
Security Target Version 1.0 9/29/2014
Requirement Auditable Events
Additional Audit
Record Content
Establishment/Termination
of an SSH session.
Non-TOE endpoint of
connection (IP address)
for both successes and
failures.
See [SYSLOG] message ID
125022
See [SYSLOG] – Security -
Warnings
Establishment/Termination
of a TLS session.
Non-TOE endpoint of
connection (IP address)
for both successes and
TLS is only used in the context of
HTTPS. Audit messages for TLS will
be the same as FCS_HTTPS_EXT.1.
Attempts to access to the
802.1X controlled port.
(IP address).
Statistics available through
“show dot1x supplicant-info”
and “show dot1x counters”.
Note: Client identity provided
by MAC address, not IP address.
IP address is not applicable prior
threshold for the
unsuccessful authentication
attempts and the actions
taken (e.g., disabling of an
account) and the
subsequent, if appropriate,
restoration to the normal
state (e.g., re-enabling of a
125060
Attempts to re-authenticate.
(e.g., IP address).
Reauthentication is not treated
differently than initial
authentication. Audit for this
activity would be identical to
authentication mechanism.
(e.g., IP address).
See [SYSLOG] – Security -
Warnings
All use of the identification
and authentication
mechanism.
origin of the attempt
(e.g., IP address).
See [SYSLOG] – Security -
Warnings
certificates.
Attempts to revoke
certificates.
Audit messages for these actions
are stored in the configuration
audit trail. For identification, all
certificate management
commands will include the
keywords “crypto-local pki”
with the rest of the message
indicating whether a certificate
Komentáře k této Příručce