WAS v8.5 > Reference > Commands (wsadmin scripting)

AuditEncryptionCommands command group for AdminTask

We can use the Jython scripting language to configure the security auditing system with wsadmin. Use the commands and parameters in the AuditEncryptionCommands group to configure the security audit system to encrypt audit records.

Use the following commands to enable, disable, and configure audit record encryption:


createAuditEncryptionConfig

The createAuditEncryptionConfig command creates the encryption model used to encrypt the audit records.

We can import the certificate from an existing key file name containing that certificate or automatically generate a certificate.

The user must have the auditor administrative role to run this command.

Target object

None.

Required parameters

-enableAuditEncryption

Whether to encrypt audit records. This parameter modifies your audit policy configuration. (Boolean, required)

-certAlias

Alias name that identifies the generated or imported certificate. (String, required)

-encryptionKeyStoreRef

Specifies the reference ID of the keystore to import the certificate to. (String, required)

Optional parameters

-autogenCert

Whether to automatically generate the certificate used to encrypt the audit records. Specify either this parameter or the -importCert parameter, but we cannot specify both. (Boolean, optional)

-importCert

Whether to import an existing certificate to encrypt the audit records. Specify either this parameter or the -autogenCert parameter, but we cannot specify both. (Boolean, optional)

-certKeyFileName

Unique name of the key file for the certificate to import. (String, optional)

-certKeyFilePath

Key file location for the certificate to import. (String, optional)

-certKeyFileType

Key file type for the certificate to import. (String, optional)

-certKeyFilePassword

Key file password for the certificate to import. (String, optional)

-certAliasToImport

Alias of the certificate to import. (String, optional)

Return value

The command returns the shortened form of the reference ID of the created encryption keystore if the system successfully creates the audit encryption configuration, as the following example output displays:

Interactive mode example usage


createAuditSelfSignedCertificate

The createAuditSelfSignedCertificate command creates a self-signed certificate. Use this command internally to automatically generate a certificate for encryption and signing or to import that certificate into the keystore.

The user must have the auditor administrative role to run this command.

Target object

None.

Required parameters

-keyStoreName

Unique name of the keystore where the system imports the self-signed certificate to. (String, optional)

-certificateAlias

Unique alias name for the certificate. (String, required)

-certificateSize

Size the private key uses for the personal certificate. Default is 1024. (Integer, required)

-certificateCommonName

Common name portion of the distinguished name. (String, required)

Optional parameters

-certificateOrganization

Organizational part of the distinguished name. (String, optional)

-keyStoreScope

Scope of the keystore the system imports the self-signed certificate to. (String, optional)

-certificateVersion

Version of the personal certificate. (String, optional)

-certificateOrganizationalUnit

Organization unit part of the distinguished name. (String, optional)

-certificateLocality

Locality portion of the distinguished name. (String, optional)

-certificateState

State portion of the distinguished name. (String, optional)

-certificateZip

Specifies the zip code portion of the distinguished name. (String, optional)

-certificateCountry

Country portion of the distinguished name. The default value is US. (String, optional)

-certificateValidDays

Length of time, in days, which the certificate is valid. Default is 365 days. (Integer, optional)

Return value

The command returns a value of true if the system successfully creates the self-signed certificate.

Interactive mode example usage


deleteAuditCertificate

The deleteAuditCertificate command deletes a self-signed certificate from an audit keystore.

The user must have the auditor administrative role to run this command.

Target object

None.

Required parameters

-keyStoreName

Unique name of the keystore from which the system deletes the self-signed certificate. (String, required)

-certificateAlias

Unique alias name for the certificate to delete. (String, required)

Optional parameters

-keyStoreScope

Unique alias name for the certificate. (String, optional)

Return value

The command returns a value of true if the system successfully deletes the audit certificate.

Interactive mode example usage


deleteAuditEncryptionConfig

The deleteAuditEncryptionConfig command deletes the encryption model used to encrypt the audit records. The command does not remove keystore files or the certificates.

The user must have the auditor administrative role to run this command.

Target object

None.

Return value

The command returns a value of true if the system successfully deletes the audit encryption configuration.

Batch mode example usage

Interactive mode example usage


disableAuditEncryption

The disableAuditEncryption command disables the encryption of audit records.

The user must have the auditor administrative role to run this command.

Target object

None.

Return value

The command returns a value of true if the system successfully disables audit record encryption.

Interactive mode example usage


enableAuditEncryption

The enableAuditEncryption command enables the encryption of audit records.

The user must have the auditor administrative role to run this command.

Target object

None.

Return value

The command returns a value of true if the system successfully enables audit record encyption.

Interactive mode example usage


exportAuditCertificate

The exportAuditCertificate command exports a self-signed certificate from a keystore. To use this command, you must adhere to the following user role and privilege guidelines:

Target object

None.

Required parameters

-keyStoreName

Unique name of the keystore. (String, required)

-keyStorePassword

Password the system uses to access the keystore specified with the -keyStoreName parameter. (String, required)

-keyFilePath

Key store path name containing the certificate to export. (String, required)

-keyFilePassword

Password of the keystore containing the certificate to export. (String, required)

-keyFileType

Type of the keystore. (String, required)

-certificateAlias

Alias of the certificate to export from the keystore. (String, required)

Optional parameters

-keyStoreScope

Scope name of the keystore. (String, optional)

-aliasInKeyStore

Specifies a new unique name to identify the exported certificate. (String, optional)

Return value

The command returns a value of true if the system successfully exports the audit certificate.

Interactive mode example usage


exportAuditCertToManagedKS

The exportAuditCertToManagedKS command exports a self-signed certificate from an audit keystore to a managed audit keystore.

The user must have the auditor administrative role to run this command.

Target object

None.

Required parameters

-keyStoreName

Unique name of the managed keystore. (String, required)

-keyStorePassword

Password of the managed keystore containing the certificate to export. (String, required)

-toKeyStoreName

Unique name of the managed keystore containing the certificate to export. (String, required)

-certificateAlias

Unique name to identify the exported certificate. (String, required)

Optional parameters

-keyStoreScope

Scope name of the keystore. (String, optional)

-toKeyStoreScope

Scope of the managed keystore containing the certificate to export. (String, optional)

-aliasInKeyStore

New unique name to identify the exported certificate. If we do not specify a value for this parameter, the system sets the unique name to the value specified for the -certificateAlias parameter. (String, optional)

Return value

The command returns a value of true if the system successfully exports the audit certificate.

Interactive mode example usage


getAuditCertificate

The getAuditCertificate command retrieves the attributes for an audit self-signed certificate in an audit keystore.

The user must have the monitor administrative role to run this command.

Target object

None.

Required parameters

-keyStoreName

Unique name of the managed keystore of interest. (String, required)

-certificateAlias

Unique name to identify the exported certificate of interest. (String, required)

Optional parameters

-keyStoreScope

Scope name of the keystore of interest. (String, optional)

Return value

The command returns a list of attributes associated with the audit certificate.

Interactive mode example usage


getAuditEncryptionConfig

The getAuditEncryptionConfig command retrieves the encryption model the system uses to encrypt the audit records.

The user must have the monitor administrative role to run this command.

Target object

None.

Return value

The command returns a list of attributes associated with the encryption model, as the following example output displays:

{{certRef Certificate_1184698729015}
{keystoreRef KeyStore_1173199825578}
{keyStore AuditDefaultKeyStore(cells/CHEYENNENode04Cell|audit.xml#KeyStore_1173199825578)}
{enabled true}
{alias mycertalias}
{_Websphere_Config_Data_Version {}}
{_Websphere_Config_Data_Id cells/CHEYENNENode04Cell|audit.xml#Certificate_1184698729015}
{_Websphere_Config_Data_Type Certificate}}

Batch mode example usage

Interactive mode example usage


getEncryptionKeyStore

The getEncryptionKeyStore command retrieves the attributes for the keystore containing the certificate the system uses to encrypt the audit records.

The user must have the monitor administrative role to run this command.

Target object

None.

Return value

The command returns a list of attributes for the keystore of interest, as the following example displays:

{{location ${CONFIG_ROOT}/audittrust.p12}
{password *****}
{_Websphere_Config_Data_Id cells/CHEYENNENode04Cell|audit.xml#KeyStore_1173199825578}
{_Websphere_Config_Data_Version {}}
{useForAcceleration false}
{slot 0}
{type PKCS12}
{additionalKeyStoreAttrs {}}
{fileBased true}
{_Websphere_Config_Data_Type KeyStore}
{customProviderClass {}}
{hostList {}}
{keystoreRef KeyStore_1173199825578}
{createStashFileForCMS false}
{description {keyStore description}}
{managementScope (cells/CHEYENNENode04Cell|audit.xml#ManagementScope_1173199825608)}
{readOnly false}
{initializeAtStartup true}
{usage {}}
{provider IBMJCE}
{name AuditDefaultKeyStore}}

Batch mode example usage

Interactive mode example usage


importAuditCertFromManagedKS

The importAuditCertFromManagedKS command imports a self-signed certificate into a keystore from a managed audit keystore. Use this command internally to automatically generate a certificate for encryption or signing and to import a certificate into the keystore.

The user must have the auditor administrative role to run this command.

Target object

None.

Required parameters

-keyStoreName

Unique name of the managed keystore. (String, required)

-fromKeyStoreName

Unique name of the managed keystore containing the certificate to import. (String, required)

-fromKeyStorePassword

Password of the managed keystore containing the certificate to import. (String, required)

-certificateAliasFromKeyFile

Alias of the certificate to import from the managed keystore file. (String, required)

Optional parameters

-keyStoreScope

Scope name of the keystore. (String, optional)

-fromKeyStoreScope

Scope of the managed keystore containing the certificate to import. (String, optional)

-certificateAlias

Unique name to identify the imported certificate. (String, optional)

Return value

The command returns a value of true if the system successfully imports the audit certificate.

Interactive mode example usage


importAuditCertificate

The importAuditCertificate command imports a self-signed certificate into a keystore. Use this command internally to automatically generate a certificate for encryption or signing and to import a certificate into the keystore. To use this command, you must adhere to the following user role and privilege guidelines:

Target object

None.

Required parameters

-keyStoreName

Unique name of the keystore. (String, required)

-keyFilePath

Key store path name containing the certificate to import. (String, required)

-keyFilePassword

Password of the keystore containing the certificate to import. (String, required)

-keyFileType

Type of the keystore. (String, required)

-certificateAliasFromKeyFile

Alias of the certificate to import from the keystore file. (String, required)

Optional parameters

-keyStoreScope

Scope name of the keystore. (String, optional)

-certificateAlias

Unique name to identify the imported certificate. (String, optional)

Return value

The command returns a value of true if the system successfully imports the audit certificate.

Interactive mode example usage


importEncryptionCertificate

The importEncryptionCertificate command imports the self-signed certificate the system uses to encrypt audit data from the encryption keystore into a managed keystore in security.xml.

The user must have the auditor administrative role to run this command.

Target object

None.

Required parameters

-keyStoreName

Unique name of the keystore. (String, required)

-keyFilePath

Key store path name containing the certificate to import. (String, required)

-keyFilePassword

Password of the keystore containing the certificate to import. (String, required)

-keyFileType

Type of the keystore. (String, required)

-certificateAliasFromKeyFile

Alias of the certificate to import from the keystore file. (String, required)

Optional parameters

-keyStoreScope

Scope name of the keystore. (String, optional)

-certificateAlias

Unique name to identify the imported certificate. (String, optional)

Return value

The command returns a value of true if the system successfully imports the encryption certificate.

Interactive mode example usage


isAuditEncryptionEnabled

The isAuditEncryptionEnabled command determines if audit record encryption is enabled.

The user must have the monitor administrative role to run this command.

Target object

None.

Return value

The command returns a value of true if audit record encryption is enabled.

Interactive mode example usage


listAuditEncryptionKeyStores

The listAuditEncryptionKeyStores command retrieves the attributes for each configured encryption keystore from the audit.xml file. The command returns attributes for active and inactive keystores.

The user must have the monitor administrative role to run this command.

Target object

None.

Return value

The command returns a list of attributes for each configured keystore, as the following example output displays:

{{location ${CONFIG_ROOT}/audittrust.p12}
{password *****}
{_Websphere_Config_Data_Id cells/CHEYENNENode04Cell|audit.xml#KeyStore_1173199825578}
{useForAcceleration false}
{slot 0}
{type PKCS12}
{additionalKeyStoreAttrs {}}
{fileBased true}
{_Websphere_Config_Data_Type KeyStore}
{customProviderClass {}}
{hostList {}}
{keystoreRef KeyStore_1173199825578}
{createStashFileForCMS false}
{description {keyStore description}}
{readOnly false}
{initializeAtStartup true}
{managementScope (cells/CHEYENNENode04Cell|audit.xml#ManagementScope_1173199825608)}
{usage {}}
{provider IBMJCE}
{name AuditDefaultKeyStore}}

Batch mode example usage

Interactive mode example usage


listCertAliases

The listCertAliases command retrieves a list of the personal certificates in the keystore, as specified by the keystore name and scope of interest.

The user must have the monitor administrative role to run this command.

Target object

None.

Required parameters

-keyStoreName

Unique name of the keystore. (String, required)

Optional parameters

-keyStoreScope

Scope of the keystore. Default is the cell scope. (String, optional)

Return value

The command returns a list of certificate aliases for the personal certificates configured for the keystore, as the following sample output displays:

Batch mode example usage

Interactive mode example usage


modifyAuditEncryptionConfig

The modifyAuditEncryptionConfig command modifies the encryption model the system uses to encrypt the audit records. Specify values for the -enableAuditEncryption, -certAlias, and encryptionKeyStoreRef parameters to use an existing keystore. Do not specify the -importCert or -autogenCert parameters if we use an existing keystore.

The user must have the auditor administrative role to run this command.

Target object

None.

Required parameters None

Optional parameters

-enableAuditEncryption

Whether to encrypt audit records. This parameter modifies your audit policy configuration. (Boolean, optional)

-autogenCert

Whether to automatically generate the certificate used to encrypt the audit records. Specify either this parameter or the -importCert parameter, but we cannot specify both. (Boolean, optional)

-importCert

Whether to import an existing certificate to encrypt the audit records. Specify either this parameter or the -autogenCert parameter, but we cannot specify both. (Boolean, optional)

-certKeyFileName

Unique name of the key file for the certificate to import. (String, optional)

-certKeyFilePath

Key file location for the certificate to import. (String, optional)

-certKeyFileType

Key file type for the certificate to import. (String, optional)

-certKeyFilePassword

Key file password for the certificate to import. (String, optional)

-certAliasToImport

Alias of the certificate to import. (String, optional)

-certAlias

Alias name that identifies the generated or imported certificate. (String, optional)

-encryptionKeyStoreRef

Specifies the reference ID of the keystore to import the certificate to. (String, optional)

Return value

The command returns a value of true if the system successfully updates the configuration.

Interactive mode example usage


renewAuditCertificate

The renewAuditCertificate command renews a self signed certificate in an audit keystore.

The user must have the auditor administrative role to run this command.

Target object

None.

-keyStoreName

Unique name of the managed keystore of interest. (String, required)

-certificateAlias

Unique name to identify the exported certificate to renew. (String, required)

Optional parameters

-keyStoreScope

Scope name of the keystore of interest. (String, optional)

Return value

The command returns a value of true if the system successfully updates the configuration.

Interactive mode example usage


Reference:

AuditKeyStoreCommands command group for AdminTask
AuditEmitterCommands for AdminTask
AuditSigningCommands command group for AdminTask
AuditEventFactoryCommands for AdminTask
AuditFilterCommands command group for AdminTask
AuditNotificationCommands command group for AdminTask
AuditPolicyCommands command group for AdminTask
AuditEventFormatterCommands command group for AdminTask


+

Search Tips   |   Advanced Search