Çözüm13 Ağustos 20265 dk okuma1059 kelime

What Is Law 5651 Log Signing? Sealing Logs with E-Signature and Timestamp

What is Law 5651 log signing and why is it required? Timestamp vs e-signature, the KamuSM credit model, daily signing and SignLogger's signed log retention.

#law 5651 log signing#log signing#timestamp#electronic signature#kamusm#signed logs

What Is Law 5651 Log Signing? Sealing Logs with E-Signature and Timestamp

Law 5651 log signing is the process of sealing internet connection logs — after they are collected — with an electronic signature and a timestamp. The goal is to mathematically prove that a record has not been altered and to establish the exact date and time it was created. Turkey's Law No. 5651 does not treat mere log keeping as sufficient; it expects you to prove that the records you keep are tamper-proof and that their time information comes from a trusted source. Unsigned raw logs carry little evidential value when a request arrives, because no one can guarantee they were not changed. Signing takes a digest (hash) of each log file and seals it with the timestamp and e-signature of an authorized certificate authority, locking the record against tampering. SignLogger performs this automatically every day: it signs the collected logs daily, seals them and archives them in a verifiable form for the full legal retention period.

This page is for informational purposes; for exact obligations consult current legislation and a legal advisor.

Why is log signing required?

A record under Law 5651 is only useful in a legal investigation if it is trustworthy. A raw log file is just text; its contents can be edited and its dates rolled back. Signing turns three questions into proof:

  • Integrity: That not a single character changed after the record was created, proven by hash comparison.
  • Time: That the record existed at the stated date and time, verified by an independent timestamp authority. Trusting the server's own clock is not enough.
  • Immutability: The content cannot be changed without breaking the signature; if it is changed, verification fails and this is detected immediately.

What is the difference between a timestamp and an electronic signature?

They complement each other but are not the same thing:

  • Timestamp: Proves that data existed at a specific moment, using trusted time information from an authorized timestamp server. It proves "this record was created before this date."
  • Electronic signature: Proves the integrity and origin of the data. It proves "this record has not changed since it was created."

In practice, Law 5651 compliance uses both together: logs are signed and the signature is timestamped. This way "when" and "unchanged" are proven simultaneously.

What role does KamuSM (TÜBİTAK Kamu SM) play in signing?

For a timestamp and qualified electronic signature to be legally valid, the signature must come from an authorized certificate authority. In Turkey the primary source is the TÜBİTAK Public Certification Authority (Kamu SM). The timestamp service from Kamu SM works with credits (prepaid stamping rights): every signing operation consumes one credit. For this reason, your Law 5651 log signing solution needs sufficient credit to run without interruption. Signing must not stall when credits run out; SignLogger is designed to sign with a server certificate to avoid losing records and to resume authorized timestamping once credits are topped up. Credit tracking and alerts prevent gaps from forming in the signing chain.

How often should logs be signed?

Signing is not a one-time task; it is regular and continuous. If logs accumulate without being signed, there is no integrity proof for the period they remained unsigned. The correct approach is to sign and seal records daily. SignLogger signs the logs it collects automatically every day with an authorized certificate authority timestamp and e-signature, so no daily gap forms in the signing chain and any day's records can be produced in signed form on request.

Are the logs produced by a firewall already signed?

No. Firewall, switch or access point devices can produce traffic records; but these records are usually unsigned and untimestamped, kept on the device for a limited time and easily overwritten. For Law 5651 compliance, these records must be collected at a central point, signed, sealed with a timestamp and stored immutably for the legal period. SignLogger provides exactly this layer: it collects logs from all devices, brand-independently, and turns them into a signed archive.

How does SignLogger perform log signing?

SignLogger handles the Law 5651 log signing process end to end:

  • Collects logs centrally from all sources, including firewalls, switches, access points and the captive portal.
  • Takes a digest of the collected records and signs them every day with an authorized certificate authority (TÜBİTAK Kamu SM) timestamp and e-signature.
  • Archives the signed records with their integrity preserved for the full legal retention period and keeps them searchable.
  • Produces the signed record for any given date, in verifiable form, on request.
  • Monitors credit status, warns before it runs out and prevents gaps in the signing chain.

Frequently Asked Questions

Is signing logs mandatory for Law 5651?

For records to carry evidential value, their integrity and time information are expected to be provable, which in practice is achieved with a timestamp and an electronic signature. Unsigned raw logs may not be accepted as sufficient when a request arrives. For exact obligations, consult current legislation. [TO BE VERIFIED]

What is the difference between a timestamp and an e-signature?

A timestamp proves that a record existed at a specific moment; an electronic signature proves that the record has not changed since then and confirms its origin. Law 5651 compliance uses both together.

Do I need KamuSM credits to sign logs?

The authorized timestamp service works with credits and provides the strongest legal proof. When credits run out, SignLogger keeps signing with a server certificate to avoid losing records and returns to authorized timestamping once credits are added; however, keeping credits topped up is recommended for continuous compliance.

How often should logs be signed?

Regularly and continuously. The healthiest approach is daily signing. SignLogger signs the collected logs automatically every day, so no gap forms in the signing chain.

I already have firewall logs — do I still need to sign them?

Yes. Firewall logs are usually unsigned and untimestamped, kept briefly on the device and overwritten. For Law 5651 compliance these records must be collected, signed, sealed and stored for the legal period.

How is it verified that a signed log has not been altered?

The digest (hash) of the signed record is recalculated and compared with the value in the signature. If even one character changed, verification fails, so a tampered record is detected instantly.

Son güncelleme: 21 Ağustos 2026

SignLogger bu çözümü kurumunuz için nasıl uyguluyor, görün

Ücretsiz demo isteyin