See below for details on logging.

Client logs

These are written to a log file specified in the client configuration or to the following default files.

Default Linux log file
/var/log/entrust/cspp11/client.log
Default Windows log file
<PROGRAMDATA>\Entrust\cspp11\logs\client.log

The client logging level is set with the log_level setting in the client configuration. 

The DEBUG log level includes sensitive information in log files. Use this level only for troubleshooting, then reduce the log level and purge the logs when troubleshooting is complete.

Server logs

Logging on the server is controlled by the following settings in the pkcs11/1.0/server API.  

  • The log_level setting controls logging from the server code and writes log messages to: 
    /var/log/hcs/p11server.log
  • The debug_level setting controls logging from the nCipher libcknfast.so library and writes log messages to: 
    /var/log/hcs/p11server_debug.log

Changing either setting restarts the PKCS#11 server and drops any active client connections. 

log_level DEBUG or debug_level 7 or higher also logs sensitive values.

Both log files are included in a support bundle.