Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Verifying audit logs

Prev Next

Digipass S3 audit logs are tamper-evident logs. When you run a checksum on the logs with the nnl-mgmt.sh command-line utility, you can be sure that no one has tampered with the logs after they were created. If the checksum fails, the verifier displays the tampered log. Each line in an audit log is written out with a checksum which allows you to start verification from any line.

The nnl-mgmt.sh audit_log verify command does not work on the Runtime Audit Log in CSV. For a complete description of the verifier, see Audit Log Verification Command in the reference to Command Line Interface.

The location of audit logs is listed below:

  • Runtime audit log in JSON: TOMCAT_HOME/logs/auditlogs/<tenant_id>

  • Server Admin Console audit log: TOMCAT_HOME/logs/admin-auditlogs/<tenant_id>

  • Command-line tool audit log: <NNL_HOME>/admin/logs/admin-auditlogs.

Make sure you assign the password encryption key to the NNL_PKEY environment variable prior to using nnl-mgmt.sh. Refer to Step 4 Encrypt Credentials Used by the Server in Install on Linux.

Example successful verification:

./nnl-mgmt.sh audit_log verify -file TOMCAT_HOME/logs/auditlogs/Admin/nnl-audit-Admin-myhostname.log 
Date/Time ==> Tue Sep 26 20:27:49 UTC 2017
Processing file ==> TOMCAT_HOME/logs/auditlogs/Admin/nnl-audit-Admin-myhostname.log
For tenant ==> Admin
Checksum Verification succeeded for file : TOMCAT_HOME/logs/auditlogs/Admin/nnl-audit-Admin-myhostname.log
1 : Checksum Verification succeeded for file : TOMCAT_HOME/logs/auditlogs/Admin/nnl-audit-Admin-myhostname.log