rsyslog 中的 ssl 加密

发布于 2024-11-30 02:22:33 字数 1645 浏览 0 评论 0原文

谁能给我提示这个问题出在哪里,

我无法加密从客户端计算机到中央日志的日志文件,我不明白原因,我可以获得任何相关信息吗? (我可以看到未加密的文件,传向中央服务器(ngrep - 进出))

Senario,我正在使用,已经创建的证书,它是 godaddy 授权的 CA。

客户端 rsyslog.conf:

$ModLoad imuxsock.so
$ModLoad imklog.so
$ModLoad imtcp


$DefaultNetstreamDriver gtls

# certificate files
$DefaultNetstreamDriverCAFile /rsyslog/pki/something.example.net.crt
$DefaultNetstreamDriverCertFile /rsyslog/pki/something.example.com.crt
$DefaultNetstreamDriverKeyFile /rsyslog/pki/something.example.com.key

$ActionSendStreamDriverAuthMode x509/name 
$ActionSendStreamDriverMode 1 

*.* @@machine.example.net:10514

时,系统挂起

异常:当我启用 defaultnetstreamDriver gtls服务器 rsyslog.conf

$ModLoad ommysql
#$UDPServerRUn 514

$ModLoad immark # provides --MARK-- message capability
#$ModLoad imudp # provides UDP syslog reception
$ModLoad imtcp # provides TCP syslog reception
$ModLoad imgssapi # provides GSSAPI syslog reception
#$ModLoad imuxsock # provides support for local system logging (e.g. via logger command)
$ModLoad imklog # provides kernel logging support (previously done by rklogd)


$InputTCPServerRun 10514

*.*    :ommysql:127.0.0.1,dbname,username,password

$DefaultNetstreamDriver gtls

# certificate files
$DefaultNetstreamDriverCAFile /var/www/html/rsyslog/ssl/something.example.net.crt
$DefaultNetstreamDriverCertFile /var/www/html/rsyslog/ssl/something.example.net.crt
$DefaultNetstreamDriverKeyFile /var/www/html/rsyslog/ssl/something.example.net.key 


$ActionSendStreamDriverAuthMode  anon
$ActionSendStreamDriverPermittedPeer *.example.net
$ActionSendStreamDriverMode 1 

could anyone give me hint where this problem is,

I am unable to encrypt log files comming from my client machine to central log, i dont understand the reason, could i get any relevent information. (i can see unencrypted files, coming towards central server (ngrep - in and out both))

Senario, I am using, already created certificate which is an authorized CA by godaddy.

Client rsyslog.conf:

$ModLoad imuxsock.so
$ModLoad imklog.so
$ModLoad imtcp


$DefaultNetstreamDriver gtls

# certificate files
$DefaultNetstreamDriverCAFile /rsyslog/pki/something.example.net.crt
$DefaultNetstreamDriverCertFile /rsyslog/pki/something.example.com.crt
$DefaultNetstreamDriverKeyFile /rsyslog/pki/something.example.com.key

$ActionSendStreamDriverAuthMode x509/name 
$ActionSendStreamDriverMode 1 

*.* @@machine.example.net:10514

unusual: system gets hung, when i enable defaultnetstreamDriver gtls

Server rsyslog.conf

$ModLoad ommysql
#$UDPServerRUn 514

$ModLoad immark # provides --MARK-- message capability
#$ModLoad imudp # provides UDP syslog reception
$ModLoad imtcp # provides TCP syslog reception
$ModLoad imgssapi # provides GSSAPI syslog reception
#$ModLoad imuxsock # provides support for local system logging (e.g. via logger command)
$ModLoad imklog # provides kernel logging support (previously done by rklogd)


$InputTCPServerRun 10514

*.*    :ommysql:127.0.0.1,dbname,username,password

$DefaultNetstreamDriver gtls

# certificate files
$DefaultNetstreamDriverCAFile /var/www/html/rsyslog/ssl/something.example.net.crt
$DefaultNetstreamDriverCertFile /var/www/html/rsyslog/ssl/something.example.net.crt
$DefaultNetstreamDriverKeyFile /var/www/html/rsyslog/ssl/something.example.net.key 


$ActionSendStreamDriverAuthMode  anon
$ActionSendStreamDriverPermittedPeer *.example.net
$ActionSendStreamDriverMode 1 

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(1

三寸金莲 2024-12-07 02:22:33

人们,可能遇到同样的问题,所以我想分享是否有人最终来到这里。

实际上,遇到了这个问题,如果有人遇到同样的问题,代码没有任何问题,但是,rsyslog 的版本不受支持所需的加密是 5.8.4,但是我还没有测试任何其他以前的版本以确保其他版本是否有效。 5.8.4 肯定有效

People, may be having same issue, so i would like to share if anyone ends up here..

Actually, got the issue, if anyone faces the same problem, there is nothing wrong in code however, the version of rsyslog is not supported by encryption, required, is 5.8.4 however, i havent tested any other previous version to ensure if other works or not. for sure 5.8.4 works

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文