payShield 10K Installation and User Guide
© Thales Group
Page 115
All Rights Reserved
The Audit Log can contain up to 100,000 entries for audit records. The audit records are added to the log until it is
full and for each subsequent record, the oldest record in the log is deleted to make room for the new one.
Whenever the HSM state is altered through power-up, state changes, or payShield Manager commands, the Audit
Log is updated with the Time/Date, the Command Code Type, the Command Code, the Response Code, and a Text
field with a brief description.
The Audit Log can be configured to record the execution of any payShield Manager, console or Host command.
Configure the Audit Log in the “Audit Settings” menu on the “Configuration” page. Refer to
Note:
Some events are always audited, even if you has not specified auditing activity.
Below the log table there are options to
Download
,
Get More
,
Reload
, and
Clear
.
The Download option retrieves a Comma-Separated-File (CSV) text file (which can be directly imported into a
spreadsheet, for example) of all the log entries. Upon completion of the download, the UI displays the SHA-256
Hash of the downloaded file. Using offline tools, you can manually compute the hash and compare your calculation
with the value displayed in the UI, to ensure that the log is accurate.
Note:
The hash is computed over the file itself, not the value of its contents. Copy/Pasting the contents into a hash
function will give incorrect results.
Note:
If the log is very long, it may take a while to retrieve and can impact performance of the HSM.
•
Selecting
Get More
returns the next batch of log entries.
•
Selecting
Reload
gets the first batch of log entries.
•
Selecting
Clear
, which is only available in secure state, clears all error log entries.
The following table lists all of the audit log messages.
Category
Audit Log Messages
Notes
Access Control
List (ACL)
TCP/TLS connection from x.x.x.x to y.y.y.y refused due to ACL
UDP traffic from x.x.x.x to y.y.y.y refused due to ACL
Optional (controlled by “Audit ACL
connection failures” audit option; Disabled
by default)
x.x.x.x - source IP address
y.y.y.y - destination IP address (Host 1 or
Host 2)
Audit log
Audit log was cleared
Cleared all retrieved audit logs
Cleared all archived audit logs
Authentication
Authentication cmd XX executed
“XX” is the authentication related console
command (such as CO, KD, SP, XD, XH,
XR) that was executed
Table 4
Audit Log Messages
Содержание payShield 10K
Страница 1: ...cpl thalesgroup com payShield 10K Installation and User Guide PUGD0535 006 ...
Страница 147: ...payShield 10K Installation and User Guide Thales Group Page 145 All Rights Reserved 8 9 Domain ...
Страница 335: ...payShield 10K Installation and User Guide Thales Group Page 333 All Rights Reserved pin clear host Online AUTH ...
Страница 451: ...payShield 10K Installation and User Guide Thales Group Page 449 All Rights Reserved ...