Setting Up Signed Audit Logs - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Table 8-3
Signed-Audit Log Events
Logging Event
PROOF_OF_POSSESSION
CRL_RETRIEVAL
CRL_VALIDATION
CMC_SIGNED_REQUEST_SIG_VER
IFY
AUDIT_LOG_SIGNING

Setting Up Signed Audit Logs

To set up signed audit logs:
Set up the certificate profiles
1.
Certificate Profiles," on page 414 for information about setting up certificate profiles.
See Chapter 11, "Certificate Profiles" for general information about certificate profiles.
Approve the
2.
caAuditCert
in the agent services interface, thus enabling them.
If the request for this certificate is received in the end-entity interface of a Certificate
Manager, enable the
If the request for this certificate is received in the end-entity interface of a Registration
Manager, enable the
profile in that Certified Manager that processes the requests of that
raAuditCert
Registration Manager.
Use the Certificate Setup Wizard to obtain a certificate request for the private keys and
3.
certificates that will be used to sign the log files. When running the certificate wizard,
specify that the request is of type Other, and request that the output be a certificate
request in PKCS#10 format. See "Certificate Setup Wizard," on page 289 for
information about using the Certificate Setup Wizard to generate requests.
Submit the PKCS#10 request generated in the previous step to the profile enrollment
4.
for auditor certificates in the end-entity interface of the Certificate Manager that will
issue the certificate.
Type of Log Messages are Generated
When proof of possession is checked during certificate
enrollment.
When a CRL is retrieved by the OCSP Responder
When a CRL is retrieved and validation process occurs.
Used when CMC (agent-pre-signed) cert requests or
revocation requests are submitted and signature is
verified.
The audit buffer is signed and flushed to disk.
caAuditCert
and
raAuditCert
profile in that Certificate Manager.
caAuditCert
profile in that Registration Manager and enable the
raAuditCert
and
. See "Setting Up
raAuditCert
certificate profiles by approving them
Chapter 8
Administrative Basics
Signed Audit Log
271

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents