The audit messages in this section are from the Cryptographic Security Platform Vault for PKCS#11.
In the table below, we list many of the audit messages and show:
Whether an Alert is also generated.
The severity (L=Low, M=Medium, H=High).
What the resolution is if any action should be taken.
In the Message column, a value in braces, such as
{user_name}, represents a placeholder that is replaced with an actual value. For example, in the following message:'{user_name}' created the policy '{policy_name}'The actual message will be displayed with the name of the user and policy, for example:
Fred created the policy Default_Policy
Msg ID | Message | Severity | Alert? | Category |
|---|---|---|---|---|
100 | '{user_name}' created the policy '{policy_name}' | M | false | PKCS11 |
101 | '{user_name}' updated the policy '{policy_name}'. New policy version is {policy_version}. | M | false | PKCS11 |
102 | '{user_name}' deleted the policy '{policy_name}' | M | false | PKCS11 |
103 | '{user_name}' changed the current version of the policy '{policy_name}'. Current policy version is {policy_version}. | M | false | PKCS11 |
200 | '{user_name}' created client certificate '{cert_name}' | M | false | PKCS11 |
201 | '{user_name}' created client certificate '{cert_name}' with CSR | M | false | PKCS11 |
202 | '{user_name}' deleted client certificate '{cert_name}' | M | false | PKCS11 |
300 | User '{user_name}' logged in successfully. | H | false | PKCS11 |
301 | Active Directory login for '{username}' succeeded but failed to get information about user. The user might not belong to the Active Directory Domain {domain_name} or user/group Base DN in Active Directory configuration might be wrong. Please contact PKCS11 Administrator to validate the Active Directory setup. | H | false | PKCS11 |
302 | Login failure for Active Directory user '{username}' from {client_ip}. Reason: {reason} | H | false | PKCS11 |
303 | User '{user_name}' logged in successfully using Personal Access Token {token_name}. | H | false | PKCS11 |
304 | '{user_name}' enabled authentication inheritance | M | false | PKCS11 |
305 | '{user_name}' updated OIDC authentication with AD | M | false | PKCS11 |
306 | User '{user_name}' logged out successfully. | H | false | PKCS11 |
400 | '{user_name}' updated AD Setting '{ad_setting_name}' | M | false | PKCS11 |
401 | '{user_name}' changed AD Domain from '{old_ad_setting_name}' to '{ad_setting_name}' | M | false | PKCS11 |
402 | '{user_name}' added AD Setting '{ad_setting_name}' | M | false | PKCS11 |
500 | '{user_name}' updated PKCS11 vault '{vault_name}' settings. 'degraded mode availability' {degraded_mode}. 'OIDC authentication' {oidc}. 'audit alert distribution list' {audit_alert_dl}. 'alert read count' {alert_read_count}. 'email notify alerts' {email_notify_alerts}. | M | false | PKCS11 |
501 | '{user_name}' renamed PKCS11 vault '{old_name}' to '{vault_name}'. | M | false | PKCS11 |
502 | '{user_name}' updated PKCS11 vault '{vault_name}' settings of authentication method to AD based authentication | M | false | PKCS11 |
503 | '{user_name}' updated the CSP Compliance Manager settings for PKCS11 Vault '{vault_name}' with CSP Compliance Manager IP '{kcm_ip}'. | M | false | PKCS11 |
504 | '{user_name}' updated PKCS11 vault '{vault_name}' settings of authentication method to OIDC based authentication | M | false | PKCS11 |
505 | '{user_name}' updated vault owner to {vault_owner} | M | false | PKCS11 |
600 | '{user_name}' created the user '{name}' | M | false | PKCS11 |
601 | '{user_name}' deleted the user '{name}' | M | false | PKCS11 |
602 | '{user_name}' updated the user '{name}' | M | false | PKCS11 |
603 | Account '{user_name}' locked for 5 minutes due to repeated login failures | M | false | PKCS11 |
604 | Account '{user_name}' disabled due to repeated login failures | M | false | PKCS11 |
605 | Login failure for Local user '{username}' from {client_ip}. Reason: {reason} | H | false | PKCS11 |
606 | Successfully updated password for user: '{username}' | H | false | PKCS11 |
607 | Account '{user_name}' enabled Two-Factor Authentication | M | false | PKCS11 |
608 | Account '{user_name}' disabled Two-Factor Authentication | M | false | PKCS11 |
609 | '{user_name}' updated the local user password policy | M | false | PKCS11 |
610 | '{user_name}' enforced Two-Factor Authentication for all users | M | false | PKCS11 |
611 | '{user_name}' removed Two-Factor Authentication enforcement | M | false | PKCS11 |
700 | '{user_name}' created Personal Access Token '{token_name}' | M | false | PKCS11 |
701 | '{user_name}' updated Personal Access Token '{token_name}' | M | false | PKCS11 |
702 | '{user_name}' deleted Personal Access Token '{token_name}' | M | false | PKCS11 |
800 | '{user_name}' created OIDC user '{name}' | M | false | PKCS11 |
801 | '{user_name}' failed to create OIDC user '{name}'. Reason: {reason} | M | false | PKCS11 |
802 | '{user_name}' updated OIDC user '{name}' | M | false | PKCS11 |
803 | '{user_name}' failed to update OIDC user '{name}'. Reason: {reason} | M | false | PKCS11 |
804 | '{user_name}' deleted OIDC user '{name}' | M | false | PKCS11 |
805 | '{user_name}' failed to delete OIDC user '{name}'. Reason: {reason} | M | false | PKCS11 |
806 | '{user_name}' created OIDC registration link for '{name}' | M | false | PKCS11 |
807 | '{user_name}' failed to create OIDC registration link for '{name}'. Reason: {reason} | M | false | PKCS11 |
808 | OIDC login failure for user '{username}' from {client_ip}. Reason: {reason} | H | false | PKCS11 |
900 | '{user_name}' created SCIM token | M | false | PKCS11 |
901 | '{user_name}' deleted SCIM user '{name}' | M | false | PKCS11 |
902 | '{user_name}' created SCIM user '{name}' | M | false | PKCS11 |
903 | '{user_name}' updated SCIM user '{name}' | M | false | PKCS11 |
904 | '{user_name}' deleted SCIM token | M | false | PKCS11 |
1000 | '{user_name}' updated OIDC configuration on vault '{vault_name}' | H | true | PKCS11 |
1001 | '{user_name}' updated OIDC CA certificate for vault '{vault_name}' | H | true | PKCS11 |
1100 | Client certificate '{cert_name}' has expired. Clients using this certificate will no longer be able to access the vault. Please create a new certificate. | H | true | PKCS11 |
1101 | Client certificate '{cert_name}' will expire in {days} days, {hours} hours and {minutes} minutes. Please create a new certificate before it expires. | H | true | PKCS11 |
1200 | '{user_name}' created softcard '{label}' | M | false | PKCS11 |
1201 | '{user_name}' failed to create softcard '{label}'. Reason: {reason} | M | false | PKCS11 |
1202 | '{user_name}' deleted softcard '{label}' | M | false | PKCS11 |
1203 | '{user_name}' failed to delete softcard '{label}'. Reason: {reason} | M | false | PKCS11 |
1204 | '{user_name}' updated the password of softcard '{label}' | H | false | PKCS11 |
1205 | '{user_name}' failed to update the password of softcard '{label}'. Reason: {reason} | H | false | PKCS11 |
1300 | '{user_name}' restarted the PKCS#11 server | M | false | PKCS11 |
1301 | '{user_name}' updated the PKCS#11 server configuration: port={port}, log_level={log_level}, debug_level={debug_level}, assurance_overrides={assurance_overrides} | M | false | PKCS11 |