Signing Log Files
85
•
Filename
. Select the log file to view. Choose
Current
to view the currently active system log
file.
5. Click
Refresh
.
The table displays the system log entries. The entries are in reverse chronological order, with the
most current entry placed at the top. Use the scroll arrows on the right edge of the panel to scroll
through the log entries.
Each entry has the following information shown:
•
Source
. The component or resource that logged the message.
•
Level
. The severity of the corresponding entry; see
Table 3.9, “Log Levels and Corresponding
Log Messages”
for more information.
•
Date
. The date on which the entry was logged.
•
Time
. The time at which the entry was logged.
•
Details
. A brief description of the log.
6. To view a full entry, double-click it, or select the entry, and click
View
.
3.9.10. Signing Log Files
The Certificate System can digitally sign log files before they are archived or distributed for audit
purposes. This feature allows files to be checked for tampering.
This is an alternative to the signed audit logs feature. The signed audit log feature creates audit logs
that are automatically signed; this tool manually signs archived logs. See
Section 3.9.1.6, “Signed
Audit Log”
for details about signed audit logs.
For signing log files, use a command-line utility called the Signing Tool (
signtool
). For details about
this utility, see
http://www.mozilla.org/projects/security/pki/nss/tools/
.
The utility uses information in the certificate, key, and security module databases of the subsystem
instance.
To sign the log directories, use the following command with the appropriate information:
signtool -d
secdb_dir
-k
cert_nickname
-Z
output input
•
secdb_dir
specifies the path to the directory that contains the certificate, key, and security module
databases for the CA.
•
cert_nickname
specifies the nickname of the certificate to use for signing.
•
output
specifies the name of the JAR file (a signed zip file).
•
input
specifies the path to the directory that contains the log files.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...