Logs relating to the privilegedprivatekeydecrypt API route

The fields described below belong to logs concerning the privilegedprivatekeydecrypt API route. A Google administrator calls up this privileged route to decrypt an encrypted email, for example via the Google decrypter.exe utility.

Field

Description

Type

Example

 

api_route

URL slug of the API route.

String

"/api/v1{tenantId}/privilegedprivatekeydecrypt"

user_agent

User agent used in the request.

String

"Chrome/27.0.1453.110"

source_address

Network traffic source (client requesting the connection).

String

"172.16.16.212"

http_status

HTTP response code that indicates the status of the request to the proxy.

Integer

Prescribed values:

"200", "400", "401", "405", "413", "415", "500"

request_payload

Data relating to the HTTP request.

Object


  reason

JSON string providing additional context about the operation. 

String

"Command-line decrypter"

authentication_token

JWT generated by a third-party tool that guarantees the user’s identity.

It contains the information below:

Object


 

claims: standard user data provided by the IDP.

  • email: e-mail address of the user that the authentication token concerns.

  • google_email: email address of the Google account of the user that the authentication token concerns.

  • iss: identifies the service that generates the JWT (issuer).

  • aud: identifies the recipient of the JWT (audience).

  • exp: identifies the expiry time after which the JWT must no longer be accepted.

  • iat: identifies the date on which the JWT was created (issued at).

 

 

 

String

 

String

String array

Integer (timestamp in seconds)

 

Integer (timestamp in seconds)

 

 

 

"username@domain.eu"

 

 

"www.onelogin.com"

 

"s6BhdRkqt3"

 

 

"1694617320"

 

 

"1694617320"

 

number_of_custom_claims: number of custom claims included in the authentication token.

Integer

2

additional_data

Additional data.
It contains the information below:

Object


   

wrap_properties: data relating to the wrap operation.

Object


 

kek_id: identifier of the KEK used.

String

"80c65a46-33db-4f26-bfe3-cefbbb4f16d8"

        

version: version of the wrap operation.

Integer

1

       

mode: mode used for the wrap operation.

  • persistence: persistence mode used

Object

 

 

String

 

 

 

 

"json_file", "kms""

        

cse_version: version of the service during the wrap operation.

String

"4.1.1637-0.2.beta"

  key_name : name of the private key used by the KMS to sign in 'kms' mode.

String

38cf0196-1fbf-11ee-be56-0242ac120002div>
  crypto_mode: type of cryptographic backend used to decrypt session keys.

String

"kms" or "node"

  supported_algorithms: encryption and signature algorithms used with this key. String array
["RSA/ECB/PKCS1Padding","RSA/ECB/OAEPwithSHA-1andMGF1Padding","RSA/ECB/OAEPwithSHA-256andMGF1Padding","RSA/ECB/OAEPwithSHA-512andMGF1Padding","SHA1withRSA","SHA256withRSA","SHA1withRSA/PSS","SHA256withRSA/PSS","SHA512withRSA/PSS"]