Support for Logging PKI Transaction Details

FastIron devices support logging of PKI transaction details. The log files are automatically generated syslog messages that contain the transaction details.

There are two types or levels of logging. Standard logging is enabled by default. The second type of logging is called extended logging, which you must enable using commands. This type of logging allows you to log additional IKE or PKI transaction details.

The following additional logging options can be configured in general configuration mode:

  • logging enable pki
  • logging enable pki pki-extended

For example, enter the following commands to configure extended logging for PKI:

device# configure terminal
device(config)# logging enable pki-extended

Once the extended logging commands are configured for PKI, the logs listed in the following table are generated on the ICX device.

Extended Logging Messages

Event Audit Log
Certificate time (validity period) expired. Certificate has expired.
Signature is not valid. Certificate signature failure.
Extended Key Usage support does not have expected key purposes. Unsupported certificate purpose.
Certificate is revoked by CA (applies to both chain and non-chained case). Revoked.
Wrong root certificate received in a certificate chain. Unable to get local issuer certificate.
Configured DN value does not match with peer certificate remote DN. Hostname mismatch.
OCSP Response does not have OCSPSigning bit set. OCSP purpose missing in responder certificate.
There is a fingerprint mismatch. Fingerprint match failed.

Limitations

All of the current limitations of the logging feature on FastIron devices apply to the logging of PKI transaction details.