Sample Code Audits of Configuration Changes
This sample code audits all changes to the configuration secret data and sends the logs to a file named messages:
[edit system]
syslog {
file messages {
authorization info;
change-log info;
interactive-commands info;
}
}
This sample code expands the scope of the minimum audit to audit all changes to the configuration, not just secret data, and sends the logs to a file named messages:
[edit system]
syslog {
file messages {
any any;
authorization info;
change-log any;
interactive-commands info;
kernel info;
pfe info;
}
}
Example: System Logging of Configuration Changes
This example shows a sample configuration and makes changes to users and secret data.
[edit system]
location {
country-code US;
building B1;
}
...
login {
message "UNAUTHORIZED USE OF THIS ROUTER\n\tIS STRICTLY PROHIBITED!";
user crypto-officer {
uid 2000;
class security-admin;
authentication {
encrypted-password “$ABC123”;
# SECRET-DATA
}
}
password {
format sha512;
}
}
radius-server 192.0.2.15 {
secret “$ABC123” # SECRET-DATA
}
services {
ssh;
}
syslog {
user *{
any emergency;
}
file messages {
any notice;
authorization info;
}
file interactive-commands {
interactive-commands any;
}
}
...
...
The new configuration changes the secret data configuration statements and adds a new user.
user@host# show | compare
[edit system login user admin authentication]
– encrypted-password “$ABC123”; # SECRET-DATA
+ encrypted-password “$ABC123”; # SECRET-DATA
[edit system login]
+ user admin2 {
+ uid 2001;
+ class read-only;
+ authentication {
+ encrypted-password “$ABC123”;
# SECRET-DATA
+ }
+ }
[edit system radius-server 192.0.2.15]
– secret “$ABC123”; # SECRET-DATA
+ secret “$ABC123”; # SECRET-DATA
Table 1 shows sample for syslog auditing for NDcPPv3.0e:
Requirement |
Auditable Events |
Additional Audit Record Contents |
How event generated |
|---|---|---|---|
FAU_GEN.1 |
None |
None |
May 19 21:43:16 host eventd[7841]: SYSTEM_OPERATIONAL: System is operational May 19 21:43:17 host jlaunchd[8318]: Found pid 7842 for already running process: eventd May 8 23:29:38 mgd[19298]: UI_AUTH_EVENT: Authenticated user 'crypto-officer' assigned to class 'j-super-user' May 8 23:29:38 mgd[19298]: UI_LOGIN_EVENT: User 'crypto-officer' login, class 'j-super-user' [19298], ssh-connection '', client-mode 'cli'
May 8 23:30:49 mgd[19298]: UI_DBASE_LOGIN_EVENT: User 'crypto-officer' entering configuration mode May 8 23:31:06 mgd[19298]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'set system login message "this is a ndcpp test box" ' May 8 23:31:09 mgd[19298]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'commit '
May 8 23:35:06 mgd[20830]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'start shell ' May 8 23:35:31 ssh-keygen[20913]: Generated SSH key file /var/home/crypto-officer/.ssh/id_rsa.pub with fingerprint SHA256:iqrLYhPTXD4KhYOeuL+tD8odyYUb/G2O+Fzk9InzZeg
May 8 23:42:38 mgd[22907]: UI_CFG_AUDIT_SET: User 'crypto-officer' set: [system root-authentication] unconfigured -- "plain-text-password" May 8 23:42:44 mgd[22907]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'set system root-authentication plain-text-password ' May 8 23:42:46 mgd[22907]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'commit ' May 8 23:42:46 mgd[22907]: UI_COMMIT: User 'crypto-officer' requested 'commit' operation (comment: none) May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: Obtaining lock for commit May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: updating commit revision May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: UI extensions feature is not configured May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: UI change-notification feature is not configured May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: Started running translation script |
FAU_GEN.2 |
None |
None |
May 8 23:29:38 mgd[19298]: UI_AUTH_EVENT: Authenticated user 'crypto-officer' assigned to class 'j-super-user' May 8 23:29:38 mgd[19298]: UI_LOGIN_EVENT: User 'crypto-officer' login, class 'j-super-user' [19298], ssh-connection '', client-mode 'cli'
May 8 23:30:49 mgd[19298]: UI_DBASE_LOGIN_EVENT: User 'crypto-officer' entering configuration mode May 8 23:31:06 mgd[19298]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'set system login message "this is a ndcpp test box" ' May 8 23:31:09 mgd[19298]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'commit '
May 8 23:35:06 mgd[20830]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'start shell ' May 8 23:35:31 ssh-keygen[20913]: Generated SSH key file /var/home/crypto-officer/.ssh/id_rsa.pub with fingerprint SHA256:iqrLYhPTXD4KhYOeuL+tD8odyYUb/G2O+Fzk9InzZeg
May 8 23:42:38 mgd[22907]: UI_CFG_AUDIT_SET: User 'crypto-officer' set: [system root-authentication] unconfigured -- "plain-text-password" May 8 23:42:44 mgd[22907]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'set system root-authentication plain-text-password ' May 8 23:42:46 mgd[22907]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'commit ' May 8 23:42:46 mgd[22907]: UI_COMMIT: User 'crypto-officer' requested 'commit' operation (comment: none) May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: Obtaining lock for commit May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: updating commit revision May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: UI extensions feature is not configured May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: UI change-notification feature is not configured May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: Started running translation script |
FAU_STG_EXT.1 |
Configuration of local audit settings. |
Identity of account making changes to the audit configuration. |
May 19 22:11:47 host mgd[13786]: UI_CFG_AUDIT_SET: User 'crypto-officer' set: [groups global system syslog file security user] unconfigured -- "any" May 19 22:11:47 host mgd[13786]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'set user any ' May 19 22:11:49 host mgd[13786]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'commit ' May 19 22:11:49 host mgd[13786]: UI_COMMIT: User 'crypto-officer' requested 'commit' operation (comment: none) May 19 22:11:49 host mgd[13786]: UI_COMMIT_PROGRESS: Commit operation in progress: Obtaining lock for commit May 19 22:11:49 host mgd[13786]: UI_COMMIT_PROGRESS: Commit operation in progress: updating commit revision |
FAU_STG.1 |
None |
None |
|
FCS_CKM.1 |
None |
None |
|
FCS_CKM.2 |
None |
None |
|
FCS_CKM.4 |
None |
None |
|
FCS_COP.1/DataEncryption |
None |
None |
|
FCS_COP.1/SigGen |
None |
None |
|
FCS_COP.1/Hash |
None |
None |
|
FCS_COP.1/KeyedHash |
None |
None |
|
FCS_RBG_EXT.1 |
None |
None |
|
FIA_PMG_EXT.1 |
None |
None |
Passwords shall be able to be composed of any combination of upper and lower case letters, numbers and the following special characters: [selection: "!", "@", "#", "$", "%", "^", "&", "*", "(", ")", [assignment: other characters]]; crypto-officer@host:fips# set system login user crypto-officer authentication plain-text-password New password: error: minimum password length is 10 error: require use of 3 character sets: upper lower digit punctuation other |
FIA_UIA_EXT.1 |
All use of identification and authentication mechanism. |
Origin of the attempt (e.g., IP address) |
Successful Local Login Banner example log: login: This is a protected device. If you are not authorized to connect, please disconnect immediately. Please contact 111-111-111 or ab123@123.net for assistance.
FreeBSD/i386 (hostname) (ttyu0)
login:
386 (host) (ttyu0)
login: cli Password: Login incorrect login: login: root Password: Last login: Tue May 13 22:38:08 on ttyu0
--- JUNOS 24.2R2.10 Kernel 64-bit _ At least one package installed on this device has limited support. Run 'file show /etc/notices/unsupported.txt' for details. root@host-01:RE:0% cli {master:0} root@host:fips> Jan 3 09:59:36 login[7637]: LOGIN_INFORMATION: User root logged in from host [unknown] on device ttyu0 Jan 3 09:59:36 login[7637]: LOGIN_ROOT: User root logged in as root from host [unknown] on device ttyu0 Unsuccessful Local Login Jan 3 09:57:52 login[7637]: LOGIN_PAM_AUTHENTICATION_ERROR: Failed password for user root Jan 3 09:57:52 login[7637]: LOGIN_FAILED: Login failed for user root from host ttyu0 Successful Remote Login Jan 3 09:32:07 mgd[47035]: UI_AUTH_EVENT: Authenticated user 'test1' assigned to class 'j-read-only' Jan 3 09:32:07 mgd[47035]: UI_LOGIN_EVENT: User 'test1' login, class 'j-read-only' [47035], ssh-connection '10.1.5.153 36784 10.1.2.68 22', client-mode 'cli' Unsuccessful Remote Login Jan 3 09:26:56 sshd: SSHD_LOGIN_FAILED: Login failed for user 'test1' from host '10.1.5.153' |
FIA_UAU.7 |
None |
None |
|
FMT_MOF.1/ManualUpdate |
Any attempt to initiate a manual update |
None |
|
FMT_MTD.1/CoreData |
None |
None |
|
FMT_SMF.1 |
All management activities of TSF data |
None |
Refer to the audit events listed in this table. |
FMT_SMR.2 |
None |
None |
|
FPT_SKP_EXT.1 |
None |
None |
|
FPT_APW_EXT.1 |
None |
None |
|
FPT_TUD_EXT.1 |
Initiation of update; result of the update attempt (success or failure) |
None |
mgd[23878]: UI_CMDLINE_READ_LINE: User 'root', command 'request system software add /var/tmp/junos-install-ex-x86-64-24.2R2.tgz root@host> show log install 2025-09-19 05:34:40 PDT mgd[22133]: /usr/libexec/ui/package -X update /var/tmp/fips-optest-x86-32-24.2R2.18-bsd15.tgz<output> Verified fips-optest-x86-32-24.2R2.18-bsd15 signed by PackageProductionECP256_2025 method ECDSA256+SHA256</output><package-result>0</package-result> |
FTA_SSL_EXT.1 (if “terminate the session is selected) |
The termination of a local session by the session lock. |
None |
user@linuxhost:~$ssh crypto-officer@host login: crypto-officer Password: Last login: Tue May 13 23:47:40 on ttyu0 --- JUNOS 24.2R2 Kernel 64-bit JNPR-15.0-20250502.32ed862a0f7_ {master:0} crypto-officer@host:fips> Warning: session will be closed in 1 minute if there is no activity Warning: session will be closed in 10 seconds if there is no activity Idle timeout exceeded: closing session
Connection to host closed. user@linuxhost:~$ |
FTA_SSL.3 |
The termination of a remote session by the session locking mechanism. |
None |
Jan 3 11:26:23 cli: UI_CLI_IDLE_TIMEOUT: Idle timeout for user 'root' exceeded and session terminated |
FTA_SSL.4 |
The termination of an interactive session. |
None |
Local Jan 3 11:47:25 mgd[52521]: UI_LOGOUT_EVENT: User 'root' logout Remote Jan 3 11:43:33 sshd[52425]: Received disconnect from 10.1.5.153 port 36800:11: disconnected by user |
FTA_TAB.1 |
None |
None |
|
FTP_ITC.1 |
|
|
Initiation of the trusted path Jan 3 12:09:00 sshd[53492]: Accepted keyboard-interactive/pam for root from 10.1.5.153 port 36802 ssh2 Termination of the trusted path Jan 3 12:09:03 sshd[53492]: Received disconnect from 10.1.5.153 port 36802:11: disconnected by user Jan 3 12:09:36 sshd: Failure of the trusted path SSHD_LOGIN_FAILED: Login failed for user 'root' from host '10.1.5.153' |
FTP_TRP.1/Admin |
|
|
Initiation of the trusted path Jan 3 12:09:00 sshd[53492]: Accepted keyboard-interactive/pam for root from 10.1.5.153 port 36802 ssh2 Termination of the trusted path Jan 3 12:09:03 sshd[53492]: Received disconnect from 10.1.5.153 port 36802:11: disconnected by user Jan 3 12:09:36 sshd: Failure of the trusted path SSHD_LOGIN_FAILED: Login failed for user 'root' from host '10.1.5.153' |
FCS_SSHS_EXT.1 |
None |
None |
sshd 72404 - - Unable to negotiate with 1.1.1.2 port 42168: no matching cipher found. Their offer: chacha20-poly1305@openssh.com, aes128-ctr, aes256-ctr, aes128-gcm@openssh.com, aes256-gcm@openssh.com, aes128-cbc, aes256-cbc |
|
FCS_SSH_EXT.1 |
|
|
|
FMT_MOF.1/Functions |
None |
None |
|
FMT_MOF.1/Services |
None |
None |
|
FMT_MTD.1/CryptoKeys |
None |
None |
|
FCS_MACSEC_EXT.1 |
Session establishment |
Secure Channel Identifier (SCI) |
Apr 10 20:43:35 dot1xd[6622]: DOT1XD_MKA_SECURE_CHANNEL_CREATED: Macsec receive secure channel created for 64:87:88:5a :19:30 on interface xe-0/0/0 |
FCS_MACSEC_EXT.3 |
Creation and update of Secure Association Key |
Creation and update times |
Jan 28 10:49:16.505519 macsec_is_sak_has_128bit_forced: ca context : fips-ca-1 found for ifd ge-0/0/47 Jan 28 10:49:16.505531 macsec_util_generate_sak_hash: sak_key_bits value 256 Jan 28 10:49:16.986810 macsec_set_sa_msg_gencfg_data: ifdx:697 iflx:0 is_ifl:0 key:ge-0/0/47-SA-TX-AN-1 len:164 an:1 sak-hash:21:8e:8e:c1:44:06:5a:73:93:c2:55:da:a7:2b:d2:38 Jan 28 10:49:16.986917 macsec_set_sa_msg_gencfg_data: ifdx:697 iflx:0 is_ifl:0 key:ge-0/0/47-SA-RX-AN-1 len:164 an:1 sak-hash:21:8e:8e:c1:44:06:5a:73:93:c2:55:da:a7:2b:d2:38 |
FCS_MACSEC_EXT.4 |
Creation of Connectivity Association |
Connectivity Association Key Names (CKNs) |
Sep 9 10:49:16.987221 DOT1XD_MACSEC_SC_PRIMARY_CAK_IN_USE: ifd: ge-0/0/47 primary cak: 0123456789 is in-use Sep 9 10:49:22.058079 DOT1XD_MACSEC_SC_CAK_ACTIVATED: ifd: ge-0/0/47 sci-out:F8C116409CB20001 sci-in:68228E6E96A20001 cak: 0123456789 |
|
FCS_NTP_EXT.1 |
|
Identify if new/removed time server |
unconfiguring ntp Sep 14 09:53:13 2025 xntpd[16061]: sig 1Sep 14 09:53:13 2025 xntpd[16061]: 172.29.147.60 local addr 0.0.0.0 -><null> after configuring ntp Jan 1 00:00:40 2025 xntpd[16061]: proto: precision = 0.126 usec (-23)Jan 1 00:00:40 2025 xntpd[16061]: GGSN RE Option SetJan 1 00:00:40 2025 xntpd[16061]: Junos Key file processingJan 1 00:00:40 2025 xntpd[16061]: basedate set to 2018-08-07Jan 1 00:00:40 2025 xntpd[16061]: gps base set to 2018-08-12 (week 2014)Jan 1 00:00:40 2025 xntpd[16061]: Listen normally on 0 v6wildcard [::]:123Jan 1 00:00:40 2025 xntpd[16061]: Listen normally on 1 v4wildcard 0.0.0.0:123Jan 1 00:00:40 2025 xntpd[16061]: Listen normally on 2 ggsn_vpn 128.0.0.1:123Jan 1 00:00:40 2025 xntpd[16061]: peer_config 636 cast_flags 0x1Jan 1 00:00:40 2025 xntpd[16061]: kernel reports TIME_ERROR: 0x2041: Clock UnsynchronizedJan 1 00:00:40 2025 xntpd[16061]: kernel reports TIME_ERROR: 0x2041: Clock UnsynchronizedJan 1 00:00:44 2025 mgd[85100]: UI_CMDLINE_READ_LINE: User 'root', command 'run show system uptime local 'Jan 1 00:00:44 2025 mgd[85100]: UI_CHILD_START: Starting child '/usr/libexec/ui/ntpsync'Jan 1 00:00:44 2025 mgd[85100]: UI_CHILD_STATUS: Cleanup child '/usr/libexec/ui/ntpsync', PID 15996, status 0Jan 1 00:00:44 2025 mgd[85100]: UI_CHILD_START: Starting child '/usr/libexec/ui/uptime'Jan 1 00:00:44 2025 mgd[85100]: UI_CHILD_STATUS: Cleanup child '/usr/libexec/ui/uptime', PID 16003, status 0Sep 14 09:58:17 2025 xntpd[16061]: ntpd: time reset +22150650.528988 sSep 14 09:58:17 2025 xntpd: NTPD_CHANGED_TIME: time reset +22150650.528988 s |
|
FIA_AFL.1.1 |
Unsuccessful login attempts limit is met or exceeded. |
Origin of the attempt (e.g., IP address). |
May 14 03:41:14 sshd[9673]: error: PAM: Authentication error for crypto-officer from 10.220.208.12 May 14 03:41:14 sshd: SSHD_LOGIN_FAILED: Login failed for user 'crypto-officer' from host '10.220.208.12' May 14 03:41:25 sshd: PAM_UNIX_LOC_PASSWD_AUTH: local password authentication of user 'crypto-officer' failed May 14 03:41:25 sshd: PAM_USER_LOCK_USER: (pam_sm_authenticate): DEBUG: PAM_USER: crypto-officer May 14 03:41:25 sshd: PAM_USER_LOCK_UPD_LOCK_ATTEMPTS: (pam_sm_authenticate): DEBUG: Updating lock-attempts of user: crypto-officer attempts: 4 May 14 03:41:25 sshd: LIBJNX_LOGIN_ACCOUNT_LOCKED: Account for user 'crypto-officer' has been locked out from logins
May 14 03:41:25 sshd[9673]: Failed password for crypto-officer from 10.220.208.12 port 37949 ssh2
May 14 03:41:45 sshd: SSHD_LOGIN_ATTEMPTS_THRESHOLD: Threshold for unsuccessful authentication attempts (4) reached by user 'crypto-officer' May 14 03:41:45 sshd[9673]: Disconnecting authenticating user crypto-officer 10.220.208.12 port 37949: Too many password failures for crypto-officer [preauth] |
|
FIA_AFL.1.2 |
Unsuccessful login attempts limit is met or exceeded. |
Origin of the attempt (e.g., IP address). |
account is unlocked: May 14 03:46:54 sshd: PAM_USER_LOCK_USER: (pam_sm_authenticate): DEBUG: PAM_USER: crypto-officer May 14 03:46:54 sshd: PAM_USER_LOCK_USER: (pam_sm_acct_mgmt): DEBUG: PAM_USER: crypto-officer May 14 03:46:54 sshd: LIBJNX_LOGIN_ACCOUNT_UNLOCKED: Account for user 'crypto-officer' has been unlocked for logins |
FPT_RPL.1 |
Detected replay attempt |
None |
Apr 15 10:05:16.142910 MKA actor #0 received duplicate or delayed PDU Apr 15 10:05:16.142932 MKA actor #0 received MKPDU, SCI 3C:94:D5:A0:A0:07/1, MI 27:D7:9F:97:53:CF:EF:86:00:52:C1:78, MN 1530 |
|
FPT_STM_EXT.1 |
Discontinuous changes to time - either Administrator actuated or changed via an automated process. (Note that no continuous changes to time need to be logged. See also application note on FPT_STM_EXT.1) |
For discontinuous changes to time: The old and new values for the time. Origin of the attempt to change time for success and failure (e.g., IP address). |
mgd 71079 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.164 username="root" command="set date 202005201815.00 "] User 'root', command 'set date 202005201815.00' mgd 71079 UI_COMMIT_PROGRESS [junos@2636.1.1.1.2.164 message="signaling 'Network security daemon', pid 2641, signal 31, status 0 with notification errors enabled"] Commit operation in progress: signaling 'Network security daemon', pid 2641, signal 31, status 0 with notification errors enabled nsd 2641 NSD_SYS_TIME_CHANGE - System time has changed Below is the syslog message when time is updated by NTP: Oct 9 00:00:44 2025 xntpd[16061]: ntpd 4.2.8p15-a Fri Feb 21 09:42:25 2025 (1): StartingOct 9 00:00:44 2025 xntpd[16061]: Command line: /usr/sbin/xntpd -j -N -gSep 9 21:21:12 2025 xntpd[16061]: ntpd: time reset -2515178.383628 s |
|
FPT_TST_EXT.1 |
None |
None |
Enter |
|
Note:
If there is a self-test error, you can recover the device via USB recovery. If USB recovery fails, you can contact JTAC for support (https://support.juniper.net/support/). Note:
The status of a package installation or deletion is updated
in the |
|||