hardcopy device health assessment network access ... · web view2/7/2013 · abstract: this...
TRANSCRIPT
February 7, 2013
Working Draft
The Printer Working Group
Common Log Format(PWG-LOG)
Status: Stable
Abstract: This standard defines a common log format for hardcopy device events that can be used with existing logging protocols such as SYSLOG. While the focus of this format is on security and auditing of devices, it also supports logging of arbitrary events such as those defined by the IPP Event Notifications and Subscriptions (RFC 3995) specification.
Copyright © 2010-2013 The Printer Working Group. All rights reserved.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15161718
February 7, 2013
Working Draft
The Printer Working Group
This document is a PWG Working Draft. For a definition of a "PWG Working Draft", see: ftp://ftp.pwg.org/pub/pwg/general/pwg-process30.pdf
This document is available electronically at:
ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-log10-20130207.docxftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-log10-20130207.pdf
Copyright © 2010-2013 The Printer Working Group. All rights reserved.
1920
21
2223
Stable Draft – PWG Common Log Format February 7, 2013
Copyright © 2010-2013 The Printer Working Group. All rights reserved.
This document may be copied and furnished to others, and derivative works that comment on, or otherwise explain it or assist in its implementation may be prepared, copied, published and distributed, in whole or in part, without restriction of any kind, provided that the above copyright notice, this paragraph and the title of the Document as referenced below are included on all such copies and derivative works. However, this document itself may not be modified in any way, such as by removing the copyright notice or references to the IEEE-ISTO and the Printer Working Group, a program of the IEEE-ISTO.
Title: PWG Common Log Format (PWG-LOG)
The IEEE-ISTO and the Printer Working Group DISCLAIM ANY AND ALL WARRANTIES, WHETHER EXPRESS OR IMPLIED INCLUDING (WITHOUT LIMITATION) ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
The Printer Working Group, a program of the IEEE-ISTO, reserves the right to make changes to the document without further notice. The document may be updated, replaced or made obsolete by other documents at any time.
The IEEE-ISTO takes no position regarding the validity or scope of any intellectual property or other rights that might be claimed to pertain to the implementation or use of the technology described in this document or the extent to which any license under such rights might or might not be available; neither does it represent that it has made any effort to identify any such rights.
The IEEE-ISTO invites any interested party to bring to its attention any copyrights, patents, or patent applications, or other proprietary rights which may cover technology that may be required to implement the contents of this document. The IEEE-ISTO and its programs shall not be responsible for identifying patents for which a license may be required by a document and/or IEEE-ISTO Industry Group Standard or for conducting inquiries into the legal validity or scope of those patents that are brought to its attention. Inquiries may be submitted to the IEEE-ISTO by e-mail at: [email protected].
The Printer Working Group acknowledges that the IEEE-ISTO (acting itself or through its designees) is, and shall at all times, be the sole entity that may authorize the use of certification marks, trademarks, or other special designations to indicate compliance with these materials.
Page 3 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
24
25262728293031
32
33343536
373839
4041424344
45464748495051
52535455
Stable Draft – PWG Common Log Format February 7, 2013
Use of this document is wholly voluntary. The existence of this document does not imply that there are no other ways to produce, test, measure, purchase, market, or provide other goods and services related to its scope.
Page 4 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
565758
59
Stable Draft – PWG Common Log Format February 7, 2013
About the IEEE-ISTO
The IEEE-ISTO is a not-for-profit corporation offering industry groups an innovative and flexible operational forum and support services. The IEEE-ISTO provides a forum not only to develop standards, but also to facilitate activities that support the implementation and acceptance of standards in the marketplace. The organization is affiliated with the IEEE (http://www.ieee.org/) and the IEEE Standards Association (http://standards.ieee.org/).
For additional information regarding the IEEE-ISTO and its industry programs visit:
http://www.ieee-isto.org.
About the IEEE-ISTO PWG
The Printer Working Group (or PWG) is a Program of the IEEE Industry Standards and Technology Organization (ISTO) with member organizations including printer manufacturers, print server developers, operating system providers, network operating systems providers, network connectivity vendors, and print management application developers. The group is chartered to make printers and the applications and operating systems supporting them work together better. All references to the PWG in this document implicitly mean “The Printer Working Group, a Program of the IEEE ISTO.” In order to meet this objective, the PWG will document the results of their work as open standards that define print related protocols, interfaces, procedures and conventions. Printer manufacturers and vendors of printer related software will benefit from the interoperability provided by voluntary conformance to these standards.
In general, a PWG standard is a specification that is stable, well understood, and is technically competent, has multiple, independent and interoperable implementations with substantial operational experience, and enjoys significant public support.
For additional information regarding the Printer Working Group visit:
http://www.pwg.org
Contact information:
The Printer Working Groupc/o The IEEE Industry Standards and Technology Organization445 Hoes LanePiscataway, NJ 08854
Page 5 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
60
616263646566
67
68
69
7071727374757677787980
818283
84
85
86
87888990
Stable Draft – PWG Common Log Format February 7, 2013
USA
Page 6 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
91
92
Stable Draft – PWG Common Log Format February 7, 2013
About the Imaging Device Security Work Group
The Imaging Device Security (IDS) working group is chartered to enable Hardcopy Device support in the Network Assessment Protocols that measure and assess the health of client computers and other devices that are attached to enterprise class networks.
For additional information regarding IDS visit:
http://www.pwg.org/ids/
Implementers of this specification are encouraged to join the IDS Mailing List in order to participate in any discussions of the specification. Suggested additions, changes, or clarification to this specification, should be sent to the IDS Mailing list for consideration.
Page 7 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
93
949596
97
98
99100101
102
Stable Draft – PWG Common Log Format February 7, 2013
Table of Contents
1. Introduction......................................................................................................................7
2. Terminology.....................................................................................................................7
2.1 Conformance Terminology.........................................................................................7
2.2 Other Terminology.....................................................................................................7
2.3 Acronyms and Organizations.....................................................................................8
3. Requirements..................................................................................................................9
3.1 Rationale for PWG Common Log Format..................................................................9
3.2 Use Cases.................................................................................................................9
3.2.1 Log Analysis at a Physician's Office....................................................................9
3.2.2 Log Analysis for Managed Print Services............................................................9
3.2.3 Log Analysis for Printer Maintenance..................................................................9
3.3 Out of Scope............................................................................................................10
3.4 Design Requirements..............................................................................................10
4. PWG Common Log Format...........................................................................................11
4.1 General Message Format........................................................................................11
4.1.1 Mapping Message Severity to/from IPP Severity Suffixes.................................11
4.2 Service Message Format.........................................................................................12
4.3 Job Message Format...............................................................................................12
4.4 Example Messages..................................................................................................12
5. PWG Parameter Definitions...........................................................................................14
5.1 General Event Parameters.......................................................................................14
5.1.1 DeviceUUID (DUU)............................................................................................14
5.1.2 Event (E)...........................................................................................................14
Page 8 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
Stable Draft – PWG Common Log Format February 7, 2013
5.1.3 LogNaturalLanguage (NL).................................................................................15
5.1.4 Status (S)..........................................................................................................15
5.1.5 <service>URI (URI)...........................................................................................15
5.1.6 UserHost (UH)...................................................................................................15
5.1.7 UserName (UN).................................................................................................15
5.1.8 UserRole (UR)...................................................................................................15
5.1.9 UserURI (UU)....................................................................................................16
5.2 Service Events and Parameters...............................................................................16
5.2.1 <service>IsAcceptingJobs (IAJ)........................................................................16
5.2.2 <service>State (ST)...........................................................................................16
5.2.3 <service>StateReasons (SR)............................................................................16
5.2.4 <service>UUID (SUU).......................................................................................17
5.3 Job Events and Parameters.....................................................................................17
5.3.1 JobID (JID)........................................................................................................17
5.3.2 JobUUID (JUU).................................................................................................17
5.3.3 JobImagesCompleted (JIM)..............................................................................17
5.3.4 JobImpressionsCompleted (JIC).......................................................................17
5.3.5 JobDestinationURI (JD).....................................................................................17
5.3.6 JobState (JS).....................................................................................................17
5.3.7 JobStateReasons (JR)......................................................................................18
5.3.8 JobAccountingID (JA)........................................................................................18
5.3.9 JobAccountingUserName (JAUN).....................................................................18
5.3.10 JobAccountingUserURI (JAUU)......................................................................18
6. Conformance Requirements..........................................................................................19
Page 9 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
Stable Draft – PWG Common Log Format February 7, 2013
7. IANA and PWG Considerations.....................................................................................19
8. Internationalization Considerations................................................................................20
9. Security Considerations.................................................................................................20
10. References..................................................................................................................20
10.1 Normative References...........................................................................................20
10.2 Informative References..........................................................................................22
11. Author's Address.........................................................................................................22
12. Change History............................................................................................................24
12.1 February 7, 2013....................................................................................................24
12.2 February 1, 2013....................................................................................................24
12.3 November 12, 2012...............................................................................................24
12.4 July 26, 2012..........................................................................................................24
12.5 December 19, 2011...............................................................................................25
12.6 March 26, 2011......................................................................................................25
12.7 January 26, 2011...................................................................................................26
12.8 October 18, 2010...................................................................................................26
12.9 August 3, 2010.......................................................................................................27
List of Tables
Table 1 - Mapping the Severity Code to IPP Severity Suffixes..........................................12
Table 2 - PWG Event Names............................................................................................19
Page 10 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
Stable Draft – PWG Common Log Format February 7, 2013
Page 11 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
175
Stable Draft – PWG Common Log Format February 7, 2013
1. Introduction
Logging is a critical component for security monitoring, compliance auditing, maintenance, and accounting in hardcopy devices. This standard defines a common log format for hardcopy device events that can be used with existing logging protocols such as The Syslog Protocol [RFC5424]. The Syslog protocol also supports the use of existing secure transport services such as Transport Layer Security v1.2 [RFC5246] and the Transport Layer Security (TLS) Transport Mapping for Syslog [RFC5425].
While the focus of this format is on security and auditing of devices as defined in IEEE Std 2600™-2008 [IEEE2600] [IEEE2600.1] [IEEE2600.2] [IEEE2600.3] [IEEE2600.4], it also supports logging of arbitrary events such as those defined by the IPP: Event Notifications and Subscriptions [RFC3995] specification.
2. Terminology
This section defines the following terms that are used throughout this document:
2.1 Conformance Terminology
Capitalized terms, such as MUST, MUST NOT, RECOMMENDED, REQUIRED, SHOULD, SHOULD NOT, MAY, and OPTIONAL, have special meaning relating to conformance as defined in Key words for use in RFCs to Indicate Requirement Levels [RFC2119].
2.2 Other Terminology
In addition, the following terms are imported or generalized from other source documents:
FQDN: The Fully Qualified Domain Name of a Printer as defined in Domain Names - Implementation and Specification [RFC1035].
Imaging Device: A printer or multifunction device capable of performing print, scan, copy, or facsimile functions, or a projector or monitor capable of displaying images.
Job: A data object, created and managed by a Service, that contains the description, processing, and status information of a Job submitted by a User. The Job can contain zero or more Document objects.
Page 12 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
176
177178179180181182
183184185186
187
188
189
190191192193
194
195
196197
198199
200201202
Stable Draft – PWG Common Log Format February 7, 2013
Service: An Imaging Service (or MFD Service) that accepts and processes requests to create, monitor and manage Jobs, or to directly support other Imaging Services in an imaging-specific way (i.e., the Resource Service). The Service accepts and processes requests to monitor and control the status of the Service itself and its associated Resources. A Service may be hosted either locally or remotely to the MFD.
TitleCase: A keyword that uses concatenated words with capital [UNICODE] letters at the beginning of each word. TitleCase keywords can be easily converted to and from keywords using hyphenated words, e.g., "InputTrayMissing" and "input-tray-missing".
2.3 Acronyms and Organizations
HIPAA: Health Insurance Portability and Accountability Act
IANA: Internet Assigned Numbers Authority, http://www.iana.org/
IEEE: Institute of Electrical and Electronics Engineers, http://www.ieee.org/
IETF: Internet Engineering Task Force, http://www.ietf.org/
IP: Internet Protocol
IPP: Internet Printing Protocol
ISO: International Organization for Standardization, http://www.iso.org/
MIB: Management Information Base
MFD: Multi-Function Device
PWG: Printer Working Group, http://www.pwg.org/
RFC: Request For Comments
URI: Uniform Resource Identifier
UUID: Universally Unique IDentifier
Page 13 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
203204205206207
208209210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
Stable Draft – PWG Common Log Format February 7, 2013
3. Requirements
3.1 Rationale for PWG Common Log Format
The Syslog Protocol [RFC5424] [RFC5425] [RFC5426] defines a standard log message format with attached machine-readable key/value parameters and human-readable message content.
The PWG Common Log Format should therefore:
1. Define a common message format to support encoding and storing of Imaging Device log messages;
2. Define Imaging Device-specific parameters necessary to support automated analysis of log data;
3. Define Imaging Device-specific parameters necessary to support common regulatory requirements;
4. Define Imaging Device-specific parameters necessary to support basic accounting of device usage; and
5. Define Imaging Device-specific parameters necessary to support security auditing.
3.2 Use Cases
3.2.1 Log Analysis at a Physician's Office
John manages the Imaging Devices at a physician's office. He monitors and audits the devices for US HIPAA [US-HIPAA] compliance to ensure that only authorized users are printing, copying, or faxing documents, and that outgoing documents are directed at authorized recipients.
3.2.2 Log Analysis for Managed Print Services
Jill provides reprographics services to several companies in her area. She uses secure logging from leased Imaging Devices to her service office to track the usage of those devices, generate monthly billing statements, and schedule supply deliveries and service appointments as needed.
Page 14 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
226
227
228229230
231
232233234235236237238239240241
242
243
244245246247
248
249250251252
Stable Draft – PWG Common Log Format February 7, 2013
3.2.3 Log Analysis for Printer Maintenance
Bob is in charge of ordering printer supplies and replacement parts for a school's printers. He uses Imaging Device log files to look for low-supply and printer fault conditions and orders new supplies and replacement parts as needed.
Page 15 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
253
254255256
257
Stable Draft – PWG Common Log Format February 7, 2013
3.3 Out of Scope
The following items are considered out of scope for this specification:
1. Definition of interfaces necessary for remote retrieval of log files.2. Strategies for automated log analysis.3. Billing algorithms.4. Supply and service scheduling algorithms.5. Log retention policies.6. Data protection policies aside from requirements to support them.
3.4 Design Requirements
The PWG Common Log Format design requirements are:
1. Define Imaging Device-specific parameters in support of the use cases; and2. Define a Syslog Protocol binding of the common log format.
Page 16 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
258
259
260261262263264265
266
267
268269270
Stable Draft – PWG Common Log Format February 7, 2013
4. PWG Common Log Format
The Syslog Protocol [RFC5424] supports secure logging of plain text messages with attached key/value pairs and date/time information. The PWG Common Log Format uses the Syslog message format with a PWG parameter block. Imaging Devices MUST use this format both for internal logging and for logs distributed off the device.
4.1 General Message Format
The general message format is as follows:
<PRI> 1 YYYY-MM-DDTHH:MM:SS.SSSSSSZ HOSTNAME - - - [PWG PARAMETER="VALUE" ...] MESSAGE
PRI is the message priority and is composed of a facility code followed by a severity code. Imaging Devices MUST use the following severity codes as defined in the Syslog Protocol specification:
3 for error conditions,4 for warning conditions, and6 for informational or report messages.
Imaging Devices SHOULD use facility code 6 ("line printer subsystem") which yields PRI values of:
63 for error conditions,64 for warning conditions, and66 for informational or report messages.
The date (YYYY-MM-DD) and time (HH:MM:SS.SSSSSSZ) MUST be present to ensure that the correct timestamp is recorded.
HOSTNAME is the FQDN or numeric IP address used by the service. The value "-" MAY be used; however, Imaging Devices SHOULD make reasonable attempts to discover their FQDN if it is not configured by the administrator.
The PARAMETER="VALUE" pairs are specific to the type of event being logged. Because the Syslog protocol only requires a server to support a 480 byte line buffer, Imaging Devices SHOULD use the abbreviated parameter names.
Page 17 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
271
272273274275
276
277
278279
280281282
283284285
286287
288289290
291292
293294295
296297298
Stable Draft – PWG Common Log Format February 7, 2013
The MESSAGE value contains the <service>StateMessage or JobStateMessage strings [PWG5108.1], as appropriate.
4.1.1 Mapping Message Severity to/from IPP Severity Suffixes
The severity code in the PRI value of a message maps directly to the three defined severity suffixes for IPP "printer-state-reasons" keyword values in section 4.4.12 of the IPP/1.1 Model and Semantics [RFC2911]. Table 1 lists the severity codes and the corresponding IPP severity suffixes.
Table 1 - Mapping the Severity Code to IPP Severity Suffixes
Severity Code IPP Severity Suffix
3 -error
4 -warning
6 -report
4.2 Service Message Format
Every service message MUST provide the general parameters defined in section 5.1 and the service parameters defined in section 5.2. The MESSAGE text corresponds to the <service>StateMessage value.
4.3 Job Message Format
Every job message MUST provide the general parameters defined in section 5.1 and the job parameters defined in section 5.3. The MESSAGE text corresponds to the JobStateMessage value.
4.4 Example Messages
Bad authorization service configured:
63 1 2010-10-18T12:34:56.789012Z printer.example.com - - - [PWG NL="en-US" E="SecurityInvalidAuthenticationService" IAJ="F" ST="Idle" SR="" SUU="urn:uuid:21c85055-f117-3781-4029-efb0ebcd9954" URI="ipp://printer.example.com/ipp"] ActiveDirectory server 'ad.example.com' does not exist.
Page 18 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
299300
301
302303304305
306
307
308
309310311
312
313314315
316
317
318319320321322
Stable Draft – PWG Common Log Format February 7, 2013
Authentication failure when processing a print job creation request:
63 1 2010-10-18T12:34:56.789012Z printer.example.com - - - [PWG NL="en-US" E="PrintJobCreated" S="client-error-not-authenticated" UH="client.example.com" URI="ipp://printer.example.com/ipp"] Refused print job - not authenticated.
Successful print job creation with an authenticated user:
66 1 2010-10-18T12:34:56.789012Z printer.example.com - - - [PWG NL="en-US" E="PrintJobCreated" S="successful-ok" ST="Pending" UH="client.example.com" UN="example user" UR="user" URI="ipp://printer.example.com/ipp" UU="urn:uuid:052cc3a5-1269-3296-45eb-e437bf9419b5" JID="123" JUU=" urn:uuid:70fe0e41-1e92-3189-6dbe-bb459dc93296"] Created job 123, 42 page PDF document.
Progress messages, the first from the service and the second for the job itself:
66 1 2010-10-18T12:34:56.789012Z printer.example.com - - - [PWG NL="en-US" E="PrintStateChanged" IAJ="T" ST="Processing" SR="" SUU="urn:uuid:21c85055-f117-3781-4029-efb0ebcd9954" URI="ipp://printer.example.com/ipp"] Started printing job 123.66 1 2010-10-18T12:34:56.789012Z printer.example.com - - - [PWG NL="en-US" E="PrintJobStateChanged" ST="Processing" JID="123" JUU="urn:uuid:70fe0e41-1e92-3189-6dbe-bb459dc93296" JIC="0" JR="" UN="example user" URI="ipp://printer.example.com/ipp" UU="urn:uuid:052cc3a5-1269-3296-45eb-e437bf9419b5"] Started printing job 123.
Printer state changes - out of paper and cover open:
64 1 2010-10-18T12:34:56.789012Z printer.example.com - - - [PWG NL="en-US" E="PrintStateChanged" IAJ="T" ST="Processing" SR="media-empty-warning" SUU=" urn:uuid:21c85055-f117-3781-4029-efb0ebcd9954" URI="ipp://printer.example.com/ipp"] The printer is out of paper.63 1 2010-10-18T12:34:56.789012Z printer.example.com - - - [PWG NL="en-US" E="PrintStateChanged" IAJ="F" ST="Stopped" SR="cover-open-error" SUU="urn:uuid:21c85055-f117-3781-4029-efb0ebcd9954" URI="ipp://printer.example.com/ipp"] The printer cover is open.
Print job processing resumes after the correction of the printer conditions:
66 1 2010-10-18T12:34:56.789012Z printer.example.com - - - [PWG NL="en-US" E="PrintStateChanged" IAJ="T" ST="Processing" SR=" " SUU=" urn:uuid:21c85055-f117-3781-4029-efb0ebcd9954" URI="ipp://printer.example.com/ipp"] The printer has resumed printing.
Print job has completed printing:Page 19 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
323
324325326327
328
329330331332333334
335
336337338339340341342343344345
346
347348349350351352353354
355
356357358359
360
Stable Draft – PWG Common Log Format February 7, 2013
66 1 2010-10-18T12:34:56.789012Z printer.example.com - - - [PWG NL="en-US" E="PrintJobStateChanged" ST="Completed" JID="123" JUU=" urn:uuid:70fe0e41-1e92-3189-6dbe-bb459dc93296" JIC=42" JR=" " UN="example user" URI="ipp://printer.example.com/ipp" UU=" urn:uuid:052cc3a5-1269-3296-45eb-e437bf9419b5"] Finished printing job 123.
Page 20 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
361362363364365
366
Stable Draft – PWG Common Log Format February 7, 2013
5. PWG Parameter Definitions
The following sections describe the parameters defined by this specification. For each parameter, a primary name is listed along with an accepted abbreviation, if any, in parenthesis.
5.1 General Event Parameters
5.1.1 DeviceUUID (DUU)
DeviceUUID specifies the globally-unique 45-octet "urn:uuid:" URI associated with the Imaging Device as defined in A Universally Unique IDentifier (UUID) URN Namespace [RFC4122].
5.1.2 Event (E)
The Event specifies the type of event being logged. Event names are TitleCase keywords. The following standard event names were originally defined by the IPP: Event Notifications and Subscriptions [RFC3995]. The <service> names were originally defined by the MFD Model and Common Semantics [PWG5108.1]:
<service>Authentication; user authentication was attempted <service>ConfigChanged; the service configuration was (or was not) changed <service>Identification; user identification was attempted <service>QueueOrderChanged; the order of jobs was (or was not) changed <service>Restarted; the service was (or was not) restarted <service>Shutdown; the service was (or was not) shut down <service>StateChanged; the service state did (or did not) change state <service>Stopped; the service was (or was not) stopped <service>JobCompleted; a job has (or has not) completed <service>JobConfigChanged; a job was (or was not) reconfigured <service>JobCreated; a job was (or was not) created <service>JobForwarded: job data was (or was not) forwarded <service>JobStateChanged; a job did (or did not) change state <service>JobStopped; a job did (or did not) stop
Service names include "Copy", "EmailIn", "EmailOut", "FaxIn", "FaxOut", "Print", "Resource", "Scan", "System", and "Transform". Most log events map directly from the
Page 21 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
367
368369370
371
372
373374375
376
377378379380
381382383384385386387388389390391392393394
395396
Stable Draft – PWG Common Log Format February 7, 2013
corresponding IPP notification events; however, logged events are sent both for success and failure.
Additional event names may also come from the IANA Printer MIB [IANA-MIB] registry for prtAlertCodeTC - names from this registry have their first letter capitalized to convert them to TitleCase form.
5.1.3 LogNaturalLanguage (NL)
The LogNaturalLanguage specifies the language used for all messages.
5.1.4 Status (S)
The Status specifies the status code returned to the Client for the request, if any. The value is either the StatusString as defined in [PWG5108.1] or a TitleCase version of a registered IANA IPP status code string as defined in section 13.1 of [RFC2911], e.g., "ClientErrorNotFound" for "client-error-not-found".
5.1.5 <service>URI (URI)
The URI specifies the service URI.
5.1.6 UserHost (UH)
The UserHost specifies the FQDN or numeric IP address of the user associated with the service or job operation.
5.1.7 UserName (UN)
The UserName specifies the name of the user associated with the service or job operation.
5.1.8 UserRole (UR)
The UserRole specifies the role of the user associated with the service or job operation. The following example roles are defined in the IDS Security Model specification [IDS-MODEL]:
"Administrator", a user who is authorized to manage all aspects of a device or service,"FieldTechnician", a user that is allowed to install physical devices, accessories, and imaging services, and
Page 22 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
397398
399400401
402
403
404
405406407408
409
410
411
412413
414
415416
417
418419420
421422423424
Stable Draft – PWG Common Log Format February 7, 2013
"GroupMember", a user that is allowed to access any operation and resources allowed for the assigned group,"Guest", a user who has limited and temporary access to basic imaging functions such as print, fax or scan."LocalUser", a user who is interacting with an Imaging Device or Service from within physical proximity to the device or service),"NetworkAdministrator", a user who is authorized to manage network configuration and access parameters of the device and services,"Operator", the user who typically oversees the printer and is allowed to query and control the printer, jobs and documents based on site policy,"Owner", the user who owns a particular work object such as a print job, an imaging service or device, or a service registration,"ReadOnlyUser", This is a role that allows a user to only perform query and read operations on the managed elements,"RemoteUser", a user who is interacting with an Imaging Device or Service from a remote location (i.e. a location not within physical proximity to a device),"SecurityAdministrator", a user who is authorized to manage security aspects of the device and services, such as defining access by user roles, installing security certificates, etc.,"ServiceTechnician", a user that is allowed to perform authorized repair and servicing of the physical device,"User", a user who is authorized to perform normal hard copy and imaging operations,
The actual mapping of user privileges to roles is implementation-specific.
5.1.9 UserURI (UU)
UserURI specifies the URI of the user associated with the service or job operation. The value is typically a UUID encoded as defined in A Universally Unique IDentifier (UUID) URN Namespace [RFC4122] or an email address encoded as defined in The "mailto:" URI scheme [RFC6068], although any valid URI may be supplied.
5.2 Service Events and Parameters
5.2.1 <service>IsAcceptingJobs (IAJ)
<service>IsAcceptingJobs specifies a boolean value indicating that the service is (T) or is not (F) accepting new jobs.
Page 23 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
425426427428429430431432433434435436437438439440441442443444445446447
448
449
450451452453
454
455
456457
Stable Draft – PWG Common Log Format February 7, 2013
5.2.2 <service>State (ST)
<service>State specifies the current state of the device:
Unknown; the service has just been created Down; the service is offline Testing; the service is offline and running tests Idle; the service is waiting to process a job Processing; the service is processing a job Stopped; the service has been stopped and is not processing jobs
These values are described in detail in section 4.7 of the MFD Model and Common Semantics [PWG5108.1].
5.2.3 <service>StateReasons (SR)
<service>StateReasons specifies zero or more TitleCase reasons associated with the current state, separated by commas. For the Print service, the IANA registry for the IPP "printer-state-reasons" attribute [IANA-IPP] provides the definitive list of valid <service>StateReasons strings (converted to TitleCase), with the exception that the "none" value should be mapped to the empty string or by omitting the <service>StateReasons parameter.
5.2.4 <service>UUID (SUU)
<service>UUID specifies the globally-unique 45-octet "urn:uuid:" URI associated with the service as defined in A Universally Unique IDentifier (UUID) URN Namespace [RFC4122].
5.3 Job Events and Parameters
5.3.1 JobID (JID)
JobID specifies an integer representing the job for the service as defined in sections 2.4 and 4.3.2 of the Internet Printing Protocol/1.1: Model and Semantics [RFC2911].
5.3.2 JobUUID (JUU)
JobUUID specifies the globally-unique 45-octet "urn:uuid:" URI representing the job for the service as defined in A Universally Unique IDentifier (UUID) URN Namespace [RFC4122].
Page 24 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
458
459
460461462463464465
466467
468
469470471472473474
475
476477
478
479
480481
482
483484
Stable Draft – PWG Common Log Format February 7, 2013
5.3.3 JobImagesCompleted (JIM)
JobImagesCompleted specifies the number of images completed for the job so far.
5.3.4 JobImpressionsCompleted (JIC)
JobImpressionsCompleted specifies the number of impressions completed for the job so far.
5.3.5 JobDestinationURI (JD)
JobDestinationURI specifies one or more destination URIs associated with the Job event being reported, separated by commas.
5.3.6 JobState (JS)
JobState specifies the current job state:
Pending PendingHeld Processing ProcessingStopped Canceled Aborted Completed
5.3.7 JobStateReasons (JR)
JobStateReasons specifies zero or more TitleCase reasons associated with the current job state, separated by commas. For the Print service, the IANA registry for the IPP "job-state-reasons" [IANA-IPP] attribute provides the definitive list of valid JobStateReasons strings (converted to TitleCase), with the exception that the "none" value should be mapped to the empty string or by omitting the JobStateReasons parameter.
5.3.8 JobAccountingID (JA)
JobAccountingID specifies an identifier, such as a billing number, for accounting purposes.
5.3.9 JobAccountingUserName (JAUN)
JobAccountingUserName specifies the user name for accounting purposes.
Page 25 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
485
486
487
488489
490
491492
493
494
495496497498499500501
502
503504505506507
508
509510
511
512
Stable Draft – PWG Common Log Format February 7, 2013
5.3.10 JobAccountingUserURI (JAUU)
JobAccountingUserURI specifies the user's URI for accounting purposes. The value is typically a UUID encoded as defined in A Universally Unique IDentifier (UUID) URN Namespace [RFC4122] or an email address encoded as defined in The "mailto:" URI scheme [RFC6068], although any valid URI may be supplied.
Page 26 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
513
514515516517
518
Stable Draft – PWG Common Log Format February 7, 2013
6. Conformance Requirements
Imaging Devices that conform to this specification MUST:
1. Support logging using the Syslog protocol [RFC5424];2. Protect log data that is stored on the Imaging Device from disclosure to
unauthorized entities or any modification;3. Protect log data in transit off the Imaging Device from disclosure to unauthorized
entities or any modification;4. Use the PWG Common Log Format for log files that can be accessed remotely;5. Use the key/value pairs defined in section 5.1, 5.2, and 5.3 of this document;6. Use UTF-8 and Byte-Order Marks as defined in section 8 of this document; and7. Conform to the security considerations defined in section 9 of this document.
7. IANA and PWG Considerations
This section provides the registration information to be used by the Printer Working Group for the registration of the PWG Common Log Format event keywords. The values defined in this specification are contained in Table 2. The general rule is to convert the IPP event name [IANA-IPP] to TitleCase, remove any leading "Printer" from the name, and then prepend the service name. Thus, "printer-config-changed" for the Scan service becomes "ScanConfigChanged".
Table 2 - PWG Event Names
Page 27 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
519
520
521522523524525526527528529
530
531532533534535536
537
Stable Draft – PWG Common Log Format February 7, 2013
PWG Event IPP Event
<service>Authentication
<service>ConfigChanged printer-config-changed
<service>Identification
<service>QueueOrderChanged
printer-queue-order-changed
<service>Restarted printer-restarted
<service>Shutdown printer-shutdown
<service>StateChanged printer-state-changed
<service>Stopped printer-stopped
<service>JobCompleted job-completed
<service>JobConfigChanged job-config-changed
<service>JobCreated job-created
<service>JobStateChanged job-state-changed
<service>JobStopped job-stopped
Page 28 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
538
539
Stable Draft – PWG Common Log Format February 7, 2013
8. Internationalization Considerations
For interoperability and basic support for multiple languages, conforming Printer implementations MUST support the UTF-8 [STD63] encoding of Unicode [UNICODE] [ISO10646]. However, unlike the recommendations in [UNICODE], Unicode messages MUST be preceded by a Unicode Byte Order Mark (BOM) as described in Syslog section 6.4 [RFC5424]. For internal or file-based logging, the BOM is OPTIONAL and MUST appear only at the beginning of the file, if included.
Note that the use of a BOM is not in agreement with Unicode recommendations [UNICODE].
9. Security Considerations
Security considerations are defined in section 8 of The Syslog Protocol [RFC5424] and Signed Syslog Messages [RFC5848]. An Imaging Device MUST protect log messages from alteration or unauthorized disclosure both on the device and when distributed outside the device. Imaging Devices SHOULD support Signed Syslog Messages [RFC5848] to protect log messages from alteration, and Transport Layer Security v1.2 [RFC5246] and the Transport Layer Security (TLS) Transport Mapping for Syslog [RFC5425] to protect log messages when distributed outside the device. When transmitting log messages via UDP, Datagram Transport Layer Security Version 1.2 [RFC6347] and Datagram Transport Layer Security (DTLS) Transport Mapping for Syslog [RFC6012] SHOULD be used.
10. References
10.1 Normative References
[IANA] The Internet Assigned Numbers Authority. http://www.iana.org
[IEEE2600] “Information Technology: Hardcopy Device and System Security”, IEEE Std. 2600™-2008
[IEEE2600.1] "IEEE Standard for a Protection Profile in Operational Environment A", IEEE Std. 2600.1™-2009
[IEEE2600.2] "IEEE Standard Protection Profile for Hardcopy Devices in IEEE Std. 2600™-2008 Operational Environment B", IEEE Std. 2600.2™-2009
Page 29 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
540
541542543544545546
547548
549
550551552553554555556557558
559
560
561
562563
564565
566567
Stable Draft – PWG Common Log Format February 7, 2013
[IEEE2600.3] "IEEE Standard Protection Profile for Hardcopy Devices in IEEE Std. 2600™-2008 Operational Environment C", IEEE Std. 2600.3™-2009
[IEEE2600.4] "IEEE Standard Protection Profile for Hardcopy Devices in IEEE Std. 2600™-2008 Operational Environment D", IEEE Std. 2600.4™-2010
[PWG5108.1] W. Wagner, P. Zehler, "MFD Model and Common Semantics", PWG 5108.1, April 2011, ftp://ftp.pwg.org/pub/pwg/candidates/cs-sm20-mfdmodel10-20110415-5108.1.pdf
[RFC1035] P. Mockapetris, "DOMAIN NAMES - IMPLEMENTATION AND SPECIFICATION", RFC 1035, November 1987, http://www.ietf.org/rfc/rfc1035.txt
[RFC2119] S. Bradner , “Key words for use in RFCs to Indicate Requirement Levels” , RFC 2119, March 1997, http://www.ietf.org/rfc/rfc2119.txt
[RFC2911] T. Hastings, R. Herriot, R. deBry, S. Isaacson, P. Powell, "Internet Printing Protocol/1.1: Model and Semantics", RFC 2911, September 2000, http://www.ietf.org/rfc/rfc2911.txt
[RFC3995] R. Herriot, T. Hastings, “Internet Printing Protocol (IPP): Event Notifications and Subscriptions”, RFC 3995, March 2005, http://www.ietf.org/rfc/rfc3995.txt
[RFC4122] P. Leach, M. Mealling, R. Salz, "A Universally Unique IDentifier (UUID) URN Namespace", RFC 4122, July 2005, http://www.ietf.org/rfc/rfc4122.txt
[RFC5246] T. Dierks, E. Rescorla, "Transport Layer Security v1.2", RFC 5246, August 2008, http://www.ietf.org/rfc/rfc5246
[RFC5424] R. Gerhards, “The Syslog Protocol”, RFC 5424, March 2009, http://www.ietf.org/rfc/rfc5424.txt
[RFC5425] F. Miao, Y. Ma, J. Salowey, “Transport Layer Security (TLS) Transport Mapping for Syslog”, RFC 5425, March 2009, http://www.ietf.org/rfc/rfc5425.txt
[RFC5426] A. Okmianski, “Transmission of Syslog Messages over UDP”, RFC 5426, March 2009, http://www.ietf.org/rfc/rfc5426.txt
Page 30 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
568569
570571
572573574
575576577
578579
580581582
583584585
586587588
589590
591592
593594595
596597
Stable Draft – PWG Common Log Format February 7, 2013
[RFC5848] J. Kelsey, J. Callas, A. Clemm, "Signed Syslog Messages", RFC 5848, May 2010, http://www.ietf.org/rfc/rfc5848.txt
[RFC6012] J. Salowey, T. Petch, R. Gerhards, H. Feng, “Datagram Transport Layer Security (DTLS) Transport Mapping for Syslog”, October 2010, http://www.ietf.org/rfc/rfc6012.txt
[RFC6068] M. Duerst, L. Masinter, J. Zawinski, "The 'mailto' URI Scheme", RFC 6068, October 2010, http://www.ietf.org/rfc/rfc6068.txt
[RFC6347] E. Rescorla, N. Modadugu, “Datagram Transport Layer Security Version 1.2”, RFC 6347, January 2012, http://www.ietf.org/rfc/rfc6347.txt
[STD63] F. Yergeau , “UTF-8 Transformation of ISO 10646”, STD 63, RFC 3629, November 2003, http://www.ietf.org/rfc/rfc3629.txt
10.2 Informative References
[IANA-IPP] IANA Internet Printing Protocol registry, http://www.iana.org/assignments/ipp-registrations
[IANA-MIB] IANA Printer MIB registry, http://www.iana.org/assignments/ianaprinter-mib
[IDS-MODEL] J. Murdock, "IDS Security Model (IDS-Model)", ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-model10-current.pdf
[ISO10646] "Information Technology - Universal Multiple-octet Coded Character Set (UCS)", ISO/IEC Standard 10646:2011
[UNICODE] The Unicode Consortium, “The Unicode Standard, Version 6.2.0”, ISBN 978-1-936213-07-8, September 2012, http://www.unicode.org/versions/Unicode6.2.0/
[US-HIPAA] US Health Insurance Portability and Accountability Act, http://www.hhs.gov/ocr/privacy/
11. Author's Address
Michael Sweet
Page 31 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
598599
600601602
603604
605606607
608609
610
611612
613614
615616
617618
619620621
622623
624
625
Stable Draft – PWG Common Log Format February 7, 2013
10431 N. De Anza Blvd.MS 38-4LPTCupertino, CA 95014Email: [email protected]
Send comments to the PWG IDS Mailing List:
[email protected] (subscribers only)
To subscribe, see the PWG web page:
http://www.pwg.org/
Implementers of this specification document are encourages to join the IDS Mailing List in order to participate in any discussions of clarification issues and review of registration proposals for additional attributes and values.
The editor would like to especially thank the members of the IDS working group for their constant valuable, and sometimes humorous, feedback during the development of this document.
Page 32 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
626627628629
630
631
632
633
634635636
637638639
640
Stable Draft – PWG Common Log Format February 7, 2013
12. Change History
[To be removed before publication.]
12.1 February 7, 2013
1. Status: Stable (not stable draft)2. Section 9: Deleted extra word.
12.2 February 1, 2013
1. Updated copyright2. Updated Unicode reference to 6.2.0.3. AS1: Added new section 2.3 Acronyms and Organizations4. AS2: Added “-2008” to IEEE Std 2600 reference.5. AS3: Grammar change in section 4.16. AS4: Added references to IEEE 2600.x, removed reference to RFC 2277 and
RFC 3998, added referencs to RFC 5246, RFC 5425, and RFC 5426.7. AS5: Fixed grammar in section 5.1.28. AS6: Fixed plural in section 5.1.89. MS1: Fixed document references throughout document10.MS2: Added text concerning TLS and Syslog to section 111.MS3: Removed blank page12.MS4: Alphabetized user roles in section 5.1.813.MS5: Added text concerning TLS, Syslog, and signing to section 914.MS6: Added reference to TLS 1.215.MS7: Added references to RFC 6347 and RFC 6012.16.NC1: Fixed title page so both document links fit on the page17.NC2: Global search/replace “must” with “MUST” or alternate wording18.RT1: Clarified section 3.3 item 6: we aren’t defining data protection policies but
we do want to support them.19.RT2: Clarified section 9: we are protecting log messages.
12.3 November 12, 2012
1. Status: Stable (for Working Group Last Call)2. Removed old comments
Page 33 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
641
642
643
644645
646
647648649650651652653654655656657658659660661662663664665666667
668
669670
Stable Draft – PWG Common Log Format February 7, 2013
12.4 July 26, 2012
1. Status: Prototype2. Fixed title in heading3. Global: PWG Common Log Format (throughout)4. Global: RFC 3629 -> STD 635. Section 2.1: Fixed conformance terminology6. Section 2.2: Updated FQDN and imaging device, copied Job and Service
definitions from MFD Model7. Section 4.1: Made PRI values into a list8. Section 4.1.1: Added subsection in reference to 29119. Section 4.4: Dropped TODO10.Section 5.1.1 DeviceUUID: Added11.Section 5.1.2 Event: Cleanup, add reference to MFD Model12.Section 5.1.4: Added subsection in reference to 291113.Section 5.1.8: Imported user roles from current IDS Model draft, added
informative reference.14.Section 5.1.9: UserUUID -> UserURI, use JPS3 wording15.Section 5.2.2: Added section reference and fixed title of MFD Model16.Section 5.2.3 <service>StateMessage: Removed since it is confusing because
syslog puts the message separately on the end.17.Section 5.2.4 <service>UUID: Use JPS3 wording18.Section 5.3.1: Add reference to RFC 291119.Section 5.3.2: Use JPS3 wording20.Section 5.3.7 JobStateMessage: Removed since it is confusing because syslog
puts the message separately on the end.21.Section 5.3.10: JobAccountingUserUUID -> JobAccountingUserURI, use JPS3
wording22.Section 6: "or any modification" for conformance requirements23.Section 9: Tightened up security wording.24.Section 10: Moved ISO 10646 and UNICODE references to informative,
updated UNICODE to 6.1.0.25.Section 11: Added WG references and acknowledgement to WG members.
12.5 December 19, 2011
1. Changed name to "Common Log Format"2. Added event names from Printer MIB registry3. Updated all references
Page 34 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
671
672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702
703
704705706
Stable Draft – PWG Common Log Format February 7, 2013
4. Updated use cases5. Updated example messages and added descriptive text.6. Updated conformance and description of PRI values
12.6 March 26, 2011
1. New document name (IDS vs Hardcopy Device)2. Replace hardcopy device and HCDs with Imaging Device(s)3. Section 1 - reference applicable standards4. Section 2 - add Imaging Device and TitleCase to terminology5. Section 3 - expand outline to text6. Section 4 - rename to "IDS Log Format" and say that we are using the Syslog
message format on disk.7. Section 4.1 - update PRI to use SHOULD for recommended values.8. Move Service Message Format and Job Message Format sections before
Example Messages9. Section 5 - rename to "PWG Parameter Definitions"10.Sections 5.1.3, 5.3.8 - provide TitleCase guidance11.Section 5.1.7 - change roles to TitleCase12.Sections 5.1.8, 5.2.5, 5.3.2, 5.3.11 - reference RFC 412213.Section 5.3.5 - Allow multiple values14.Section 6 - Expand to use numbered list format15.Section 8 - Clarify use of BOM in files16.Section 9 - Reference RFC 5848.17.Updated normative references (again) and used approved PWG reference
format.
12.7 January 26, 2011
1. Added new boilerplate content.2. Added introduction3. Added references for 5.1.4 Status (S)4. Expanded 5.1.8 UserRole (UR)5. 5.3.5 now defined to be a URI6. Added JobAccountingUserName and JobAccountingUserUUID7. Added conformance requirements8. Explained the use of title case in section 7.9. Clarified section 8 concerning the use of a BOM with UTF-810.Reworded section 9.
Page 35 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
707708709
710
711712713714715716717718719720721722723724725726727728729730
731
732733734735736737738739740741
Stable Draft – PWG Common Log Format February 7, 2013
11.Updated normative references
12.8 October 18, 2010
1. Added terminology2. Added outline of section 3.1 rationale and 3.2 use cases3. Section 4 - use Syslog terminology (parameter instead of attribute) and add
examples4. Section 5 - use Syslog terminology and list the valid service names.5. Section 5.1 - added LogNaturalLanguage, Status, <service>URI, UserHost,
UserRole, and UserUUID parameters.6. Section 5.2 - added <service>UUID7. Section 5.2.2 - expanded to include all MFD states.8. Section 5.2.4 - reference 2911.9. Section 5.3 - added JobUUID, JobImagesCompleted, JobDestination, and
JobAccountingID10.Section 5.3.8 - reference 2911.11.Section 7 - require BOM per Syslog12.Section 8 - Add references and message integrity section.13.Updated normative references.
12.9 August 3, 2010
Initial revision.
Page 36 of 36 Copyright © 2010-2013 The Printer Working Group. All rights reserved.
742
743
744745746747748749750751752753754755756757758759
760
761
762