Red Hat CERTIFICATE SYSTEM 7.2 - ADMINISTRATION Administration Manual page 109

Hide thumbs Also See for CERTIFICATE SYSTEM 7.2 - ADMINISTRATION:
Table of Contents

Advertisement

Logging Event
CERT_STATUS_CHANGE_REQUEST_PROCESSED
AUTHZ_SUCCESS
AUTHZ_FAIL
INTER_BOUNDARY
AUTH_FAIL
AUTH_SUCCESS
CERT_PROFILE_APPROVAL
PROOF_OF_POSSESSION
CRL_RETRIEVAL
CRL_VALIDATION
CMC_SIGNED_REQUEST_SIG_VERIFY
AUDIT_LOG_SIGNING
Table 3.11. Signed Audit Log Events
3.9.13.1. Setting up Signed Audit Logs
To set up signed audit logs:
1. Set up the caAuditCert certificate profile. See
information about setting up certificate profiles.
2. Approve the caAuditCert certificate profile by approving it in the agent services interface.
If the request for this certificate is received in the end-entities page of a Certificate Manager,
enable the caAuditCert profile in that Certificate Manager.
3. Use the Certificate Setup Wizard to obtain a certificate request for the private keys and certificates
that will be used to sign the log files. When running the wizard, specify that the request is of the
type Other .
4. Submit the PKCS#10 request generated to the Manual Log Signing Certificate Enrollment form
in the end-entities page of the Certificate Manager that will issue the certificate.
5. Set the signed audit log . Follow the procedure in the section
Logs in the
Console". Specify the nickname of the log in the previous step as the value of the
signedAuditCertNickname parameter, and set the events that will be logged in the events
parameter.
Type of Log Messages Generated
Shows when a certificate status change is
processed.
Shows when a user is successfully processed by
the authorization servlets.
Shows when a user is not successfully
processed by the authorization servlets.
Records stat transfer between different
subsystems.
Shows when a user does not successfully
authenticate.
Shows when a user successfully authenticates.
Shows when a certificate profile sent by an
administrator is approved by an agent.
Shows when proof of possession is checked
during certificate enrollment.
Shows when a CRL is retrieved by the OCSP.
Shows when a CRL is retrieved and the
validation process occurs.
Used when CMC (agent pre-signed) certificate
requests or revocation requests are submitted
and the signature is verified.
Shows when the audit buffer is signed and
flushed to disk.
Section 12.3, "Setting up Certificate Profiles"
Section 3.9.6, "Configuring
Signed Audit Log
for
89

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?

Table of Contents