Self-Tests - Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION:
Table of Contents

Advertisement

6. Assign auditor users by creating the user and assigning that entry to the auditor group. Members
of the auditor group are the only users who can view and verify the signed audit log. See
Section 17.2, "Creating Users"
Auditors can view signed audit logs from the IT environment. Auditors can verify logs by using the
AuditVerify tool. See the Certificate System Command-Line Tools Guide for details about using
this tool.
3.9.13.2. Audit Logging Failures
There are events that could cause the audit logging function to fail, so events cannot be written to
the log. For example, audit logging can fail when the filesystem containing the audit log file is full or
when the file permissions for the log file are accidentally changed. If audit logging fails, the Certificate
System instance shuts down in the following manner.
• Servlets are disabled and will not process new requests.
• All pending and new requests are killed.
• The subsystem is shut down.
When this happens, administrators and auditors should work together with the operating system
administrator to resolve the disk space or file permission issues. When the IT problem is resolved, the
auditor should make sure that the last audit log entries are signed. If not, they should be preserved
(Section 3.9.10, "Signing Log
by manual signing
verification failures in the future. When this is completed, the administrators can restart the Certificate
System.

3.10. Self-Tests

The Certificate System has the added functionality to allow self-tests of the server. The self-tests are
run at start up and can also be run on demand. The startup self-tests run when the server starts and
keep the server from starting if a critical self-test fails. The on-demand self-tests are run by clicking the
self-tests button in the subsystem console.
NOTE
There are no self-tests available for the TPS subsystem.
To run an on-demand self-test:
1. Log into the Console.
2. Select the subsystem name at the top of the left pane.
3. Select the Self Tests tab.
4. Click Run.
The self-tests that are configured for the subsystem will run. If any critical self-tests fail, the server
will stop.
for details about setting up auditors.
Files"), archived, and removed to prevent audit
Self-Tests
91

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Table of Contents