![Netscape Certificate Management System 6.2 Скачать руководство пользователя страница 279](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697279.webp)
Signed Audit Log
Chapter
7
Administrative Basics
279
3.
Use the Certificate Setup Wizard to obtain a certificate request for the private
keys and certificates that will be used to sign the log files. When running the
certificate wizard, specify that the request is of type Other, and request that the
output be a certificate request in PKCS#10 format. See “Certificate Setup
Wizard,” on page 296 for information about using the Certificate Setup Wizard
to generate requests.
4.
Submit the PKCS#10 request generated in the previous step to the profile
enrollment for auditor certificates in the end-entity interface of the Certificate
Manager that will issue the certificate.
5.
Set up the signed audit log—it is disabled by default—by setting it up in
Netscape Console. Follow the procedure in the section “Configuring Logs in
the CMS Console,” on page 268. Specify the nickname of the log you received
in the previous step as the value of the
signedAuditCertNickname
parameter
and specify the events that will be logged in the events parameter.
6.
Assign auditor users, if you have not done so, by creating the user and
assigning them to the auditor group. Members of the auditor group are the
only users who can view and verify the signed audit log. See “Setting up
Administrators, Agents, and Auditors,” on page 328 for details about setting
up auditors.
7.
Auditors can view signed audit logs by viewing them from the IT
environment.
8.
Auditors can verify logs by using the
AuditVerify
tool. See the CMS
Command-Line Tools Guide for details about using this tool.
Audit Logging Failures
There are events that could cause the audit logging function to fail. In other words,
events cannot be written to the log. For example, when the file system containing
the audit log file is full or when the file permissions for the log file is accidentally
changed. If audit logging fails, CMS will shut down in the following manner:
•
Servlets are disabled and will not processes new requests.
•
All pending and new requests are killed.
•
The CMS subsystem is shut down.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...