The audit messages in this section are from the Cryptographic Security Platform Vault for PKCS#11.

In the table below, we list many of the audit messages and show:

  • Whether an Alert is also generated.

  • The severity (L=Low, M=Medium, H=High).

  • What the resolution is if any action should be taken.

  • In the Message column, a value in braces, such as {user_name}, represents a placeholder that is replaced with an actual value. For example, in the following message:

    '{user_name}' created the policy '{policy_name}'

    The actual message will be displayed with the name of the user and policy, for example:

    Fred created the policy Default_Policy


Msg ID

Message

Severity

Alert?

Category

100

'{user_name}' created the policy '{policy_name}'

M

false

PKCS11

101

'{user_name}' updated the policy '{policy_name}'. New policy version is {policy_version}.

M

false

PKCS11

102

'{user_name}' deleted the policy '{policy_name}'

M

false

PKCS11

103

'{user_name}' changed the current version of the policy '{policy_name}'. Current policy version is {policy_version}.

M

false

PKCS11

200

'{user_name}' created client certificate '{cert_name}'

M

false

PKCS11

201

'{user_name}' created client certificate '{cert_name}' with CSR

M

false

PKCS11

202

'{user_name}' deleted client certificate '{cert_name}'

M

false

PKCS11

300

User '{user_name}' logged in successfully.

H

false

PKCS11

301

Active Directory login for '{username}' succeeded but failed to get information about user. The user might not belong to the Active Directory Domain {domain_name} or user/group Base DN in Active Directory configuration might be wrong. Please contact PKCS11 Administrator to validate the Active Directory setup.

H

false

PKCS11

302

Login failure for Active Directory user '{username}' from {client_ip}. Reason: {reason}

H

false

PKCS11

303

User '{user_name}' logged in successfully using Personal Access Token {token_name}.

H

false

PKCS11

304

'{user_name}' enabled authentication inheritance

M

false

PKCS11

305

'{user_name}' updated OIDC authentication with AD

M

false

PKCS11

306

User '{user_name}' logged out successfully.

H

false

PKCS11

400

'{user_name}' updated AD Setting '{ad_setting_name}'

M

false

PKCS11

401

'{user_name}' changed AD Domain from '{old_ad_setting_name}' to '{ad_setting_name}'

M

false

PKCS11

402

'{user_name}' added AD Setting '{ad_setting_name}'

M

false

PKCS11

500

'{user_name}' updated PKCS11 vault '{vault_name}' settings. 'degraded mode availability' {degraded_mode}. 'OIDC authentication' {oidc}. 'audit alert distribution list' {audit_alert_dl}. 'alert read count' {alert_read_count}. 'email notify alerts' {email_notify_alerts}.

M

false

PKCS11

501

'{user_name}' renamed PKCS11 vault '{old_name}' to '{vault_name}'.

M

false

PKCS11

502

'{user_name}' updated PKCS11 vault '{vault_name}' settings of authentication method to AD based authentication

M

false

PKCS11

503

'{user_name}' updated the CSP Compliance Manager settings for PKCS11 Vault '{vault_name}' with CSP Compliance Manager IP '{kcm_ip}'.

M

false

PKCS11

504

'{user_name}' updated PKCS11 vault '{vault_name}' settings of authentication method to OIDC based authentication

M

false

PKCS11

505

'{user_name}' updated vault owner to {vault_owner}

M

false

PKCS11

600

'{user_name}' created the user '{name}'

M

false

PKCS11

601

'{user_name}' deleted the user '{name}'

M

false

PKCS11

602

'{user_name}' updated the user '{name}'

M

false

PKCS11

603

Account '{user_name}' locked for 5 minutes due to repeated login failures

M

false

PKCS11

604

Account '{user_name}' disabled due to repeated login failures

M

false

PKCS11

605

Login failure for Local user '{username}' from {client_ip}. Reason: {reason}

H

false

PKCS11

606

Successfully updated password for user: '{username}'

H

false

PKCS11

607

Account '{user_name}' enabled Two-Factor Authentication

M

false

PKCS11

608

Account '{user_name}' disabled Two-Factor Authentication

M

false

PKCS11

609

'{user_name}' updated the local user password policy

M

false

PKCS11

610

'{user_name}' enforced Two-Factor Authentication for all users

M

false

PKCS11

611

'{user_name}' removed Two-Factor Authentication enforcement

M

false

PKCS11

700

'{user_name}' created Personal Access Token '{token_name}'

M

false

PKCS11

701

'{user_name}' updated Personal Access Token '{token_name}'

M

false

PKCS11

702

'{user_name}' deleted Personal Access Token '{token_name}'

M

false

PKCS11

800

'{user_name}' created OIDC user '{name}'

M

false

PKCS11

801

'{user_name}' failed to create OIDC user '{name}'. Reason: {reason}

M

false

PKCS11

802

'{user_name}' updated OIDC user '{name}'

M

false

PKCS11

803

'{user_name}' failed to update OIDC user '{name}'. Reason: {reason}

M

false

PKCS11

804

'{user_name}' deleted OIDC user '{name}'

M

false

PKCS11

805

'{user_name}' failed to delete OIDC user '{name}'. Reason: {reason}

M

false

PKCS11

806

'{user_name}' created OIDC registration link for '{name}'

M

false

PKCS11

807

'{user_name}' failed to create OIDC registration link for '{name}'. Reason: {reason}

M

false

PKCS11

808

OIDC login failure for user '{username}' from {client_ip}. Reason: {reason}

H

false

PKCS11

900

'{user_name}' created SCIM token

M

false

PKCS11

901

'{user_name}' deleted SCIM user '{name}'

M

false

PKCS11

902

'{user_name}' created SCIM user '{name}'

M

false

PKCS11

903

'{user_name}' updated SCIM user '{name}'

M

false

PKCS11

904

'{user_name}' deleted SCIM token

M

false

PKCS11

1000

'{user_name}' updated OIDC configuration on vault '{vault_name}'

H

true

PKCS11

1001

'{user_name}' updated OIDC CA certificate for vault '{vault_name}'

H

true

PKCS11

1100

Client certificate '{cert_name}' has expired. Clients using this certificate will no longer be able to access the vault. Please create a new certificate.

H

true

PKCS11

1101

Client certificate '{cert_name}' will expire in {days} days, {hours} hours and {minutes} minutes. Please create a new certificate before it expires.

H

true

PKCS11

1200

'{user_name}' created softcard '{label}'

M

false

PKCS11

1201

'{user_name}' failed to create softcard '{label}'. Reason: {reason}

M

false

PKCS11

1202

'{user_name}' deleted softcard '{label}'

M

false

PKCS11

1203

'{user_name}' failed to delete softcard '{label}'. Reason: {reason}

M

false

PKCS11

1204

'{user_name}' updated the password of softcard '{label}'

H

false

PKCS11

1205

'{user_name}' failed to update the password of softcard '{label}'. Reason: {reason}

H

false

PKCS11

1300

'{user_name}' restarted the PKCS#11 server

M

false

PKCS11

1301

'{user_name}' updated the PKCS#11 server configuration: port={port}, log_level={log_level}, debug_level={debug_level}, assurance_overrides={assurance_overrides}

M

false

PKCS11