
Configure the audit of Common Criteria specific events
F
ollow this process to configure the auditing of failed S
SL connections, the creation and/or termination
of HT
TPS connections, and enabling the Web Mail Client audit trail.
Some of the required configuration is not available through the user interface.
Task
1
Back up the appliance configuration.
a
Navigate to System | System Administration | Configuration Management.
b
Select Backup Configuration to save the ZIP file to disk.
2
On the workstation, extract the ZIP file.
It is important to preserve the directory structure of the ZIP file.
3
Use WordPad to open the file config\channels.xml
from the folder.
The file opens.
4
Locate the line: <EventGroup enabled=“yes” name=“SystemEvents”>.
5
Immediately underneath that line add the lines:
<Event id=“220050” enabled=“yes” default=“yes”/>
<Event id=“220051” enabled=“yes” default=“yes”/ >
<Event id=“50061” enabled=“yes” default=“yes”/>
6
Locate the following near the beginning of the file:
<xsl:value‑of select=“@app”/>
7
Immediately underneath that line, add the following lines:
<xsl:if test=“Info [@name=username]/text()”>
<xsl:text>',Username='</xsl:text>
<xsl:value‑of select=“Info [@name='username']/text()”/>
</xsl:if>
8
Save the updated file in text format.
9
Use W
ordPad to open the file config\ui‑logging.xml from the folder.
The file opens
10
Locate the line:
<Group name=“ui” level=“1” default=“1”/>
The level attribute may contain a different value (such as “3”). This is allowed.
11
Immediately underneath that line add the line: .
<Event id=“220051” group=“ui” enabled=“yes” default=“yes” level=“1”/>
12
Sa
ve the updated file in text format.
13
Use W
ordPad to open the file config\smtp‑logging.xml from the folder.
The file opens.
Maintaining a TOE configuration
Configure additional settings for Common Criteria
3
McAfee
®
Email Gateway 7.0.1 Common Criteria Ev
aluated Configuration Guide
Appliances
25
Commentaires sur ces manuels