pki-bot / pki-issues-final

0 stars 0 forks source link

Incorrect sequence of SECURITY_DATA_ARCHIVAL events. #2398

Open pki-bot opened 4 years ago

pki-bot commented 4 years ago

This issue was migrated from Pagure Issue #2849. Originally filed by edewata (@edewata) on 2017-11-01 14:55:23:


Key archival via pki kra-key-archive generate audit events in the wrong order. For example:

$ pki -d /root/.dogtag/pki-tomcat/ca/alias -c Secret.123 -n caadmin \
  kra-key-archive --clientKeyID test --passphrase secret

The command generates the following logs:

[AuditEvent=SECURITY_DATA_ARCHIVAL_REQUEST_PROCESSED][SubjectID=kraadmin][Outcome=Success][ArchivalRequestID=<null>][RequestId=44][ClientKeyID=test][KeyID=16][FailureReason=None][PubKey=<null>] security data archival request processed
[AuditEvent=SECURITY_DATA_ARCHIVAL_REQUEST][SubjectID=kraadmin][Outcome=Success][ArchivalRequestID=<null>][RequestId=44][ClientKeyID=test] security data archival request made

Ideally the SECURITY_DATA_ARCHIVAL_REQUEST should happen before SECURITY_DATA_ARCHIVAL_REQUEST_PROCESSED.

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2017-11-01 19:57:35

Metadata Update from @mharmsen:

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2017-11-09 19:25:09

Metadata Update from @mharmsen:

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2017-11-14 11:48:25

Metadata Update from @mharmsen:

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2017-11-14 11:48:53

Per meeting of 20171113 - 10.5 - critical

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2017-11-14 11:49:40

Metadata Update from @mharmsen:

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2018-01-23 23:40:10

Per CS/DS Meeting of 20180122: FUTURE

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2018-01-23 23:40:11

Metadata Update from @mharmsen: