shibboleth-dev - Re: [Shib-Dev] Parseable audit logs for SP
Subject: Shibboleth Developers
List archive
- From: Kristof Bajnok <>
- To:
- Subject: Re: [Shib-Dev] Parseable audit logs for SP
- Date: Wed, 9 Feb 2011 11:01:35 +0100
- Organization: NIIF Institute
I strongly support this idea. Details below:
On Tuesday 08 February 2011 22:28:58 Philip Brusten wrote:
> I think, the SP audit log should contain at least the following fields
> delimited by a '|':
> - Authentication Time
> - SessionId
> - REMOTE_USER if any
> - Client IP address
> - Authentication Context Class
> - User-agent
> - Application id
> - entityID of SP
> - entityID of IdP
> - Protocol
> - Binding
> - filtered attribute IDs
The NameID would be very important to include, as this is often different
from
REMOTE_USER, although the qualifyers should be probably omitted.
OTOH I can not thinkof any good use of User-Agent and Protocol (should that
mean http/https?) fields, IMO these would only generate noise. SP entityID
seems to be redundant with the application id, if that's true, I'd keep the
application id.
I suppose that a timestamp should also be logged if it's not done implicitly
by the library. For audit logs, I prefer to use unix timestamps, but as long
as it is machine parseable, any solution would do.
The IdP contains many specifics of the SAML exchange (request id, assertion
ids, etc), but I think, for an SP audit log, these are of little use.
To sum up, I'd propose the following record format:
timestamp|sessionId|REMOTE_USER|NameID|client_IP|appId|IDP_entityid|binding|
authnTime|authncontext|filtered_attribute_ids
Kristof
- [Shib-Dev] Parseable audit logs for SP, Philip Brusten, 02/08/2011
- Re: [Shib-Dev] Parseable audit logs for SP, Cantor, Scott E., 02/08/2011
- Re: [Shib-Dev] Parseable audit logs for SP, Chad La Joie, 02/08/2011
- Re: [Shib-Dev] Parseable audit logs for SP, Cantor, Scott E., 02/08/2011
- Re: [Shib-Dev] Parseable audit logs for SP, Kristof Bajnok, 02/09/2011
- RE: [Shib-Dev] Parseable audit logs for SP, Cantor, Scott E., 02/09/2011
- Re: [Shib-Dev] Parseable audit logs for SP, Peter Schober, 02/09/2011
- RE: [Shib-Dev] Parseable audit logs for SP, Cantor, Scott E., 02/09/2011
- Re: [Shib-Dev] Parseable audit logs for SP, Chad La Joie, 02/09/2011
- RE: [Shib-Dev] Parseable audit logs for SP, Cantor, Scott E., 02/09/2011
- Re: [Shib-Dev] Parseable audit logs for SP, Philip Brusten, 02/14/2011
- Re: [Shib-Dev] Parseable audit logs for SP, Peter Schober, 02/09/2011
- RE: [Shib-Dev] Parseable audit logs for SP, Cantor, Scott E., 02/09/2011
Archive powered by MHonArc 2.6.16.