Solved

how do i Secure syslog with TLS

Posted on 2012-04-10
6
1,056 Views
Last Modified: 2012-04-19
Hello Experts,

I am using Linux RHEL 5.7 server, I want to secure syslog with TLS, Please guide me through the steps.
0
Comment
Question by:sudhirgoogle
6 Comments
 
LVL 51

Expert Comment

by:ahoffmann
ID: 37831617
can you please explain what you want to archive: a) sending syslog data from host A to host B or b) reading syslog file with your browser?
0
 
LVL 33

Accepted Solution

by:
Dave Howe earned 250 total points
ID: 37832295
You don't - seriously, TLS is a TCP based protocol, and *normally* syslog is UDP - therefore, if you want to protect the data in transit, you would need to wrap the traffic in some sort of tunnel (probably vpn, as most tunnels are also TCP only)

There is an RFC regarding how this *could* be done - rfc5425 - but at this time, almost nobody supports this new format so getting it to work in practice would be a nightmare. In addition, rfc6012 details how the new and experimental DTLS (rfc4347 - TLS for UDP, basically) could be used for a syslog transport, but this is (as far as I know) not implemented by *anyone* in the real world.

In short, trying to do TLS for syslog opens a can of worms, and probably not one you want opening. most sites avoid the issue entirely by having a dedicated management VLAN which also carries syslog traffic.
0
 
LVL 29

Assisted Solution

by:Michael Worsham
Michael Worsham earned 250 total points
ID: 37832377
Here's the how-to:

https://www.icts.uiowa.edu/confluence/display/ICTSit/Add+TLS+Functionality+to+your+syslog-ng+setup

Just remember that you have to enable TCP mode to use Syslog-NG with TLS.
0
Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

 
LVL 33

Expert Comment

by:Dave Howe
ID: 37832456
mwecomputers: yup, syslog-ng supports it, but how do you plan to get anything to send TLS wrapped syslog packets to it?
0
 
LVL 1

Author Comment

by:sudhirgoogle
ID: 37854206
i want to achieve sending syslog data from host A to host B
0
 
LVL 1

Author Closing Comment

by:sudhirgoogle
ID: 37864864
Thanks.
0

Featured Post

Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
CentOS/RHEL 7 Linux maillog worldwide readable 2 89
maybe no no httpd.conf 6 62
Upgrade BIOS / EUFI at Scale 4 55
what do I need to host my own web sites? 13 51
If you have a server on collocation with the super-fast CPU, that doesn't mean that you get it running at full power. Here is a preamble. When doing inventory of Linux servers, that I'm administering, I've found that some of them are running on l…
Little introduction about CP: CP is a command on linux that use to copy files and folder from one location to another location. Example usage of CP as follow: cp /myfoder /pathto/destination/folder/ cp abc.tar.gz /pathto/destination/folder/ab…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question