PKCS#11 key usage event
This subtype consists of a number of tag-length-value (TLV) triplets. The following triplets may be contained in the record. The specific set of triplets is dependent on the type of event and the information that is available.
Tag value | Name | Length | Format | Description | |
---|---|---|---|---|---|
Dec | Hex | ||||
257 | 101 | KDS_LABEL | 72 | EBCDIC | The 44-byte key handle left-justified and padded on the right with blanks. If the sequence number of the handle is 'FFFFFFFF', this was a raw object. |
259 | 103 | KEY_NAME | 1 - 513 | EBCDIC | The CKA_LABEL attribute from the object. If the CKA_Label is greater than 512 characters, the plus (+) symbol is placed at the 513th character to indicate truncation. |
260 | 104 | OBJ_TYPE | 1 | binary | Object type.
|
261 | 105 | KEY_FPRINT | 1 - 64 | binary |
One or more key fingerprints. The first byte is the number (n) of fingerprints present for the key. Following that are n type-length-value triplets. Within each of these triplets is a 1-byte fingerprint type, followed by a 1-byte length for the triplet, followed by the fingerprint. Fingerprint types:
|
262 | 106 | SERVICE | 8 | EBCDIC | The service associated with the event. |
265 | 109 | KEY_SEC | 1 | binary | Key security.
|
266 | 10A | KEY_ALG | 1 | binary | Key algorithm.
|
270 | 10E | KEY_LEN | 2 | binary | The length of the key (in bits). For RSA, this is the modulus length. For other asymmetric keys, this is the length of the public key. |
273 | 111 | KEY_USAGE_TKDS | 4 | binary | Key usage.
|
274 | 112 | KEY_EC_CURVE | 1 | binary | ECC curve type.
|
275 | 113 | START_TOD | 16 | binary | Start time of the interval in STCKE format. |
276 | 114 | END_TOD | 16 | binary | End time of the interval in STCKE format. |
277 | 115 | USG_COUNT | 4 | binary | Number of usages accounted for in this record. |
279 | 117 | FIPS_INFO | 4 | binary | FIPS information related to the event.
|
The following tags may be present in the end user audit section:
- X500_IDN
- X500_SDN
- IDID_USRI
- IDID_USRF
- IDID_REG
- USRI