Handling Audit Logging Failures
381
logging.audit.logSigning=true
logging.audit.nonselectable.events=AUDIT_LOG_STARTUP,AUDIT_LOG_SHUTDOWN,LOGGING_SIGNED_AUDIT_SIGNING
logging.audit.selectable.events=
optional events
logging.audit.selected.events=
selected events
logging.audit.signedAuditCertNickname=auditSigningCert cert-pki-tps
logging.audit.signedAuditFilename=/var/log/pki-tps/signedAudit/tps_audit/audit
Example 15.9. TPS Audit Logging Config
3. Start the TPS instance.
service pki-tps start
Event
Description
logging.audit.logSigning
Sets whether to sign the audit log. The default value is
false
.
logging.audit.signedAuditCertNickname
Gives the nickname of the certificate in the TPS database to use to sign the audit log file.
logging.audit.signedAuditFilename
Gives the full path and filename of the file to use for the signed audit log file. This is set in addition to
logging.audit.filename
parameter for the regular audit log file location.
Table 15.10. TPS Signed Audit Log Parameters
Many events can be or are required to be recorded to the audit log. Some events (such as
the system startup) are listed in the
logging.audit.nonselectable.events
parameter
as required events, and they are always recorded in the audit log. A list of other events in the
logging.audit.selectable.events
parameter provide additional options that can be recorded
in the audit log. All loggable events, both required and optional, are listed in
Table 15.11, “Events
Recorded to the TPS Audit Log”
.
Event
Description
AUDIT_LOG_STARTUP
The start of the subsystem, and thus the start of the audit function.
AUDIT_LOG_SHUTDOWN
The shutdown of the subsystem, and thus the shutdown of the audit function.
LOGGING_SIGNED_AUDIT_SIGNING
Shows changes in whether the audit log is signed.
AUTHZ_SUCCESS
Shows when a user is successfully processed by the authorization servlets.
AUTH_SUCCESS
Shows when a user successfully authenticates.
ENROLLMENT
Shows when a token is enrolled through the TPS.
UPGRADE
Shows when the applet on the token is upgraded.
AUTHZ_FAIL
Shows when a user is not successfully processed by the authorization servlets.
ROLE_ASSUME
A user assuming a role. A user assumes a role after passing through authentication and authorization systems. Only the default roles
of administrator, auditor, and agent are tracked. Custom roles are not tracked.
PIN_RESET
Shows when the password used to access the token is reset.
AUTH_FAIL
Shows when a user does not successfully authenticate.
CONFIG_SIGNED_AUDIT
Records when any change is made to the configuration settings for the signed audit log.
FORMAT
Records when a token is formatted.
Table 15.11. Events Recorded to the TPS Audit Log
15.5.3. Handling Audit Logging Failures
There are events that could cause the audit logging function to fail, so events cannot be written to
the log. For example, audit logging can fail when the filesystem containing the audit log file is full or
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...