Transactions Log
This log records messages specific to the certificate service—messages such as certificate
requests, certificate renewal and revocation requests, and CRL publication—and enables
you to detect any unauthorized access or activity. This log is on by default.
Signed Audit Log
This log contains audit records for events that have been set up as recordable events. If the
attribute is set to
logSigning
belonging to the server. This certificate can be used by auditors to verify that the log has not
been tampered with. See "Signed Audit Log," on page 268.
Services That Are Logged
All major components and protocols (or services) of CS log messages to log files. Table 8-1
lists services that are logged by default. If you want to view messages logged by a specific
service, you can customize log settings accordingly. For details, see "Monitoring Logs" on
page 265.
Table 8-1
Services Logged
Service
ACLs
Administration
All
Authentication
Certificate Authority
Database
HTTP
Key Recovery Authority
LDAP
, the audit log is signed with a log signing certificate
true
Description
Specifies logged events related to access control lists.
Specifies logged events related to this server's administration
—that is, HTTPS
activities
CS
console and
.
Specifies logged events related to all the services.
Specifies logged events related to this server's activity with the
authentication module.
Specifies logged events related to the Certificate Manager.
Specifies logged events related to this server's activity with the
internal database.
Specifies logged events related to the HTTP activity of the server.
(Note, HTTP events are actually logged to the errors log
Red Hat
belonging to the
CS
into
to provide HTTP services.)
Specifies logged events related to the Data Recovery Manager.
Specifies logged events related to this server's activity with the
LDAP directory (used for publishing certificates and CRLs).
communication between the CS
Enterprise Server that is incorporated
Chapter 8
Administrative Basics
Logs
257
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?