Skip to content

bifroest audit producer-id

Prints the 64-character lowercase hexadecimal producer ID derived from the selected entry's local signing private key, not from the journal. It also works when only session recording is enabled. It does not create a missing identity or access audit records. The ID is safe to transfer; the signing private key is not.

Syntax

bifroest audit producer-id [flags] <auditlogName>

Flags

Includes all general flags.

--configuration

Optional configuration path; defaults to the same platform path as bifroest run.

Example

On the Bifröst host after the signing identity has been created:

1
bifroest audit producer-id default

Save this value via an independently trusted channel before inspecting an offline copy. A producer ID taken only from the copied journal or a recording cannot establish producer trust. See encrypted audit events for the offline workflow.