Support for Logging PKI Transaction Details
There are two types or levels of logging. Standard logging is enabled by default. The second type of logging is called extended logging, which you must enable using commands. This type of logging allows you to log additional IKE or PKI transaction details.
The following additional logging options can be configured in general configuration mode:
For example, enter the following commands to configure extended logging for PKI:
device# configure terminal device(config)# logging enable pki-extended
Once the extended logging commands are configured for PKI, the logs listed in the following table are generated on the ICX device.
Extended Logging Messages
| Event | Audit Log |
|---|---|
| Certificate time (validity period) expired. | Certificate has expired. |
| Signature is not valid. | Certificate signature failure. |
| Extended Key Usage support does not have expected key purposes. | Unsupported certificate purpose. |
| Certificate is revoked by CA (applies to both chain and non-chained case). | Revoked. |
| Wrong root certificate received in a certificate chain. | Unable to get local issuer certificate. |
| Configured DN value does not match with peer certificate remote DN. | Hostname mismatch. |
| OCSP Response does not have OCSPSigning bit set. | OCSP purpose missing in responder certificate. |
| There is a fingerprint mismatch. | Fingerprint match failed. |
Limitations
All of the current limitations of the logging feature on FastIron devices apply to the logging of PKI transaction details.