Sample Code Audits of Configuration Changes

This sample code audits all changes to the configuration secret data and sends the logs to a file named messages:

This sample code expands the scope of the minimum audit to audit all changes to the configuration, not just secret data, and sends the logs to a file named messages:

Example: System Logging of Configuration Changes

This example shows a sample configuration and makes changes to users and secret data.

The new configuration changes the secret data configuration statements and adds a new user.

Table 1 shows sample for syslog auditing for NDcPPv3.0e:

Table 1: Auditable Events

Requirement

Auditable Events

Additional Audit Record Contents

How event generated

FAU_GEN.1

None

None

May 19 21:43:16 host eventd[7841]: SYSTEM_OPERATIONAL: System is operational

May 19 21:43:17 host jlaunchd[8318]: Found pid 7842 for already running process: eventd

May 8 23:29:38 mgd[19298]: UI_AUTH_EVENT: Authenticated user 'crypto-officer' assigned to class 'j-super-user'

May 8 23:29:38 mgd[19298]: UI_LOGIN_EVENT: User 'crypto-officer' login, class 'j-super-user' [19298], ssh-connection '', client-mode 'cli'

May 8 23:30:49 mgd[19298]: UI_DBASE_LOGIN_EVENT: User 'crypto-officer' entering configuration mode

May 8 23:31:06 mgd[19298]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'set system login message "this is a ndcpp test box" '

May 8 23:31:09 mgd[19298]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'commit '

May 8 23:35:06 mgd[20830]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'start shell '

May 8 23:35:31 ssh-keygen[20913]: Generated SSH key file /var/home/crypto-officer/.ssh/id_rsa.pub with fingerprint SHA256:iqrLYhPTXD4KhYOeuL+tD8odyYUb/G2O+Fzk9InzZeg

May 8 23:42:38 mgd[22907]: UI_CFG_AUDIT_SET: User 'crypto-officer' set: [system root-authentication] unconfigured -- "plain-text-password"

May 8 23:42:44 mgd[22907]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'set system root-authentication plain-text-password '

May 8 23:42:46 mgd[22907]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'commit '

May 8 23:42:46 mgd[22907]: UI_COMMIT: User 'crypto-officer' requested 'commit' operation (comment: none)

May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: Obtaining lock for commit

May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: updating commit revision

May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: UI extensions feature is not configured

May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: UI change-notification feature is not configured

May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: Started running translation script

FAU_GEN.2

None

None

May 8 23:29:38 mgd[19298]: UI_AUTH_EVENT: Authenticated user 'crypto-officer' assigned to class 'j-super-user'

May 8 23:29:38 mgd[19298]: UI_LOGIN_EVENT: User 'crypto-officer' login, class 'j-super-user' [19298], ssh-connection '', client-mode 'cli'

May 8 23:30:49 mgd[19298]: UI_DBASE_LOGIN_EVENT: User 'crypto-officer' entering configuration mode

May 8 23:31:06 mgd[19298]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'set system login message "this is a ndcpp test box" '

May 8 23:31:09 mgd[19298]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'commit '

May 8 23:35:06 mgd[20830]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'start shell '

May 8 23:35:31 ssh-keygen[20913]: Generated SSH key file /var/home/crypto-officer/.ssh/id_rsa.pub with fingerprint SHA256:iqrLYhPTXD4KhYOeuL+tD8odyYUb/G2O+Fzk9InzZeg

May 8 23:42:38 mgd[22907]: UI_CFG_AUDIT_SET: User 'crypto-officer' set: [system root-authentication] unconfigured -- "plain-text-password"

May 8 23:42:44 mgd[22907]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'set system root-authentication plain-text-password '

May 8 23:42:46 mgd[22907]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'commit '

May 8 23:42:46 mgd[22907]: UI_COMMIT: User 'crypto-officer' requested 'commit' operation (comment: none)

May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: Obtaining lock for commit

May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: updating commit revision

May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: UI extensions feature is not configured

May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: UI change-notification feature is not configured

May 8 23:42:46 mgd[22907]: UI_COMMIT_PROGRESS: Commit operation in progress: Started running translation script

FAU_STG_EXT.1

Configuration of local audit settings.

Identity of account making changes to the audit configuration.

May 19 22:11:47 host mgd[13786]: UI_CFG_AUDIT_SET: User 'crypto-officer' set: [groups global system syslog file security user] unconfigured -- "any"

May 19 22:11:47 host mgd[13786]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'set user any '

May 19 22:11:49 host mgd[13786]: UI_CMDLINE_READ_LINE: User 'crypto-officer', command 'commit '

May 19 22:11:49 host mgd[13786]: UI_COMMIT: User 'crypto-officer' requested 'commit' operation (comment: none)

May 19 22:11:49 host mgd[13786]: UI_COMMIT_PROGRESS: Commit operation in progress: Obtaining lock for commit

May 19 22:11:49 host mgd[13786]: UI_COMMIT_PROGRESS: Commit operation in progress: updating commit revision

FAU_STG.1

None

None

FCS_CKM.1

None

None

FCS_CKM.2

None

None

FCS_CKM.4

None

None

FCS_COP.1/DataEncryption

None

None

FCS_COP.1/SigGen

None

None

FCS_COP.1/Hash

None

None

FCS_COP.1/KeyedHash

None

None

FCS_RBG_EXT.1

None

None

FIA_PMG_EXT.1

None

None

Passwords shall be able to be composed of any combination of upper and lower

case letters, numbers and the following special characters: [selection: "!", "@",

"#", "$", "%", "^", "&", "*", "(", ")", [assignment: other characters]];

crypto-officer@host:fips# set system login user crypto-officer authentication plain-text-password

New password:

error: minimum password length is 10

error: require use of 3 character sets: upper lower digit punctuation other

FIA_UIA_EXT.1

All use of identification and authentication mechanism.

Origin of the attempt (e.g., IP address)

Successful Local Login

Banner example log:

login:

This is a protected device.

If you are not authorized to connect, please disconnect immediately.

Please contact 111-111-111 or ab123@123.net for assistance.

FreeBSD/i386 (hostname) (ttyu0)

login:

386 (host) (ttyu0)

login: cli
Password:
Login incorrect
login:
login: root
Password:
Last login: Tue May 13 22:38:08 on ttyu0

--- JUNOS 24.2R2.10 Kernel 64-bit _
At least one package installed on this device has limited support.
Run 'file show /etc/notices/unsupported.txt' for details.
root@host-01:RE:0% cli
{master:0}
root@host:fips>

Jan 3 09:59:36 login[7637]: LOGIN_INFORMATION: User root logged in from host [unknown] on device ttyu0

Jan 3 09:59:36 login[7637]: LOGIN_ROOT: User root logged in as root from host [unknown] on device ttyu0

Unsuccessful Local Login

Jan 3 09:57:52 login[7637]: LOGIN_PAM_AUTHENTICATION_ERROR: Failed password for user root

Jan 3 09:57:52 login[7637]: LOGIN_FAILED: Login failed for user root from host ttyu0

Successful Remote Login

Jan 3 09:32:07 mgd[47035]: UI_AUTH_EVENT: Authenticated user 'test1' assigned to class 'j-read-only' Jan 3 09:32:07 mgd[47035]: UI_LOGIN_EVENT: User 'test1' login, class 'j-read-only' [47035], ssh-connection '10.1.5.153 36784 10.1.2.68 22', client-mode 'cli'

Unsuccessful Remote Login

Jan 3 09:26:56 sshd: SSHD_LOGIN_FAILED: Login failed for user 'test1' from host '10.1.5.153'

FIA_UAU.7

None

None

FMT_MOF.1/ManualUpdate

Any attempt to initiate a manual update

None

mgd[23878]: UI_CMDLINE_READ_LINE: User 'root', command 'request system software add /var/tmp/junos-install-ex-x86-64-24.2R2.tgz

FMT_MTD.1/CoreData

None

None

FMT_SMF.1

All management activities of TSF data

None

Refer to the audit events listed in this table.

FMT_SMR.2

None

None

FPT_SKP_EXT.1

None

None

FPT_APW_EXT.1

None

None

FPT_TUD_EXT.1

Initiation of update; result of the update attempt (success or failure)

None

mgd[23878]: UI_CMDLINE_READ_LINE: User 'root', command 'request system software add /var/tmp/junos-install-ex-x86-64-24.2R2.tgz

root@host> show log install 2025-09-19 05:34:40 PDT mgd[22133]: /usr/libexec/ui/package -X update /var/tmp/fips-optest-x86-32-24.2R2.18-bsd15.tgz<output> Verified fips-optest-x86-32-24.2R2.18-bsd15 signed by PackageProductionECP256_2025 method ECDSA256+SHA256</output><package-result>0</package-result>

FTA_SSL_EXT.1 (if “terminate the session is selected)

The termination of a local session by the session lock.

None

user@linuxhost:~$ssh crypto-officer@host

login: crypto-officer

Password:

Last login: Tue May 13 23:47:40 on ttyu0

--- JUNOS 24.2R2 Kernel 64-bit JNPR-15.0-20250502.32ed862a0f7_

{master:0}

crypto-officer@host:fips>

Warning: session will be closed in 1 minute if there is no activity

Warning: session will be closed in 10 seconds if there is no activity

Idle timeout exceeded: closing session

Connection to host closed.

user@linuxhost:~$

FTA_SSL.3

The termination of a remote session by the session locking mechanism.

None

Jan 3 11:26:23 cli: UI_CLI_IDLE_TIMEOUT: Idle timeout for user 'root' exceeded and session terminated

FTA_SSL.4

The termination of an interactive session.

None

Local

Jan 3 11:47:25 mgd[52521]: UI_LOGOUT_EVENT: User 'root' logout

Remote

Jan 3 11:43:33 sshd[52425]: Received disconnect from 10.1.5.153 port 36800:11: disconnected by user

FTA_TAB.1

None

None

FTP_ITC.1

  • Initiation of the trusted channel.

  • Termination of the trusted channel.

  • Failure of the trusted channel functions.

  • None

  • None

  • Reason for failure.

Initiation of the trusted path

Jan 3 12:09:00 sshd[53492]: Accepted keyboard-interactive/pam for root from 10.1.5.153 port 36802 ssh2

Termination of the trusted path

Jan 3 12:09:03 sshd[53492]: Received disconnect from 10.1.5.153 port 36802:11: disconnected by user Jan 3 12:09:36 sshd:

Failure of the trusted path

SSHD_LOGIN_FAILED: Login failed for user 'root' from host '10.1.5.153'

FTP_TRP.1/Admin

  • Initiation of the trusted channel.

  • Termination of the trusted channel.

  • Failure of the trusted channel functions.

  • None

  • None

  • Reason for failure.

Initiation of the trusted path

Jan 3 12:09:00 sshd[53492]: Accepted keyboard-interactive/pam for root from 10.1.5.153 port 36802 ssh2

Termination of the trusted path

Jan 3 12:09:03 sshd[53492]: Received disconnect from 10.1.5.153 port 36802:11: disconnected by user Jan 3 12:09:36 sshd:

Failure of the trusted path

SSHD_LOGIN_FAILED: Login failed for user 'root' from host '10.1.5.153'

FCS_SSHS_EXT.1

None

None

sshd 72404 - - Unable to negotiate with 1.1.1.2 port 42168: no matching cipher found. Their offer: chacha20-poly1305@openssh.com, aes128-ctr, aes256-ctr, aes128-gcm@openssh.com, aes256-gcm@openssh.com, aes128-cbc, aes256-cbc

FCS_SSH_EXT.1

  • Failure to establish an SSH session

  • Establishment of SSH connection

  • Termination of SSH connection session

  • Droping of packet(s) outsize defined size limits

  • Reason for failure

  • Non-TOE endpoint of connection (IP address)

  • Non-TOE endpoint of connection (IP address)

  • Packet size

  • crypto-officer@toby-shell:~$ ssh -o "userknownhostsfile /dev/null" crypto-officer@host

    Warning: Permanently added 'host,10.204.33.5' (ECDSA) to the list of known hosts.

    This is a protected device. If you are not authorized to connect, please disconnect immediately. Please contact 111-111-111 or ab123@123.net for assistance

    Password:

    Password:

    Password:

    crypto-officer@host's password:

    Received disconnect from 10.204.33.5 port 22:2: Too many password failures for crypto-officer Disconnected from 10.204.33.5 port 22

    On the TOE below syslog messages are seen:

    Sep 9 21:02:32 2025 sshd: PAM_UNIX_LOC_PASSWD_AUTH: local password authentication of user 'crypto-officer' failed

    Sep 9 21:02:32 2025 sshd[33070]: error: PAM: Authentication error for crypto-officer from 10.220.212.12

    Sep 9 21:02:32 2025 sshd: SSHD_LOGIN_FAILED: Login failed for user 'crypto-officer' from host '10.220.212.12'

  • successful login :

    Last login: Tue May 13 23:35:43 2025 from 10.220.208.12

    --- JUNOS 24.2R2 Kernel 64-bit JNPR-15.0-20250502.32ed862a0f7_

    At least one package installed on this device has limited support.

    Run 'file show /etc/notices/unsupported.txt' for details.

    {master:0}

  • disconnection log:

    crypto-officer@host:fips> exit

    Connection to host closed.

FMT_MOF.1/Functions

None

None

FMT_MOF.1/Services

None

None

FMT_MTD.1/CryptoKeys

None

None

FCS_MACSEC_EXT.1

Session establishment

Secure Channel Identifier (SCI)

Apr 10 20:43:35 dot1xd[6622]: DOT1XD_MKA_SECURE_CHANNEL_CREATED: Macsec receive secure channel created for 64:87:88:5a :19:30 on interface xe-0/0/0

FCS_MACSEC_EXT.3

Creation and update of Secure Association Key

Creation and update times

Jan 28 10:49:16.505519 macsec_is_sak_has_128bit_forced: ca context : fips-ca-1 found for ifd ge-0/0/47

Jan 28 10:49:16.505531 macsec_util_generate_sak_hash: sak_key_bits value 256

Jan 28 10:49:16.986810 macsec_set_sa_msg_gencfg_data: ifdx:697 iflx:0 is_ifl:0 key:ge-0/0/47-SA-TX-AN-1 len:164 an:1 sak-hash:21:8e:8e:c1:44:06:5a:73:93:c2:55:da:a7:2b:d2:38

Jan 28 10:49:16.986917 macsec_set_sa_msg_gencfg_data: ifdx:697 iflx:0 is_ifl:0 key:ge-0/0/47-SA-RX-AN-1 len:164 an:1 sak-hash:21:8e:8e:c1:44:06:5a:73:93:c2:55:da:a7:2b:d2:38

FCS_MACSEC_EXT.4

Creation of Connectivity Association

Connectivity Association Key Names (CKNs)

Sep 9 10:49:16.987221 DOT1XD_MACSEC_SC_PRIMARY_CAK_IN_USE: ifd: ge-0/0/47 primary cak: 0123456789 is in-use

Sep 9 10:49:22.058079 DOT1XD_MACSEC_SC_CAK_ACTIVATED: ifd: ge-0/0/47 sci-out:F8C116409CB20001 sci-in:68228E6E96A20001 cak: 0123456789

FCS_NTP_EXT.1

  • Configure of a new time server

  • Removal of configured time server

Identify if new/removed time server

unconfiguring ntp

Sep 14 09:53:13 2025 xntpd[16061]: sig 1Sep 14 09:53:13 2025 xntpd[16061]: 172.29.147.60 local addr 0.0.0.0 -><null>

after configuring ntp

Jan 1 00:00:40 2025 xntpd[16061]: proto: precision = 0.126 usec (-23)Jan 1 00:00:40 2025 xntpd[16061]: GGSN RE Option SetJan 1 00:00:40 2025 xntpd[16061]: Junos Key file processingJan 1 00:00:40 2025 xntpd[16061]: basedate set to 2018-08-07Jan 1 00:00:40 2025 xntpd[16061]: gps base set to 2018-08-12 (week 2014)Jan 1 00:00:40 2025 xntpd[16061]: Listen normally on 0 v6wildcard [::]:123Jan 1 00:00:40 2025 xntpd[16061]: Listen normally on 1 v4wildcard 0.0.0.0:123Jan 1 00:00:40 2025 xntpd[16061]: Listen normally on 2 ggsn_vpn 128.0.0.1:123Jan 1 00:00:40 2025 xntpd[16061]: peer_config 636 cast_flags 0x1Jan 1 00:00:40 2025 xntpd[16061]: kernel reports TIME_ERROR: 0x2041: Clock UnsynchronizedJan 1 00:00:40 2025 xntpd[16061]: kernel reports TIME_ERROR: 0x2041: Clock UnsynchronizedJan 1 00:00:44 2025 mgd[85100]: UI_CMDLINE_READ_LINE: User 'root', command 'run show system uptime local 'Jan 1 00:00:44 2025 mgd[85100]: UI_CHILD_START: Starting child '/usr/libexec/ui/ntpsync'Jan 1 00:00:44 2025 mgd[85100]: UI_CHILD_STATUS: Cleanup child '/usr/libexec/ui/ntpsync', PID 15996, status 0Jan 1 00:00:44 2025 mgd[85100]: UI_CHILD_START: Starting child '/usr/libexec/ui/uptime'Jan 1 00:00:44 2025 mgd[85100]: UI_CHILD_STATUS: Cleanup child '/usr/libexec/ui/uptime', PID 16003, status 0Sep 14 09:58:17 2025 xntpd[16061]: ntpd: time reset +22150650.528988 sSep 14 09:58:17 2025 xntpd: NTPD_CHANGED_TIME: time reset +22150650.528988 s

FIA_AFL.1.1

Unsuccessful login attempts limit is met or exceeded.

Origin of the attempt (e.g., IP address).

May 14 03:41:14 sshd[9673]: error: PAM: Authentication error for crypto-officer from 10.220.208.12

May 14 03:41:14 sshd: SSHD_LOGIN_FAILED: Login failed for user 'crypto-officer' from host '10.220.208.12'

May 14 03:41:25 sshd: PAM_UNIX_LOC_PASSWD_AUTH: local password authentication of user 'crypto-officer' failed

May 14 03:41:25 sshd: PAM_USER_LOCK_USER: (pam_sm_authenticate): DEBUG: PAM_USER: crypto-officer

May 14 03:41:25 sshd: PAM_USER_LOCK_UPD_LOCK_ATTEMPTS: (pam_sm_authenticate): DEBUG: Updating lock-attempts of user: crypto-officer attempts: 4

May 14 03:41:25 sshd: LIBJNX_LOGIN_ACCOUNT_LOCKED: Account for user 'crypto-officer' has been locked out from logins

May 14 03:41:25 sshd[9673]: Failed password for crypto-officer from 10.220.208.12 port 37949 ssh2

May 14 03:41:45 sshd: SSHD_LOGIN_ATTEMPTS_THRESHOLD: Threshold for unsuccessful authentication attempts (4) reached by user 'crypto-officer'

May 14 03:41:45 sshd[9673]: Disconnecting authenticating user crypto-officer 10.220.208.12 port 37949: Too many password failures for crypto-officer [preauth]

FIA_AFL.1.2

Unsuccessful login attempts limit is met or exceeded.

Origin of the attempt (e.g., IP address).

account is unlocked:

May 14 03:46:54 sshd: PAM_USER_LOCK_USER: (pam_sm_authenticate): DEBUG: PAM_USER: crypto-officer
May 14 03:46:54 sshd: PAM_USER_LOCK_USER: (pam_sm_acct_mgmt): DEBUG: PAM_USER: crypto-officer
May 14 03:46:54 sshd: LIBJNX_LOGIN_ACCOUNT_UNLOCKED: Account for user 'crypto-officer' has been unlocked for logins

FPT_RPL.1

Detected replay attempt

None

Apr 15 10:05:16.142910 MKA actor #0 received duplicate or delayed PDU Apr 15 10:05:16.142932 MKA actor #0 received MKPDU, SCI 3C:94:D5:A0:A0:07/1, MI 27:D7:9F:97:53:CF:EF:86:00:52:C1:78, MN 1530

FPT_STM_EXT.1

Discontinuous changes to time - either Administrator actuated or changed via an automated process. (Note that no continuous changes to time need to be logged. See also application note on FPT_STM_EXT.1)

For discontinuous changes to time: The old and new values for the time. Origin of the attempt to change time for success and failure (e.g., IP address).

mgd 71079 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.164 username="root" command="set date 202005201815.00 "] User 'root', command 'set date 202005201815.00'

mgd 71079 UI_COMMIT_PROGRESS [junos@2636.1.1.1.2.164 message="signaling 'Network security daemon', pid 2641, signal 31, status 0 with notification errors enabled"] Commit operation in progress: signaling 'Network security daemon', pid 2641, signal 31, status 0 with notification errors enabled nsd 2641 NSD_SYS_TIME_CHANGE - System time has changed

Below is the syslog message when time is updated by NTP:

Oct 9 00:00:44 2025 xntpd[16061]: ntpd 4.2.8p15-a Fri Feb 21 09:42:25 2025 (1): StartingOct 9 00:00:44 2025 xntpd[16061]: Command line: /usr/sbin/xntpd -j -N -gSep 9 21:21:12 2025 xntpd[16061]: ntpd: time reset -2515178.383628 s

 

FPT_TST_EXT.1

None

None

Enter request system fips self-test at command line for on demand self-test. or Reboot the device to view the self-test during start-up.

Note:

If there is a self-test error, you can recover the device via USB recovery.

If USB recovery fails, you can contact JTAC for support (https://support.juniper.net/support/).

Note:

The status of a package installation or deletion is updated in the /var/log/ install file.