are based on this module;
see “Log File Rotation” on page 269.
To delete a module:
1.
Log in to the CMS console (see “Logging Into the CMS Console” on page 247).
2.
Select the Configuration tab.
3.
In the navigation tree, select Logs, and then in the right pane, select the Log
Event Listener Plug-in Registration tab.
4.
In the Plug-in Name list, select the module you want to delete and click Delete.
5.
When prompted, confirm the delete action.
Signed Audit Log
The signed audit log is a feature that creates a log recording system events; the
events that are recorded are selectable from a list of events. This feature, when
enabled, records all system events and produces a verbose set of messages about
this activity; be careful when using this feature to provide enough space in your file
system for this log. The signed audit log feature is disabled by default.
You can also set this audit log up as a signed audit log. You enable this by setting
the
logSigning
parameter to enable and providing the nickname of the certificate
that will be used to sign this log.
When this log is setup as a signed audit log, only a user with auditor privileges can
access and view the log. Auditors can use the
AuditVerify
tool to verify that
signed audit logs have not been tampered with.
When you first set the server up, if you have not created a dedicated certificate for
log signing, but you want to turn on the auditing feature anyway, you can use the
singing certificate for that subsystem to sign the logs. To do this, specify
caSigningCert cert-<cms instance name>
as the value in the
signedAuditCertNickname
parameter for a Certificate Manager, specify the
appropriate signing certificate for other subsystems.
You can also configure which events are recorded in the log by adding or deleting
the event type form the value of the events parameter. Table 7-3 lists the events that
are loggable events. To add an event, add the logging event to the list; to delete an
event, remove it from the list. Log events are separated by commas with no spaces.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...