Audit Logging Failures - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Use the Certificate Setup Wizard to obtain a certificate request for the private
3.
keys and certificates that will be used to sign the log files. When running the
certificate wizard, specify that the request is of type Other, and request that the
output be a certificate request in PKCS#10 format. See "Certificate Setup
Wizard," on page 298 for information about using the Certificate Setup Wizard
to generate requests.
Submit the PKCS#10 request generated in the previous step to the profile
4.
enrollment for auditor certificates in the end-entity interface of the Certificate
Manager that will issue the certificate.
Set up the signed audit log—it is disabled by default—by setting it up in
5.
Netscape Console. Follow the procedure in the section "Configuring Logs in
the CMS Console," on page 270. Specify the nickname of the log you received
in the previous step as the value of the
and specify the events that will be logged in the events parameter.
Assign auditor users, if you have not done so, by creating the user and
6.
assigning them to the auditor group. Members of the auditor group are the
only users who can view and verify the signed audit log. See "Setting up
Administrators, Agents, and Auditors," on page 330 for details about setting
up auditors.
Auditors can view signed audit logs by viewing them from the IT
7.
environment.
Auditors can verify logs by using the
8.
Command-Line Tools Guide for details about using this tool.

Audit Logging Failures

There are events that could cause the audit logging function to fail. In other words,
events cannot be written to the log. For example, when the file system containing
the audit log file is full or when the file permissions for the log file is accidentally
changed. If audit logging fails, CMS will shut down in the following manner:
Servlets are disabled and will not processes new requests.
All pending and new requests are killed.
The CMS subsystem is shut down.
signedAuditCertNickname
tool. See the CMS
AuditVerify
Chapter 7
Signed Audit Log
parameter
Administrative Basics
281

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents