Configure Logging

By default, the Keyfactor Windows EnrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). Gateway outputs logging information to both the Windows event log and the local file system, places file system log files in the c:\cms\logs directory, generates file system logs at the Info logging level, and stores file system logs for two days before deleting them.

Understanding Log Files

Log files by default are generated using the following layout:

  • Timestamp: The date and time the log was generated, in ISO 8601 extended format.

    Example: 2026-02-11 11:35:21.1402
  • Correlation ID: A system-generated GUID that identifies all log messages from a single request. It typically appears immediately after the timestamp.

    Example: 3443C462-1AC7-40FA-9FF6-4554B0F761BC

    The correlation ID appears at all logging levels.

  • Log Level: Indicates the severity of the message—ranging from Trace and Debug (low-level detail) to Info, Warn, Error, and Fatal (critical failures).

  • Message: The main content of the log entry. This may include descriptive text, data values, or stack traces in the case of errors.

    Example:

    Requesting new certificate.

The above references as found in a full log entry would look like:

2026-02-12 11:20:28.7105 CD90E3FC-EE5F-4093-9B30-A4CA8518E237 CAProxy.WebMS.WebMSCertReqProxy [Info] - Requesting new certificate.

Modifying Logging Configuration

If you wish to change these defaults:

  1. On the Keyfactor Windows Enrollment Gateway server where you wish to adjust logging, open a text editor (for example, Notepad) using the Run as administrator option.
  2. In the text editor, browse to open the NLog.config file in the directory in which you installed the Keyfactor Windows Enrollment Gateway. By default, this is the following directory:

    C:\Program Files\Keyfactor\Keyfactor Managed CA Gateway

  3. Your NLog.config file may have a slightly different layout than shown here, but it will contain the fields highlighted in the below figure. The fields you may wish to edit are:

Figure 759: NLog.config File for the Keyfactor Windows Enrollment Gateway

Tip:  The NLog.config file also contains a few filters that remove log messages of certain types from logging at debug and trace level as they can be chatty and may not be helpful except in special cases. You may find it helpful to emulate these with filters of your own when troubleshooting.