Create the third-party audit class ec and two audit events, AUE_second_signature and AUE_second_signature_verify. See the audit_class(4) and audit_event(4) man pages for more information on these files.
Third-party audit classes are added to the /etc/security/audit_class file in the form mask:name:description as follows:
0x00008000:ec:example class
Third-party audit events are added to the /etc/security/audit_event file and assigned one of the numbers reserved for third-party events from 32768 to 65535. This file also contains the audit event to audit class mapping. The following lines add two events and map them to the example (ec) class:
32768:AUE_second_signature:second signature requested:ec
32769:AUE_second_signature_verify:second signature added:ec