Logs relating to the privatekeysign API route
The fields described below belong to logs concerning the privatekeysign API route. Google calls up this route when it encrypts and sends encrypted emails.
|
Field |
Description |
Type |
Example |
|---|---|---|---|
|
api_route |
URL slug of the API route. |
String |
"/api/v1/{tenantId}/privatekeysign"
|
|
user_agent |
User agent used in the request. |
String |
"Chrome/27.0.1453.110" |
|
source_address |
Network traffic source (client requesting the connection). |
String |
"172.16.16.212" |
|
http_status |
HTTP response code that indicates the status of the request to the proxy. |
Integer |
Prescribed values: "200", "400", "401", "405", "413", "415", "500" |
|
request_payload |
Data relating to the HTTP request. |
Object |
|
|
reason |
JSON string providing additional context about the operation. |
String |
"sign email" |
|
authorization_token |
JWT guaranteeing that the user is allowed to wrap a key for ‘resource_name’. It contains the information below: |
Object |
|
|
|
email: e-mail address of the user that the authorization token concerns. |
String |
"username@domain.eu" |
|
|
role: role requested in the authorization token. |
String |
Prescribed value: "signer" |
|
|
resource_name: resource identifier. |
String |
"6Bhds6BhdRkqt3Rkqt36Bhd"
|
|
|
perimeter_id: identifier to conduct verifications of authentication and authorization requests. |
String |
"s6Bhds6BhdRkqt3Rkqt3" |
|
|
kacls_url: URL of the KACLS. |
String |
"https://someserver.eu" |
|
|
iss: identifies the service that generates the JWT (issuer). |
String |
"gsuitecse-tokenissuer-gmail@system.gserviceaccount.com"
|
|
|
aud: identifies the recipient of the JWT (audience). |
String array |
"cse-authorization" |
|
|
exp: identifies the expiry time after which the JWT must no longer be accepted. |
Integer (timestamp in seconds) |
"1694617320" |
|
|
iat: identifies the date on which the JWT was created (issued at). |
Integer (timestamp in seconds) |
"1694617320" |
| spki_hash: digest of the private key in Base64. | String |
"saEz24lohD0HIGjddhscQsdjCQfFBqNHs1crLUE+Kt4="
|
|
| spki_hash_algorithm: encryption algorithm used | String | "SHA-256" | |
| message_id: optional ID of the message to which the signature applies. | String | ||
|
authentication_token |
JWT generated by a third-party tool that guarantees the user’s identity. It contains the information below: |
Object |
|
|
|
claims: standard user data provided by the IDP.
|
String
String String array Integer (timestamp in seconds)
Integer (timestamp in seconds) |
"username@domain.eu"
"www.onelogin.com"
"s6BhdRkqt3"
"1694617320"
"1694617320" |
|
number_of_custom_claims: number of custom claims included in the authentication token. |
Integer |
2 |
|
|
additional_data |
Additional data. |
Object |
|
|
|
wrap_properties: data relating to the wrap operation. |
Object |
|
|
|
kek_id: identifier of the KEK used. |
String |
"80c65a46-33db-4f26-bfe3-cefbbb4f16k8"
|
|
|
version: version of the wrap operation. |
Integer |
"2" |
|
|
mode: Mode used for the wrap operation.
|
Object
String |
"json_file", "kms" |
|
|
cse_version: version of the service during the wrap operation. |
String |
"4.1.1637-0.2.beta" |
| key_name : name of the private key used by the KMS to sign in 'kms' mode. |
String |
38cf0196-1fbf-11ee-be56-0242ac120002
|
|
| crypto_mode: type of cryptographic backend used to decrypt session keys. |
String |
"kms" or "node" |
|
| supported_algorithms: encryption and signature algorithms used with this key. | String array |
["RSA/ECB/PKCS1Padding","RSA/ECB/OAEPwithSHA-1andMGF1Padding","RSA/ECB/OAEPwithSHA-256andMGF1Padding","RSA/ECB/OAEPwithSHA-512andMGF1Padding","SHA1withRSA","SHA256withRSA","SHA512withRSA","SHA1withRSA/PSS","SHA256withRSA/PSS","SHA512withRSA/PSS"]
|