OPNsense Forum

English Forums => General Discussion => Topic started by: homelabber123 on October 07, 2026, 01:42:01 PM

Title: Remote logging to Alloy, over TLS, fails with unknown certificate authority
Post by: homelabber123 on October 07, 2026, 01:42:01 PM
Hello good people,

I'm trying to do the following thing:


Overall, I've arrived at a pretty decent & workable solution, using TCP as transport.

And the final piece that I want to achieve is to actually transport those logs over TLS(4) - effectively doing mTLS between OPNsense (as syslog-provider) and Grafana Alloy (as syslog-receiver)

What I did was the following:



Here is the relevant Grafana Alloy configuration:

otelcol.receiver.syslog "remote_syslog" {
protocol = "rfc5424"
allow_skip_pri_header = true

tcp {
listen_address = "0.0.0.0:8094"
tls {
cert_file      = "/etc/alloy/certs/server.pem"
key_file       = "/etc/alloy/certs/server.key"
client_ca_file = "/etc/alloy/certs/ca.pem"
min_version = "1.2"
max_version = "1.2"
}
}

output {
logs = [otelcol.exporter.syslog.syslog_out.input]
}
}

On the OPNsense side, I've done the following:


The error that I'm getting on the Alloy side is the following:

remote error: tls: unknown certificate authority

Which kind-of leads me to think that OPNsense is not using the CA to validate the server cert when doing the handshake.

Debugging steps I've done:


I would really appreciate your help & directions.

Please ask for whatever additional information & context you think you'll need.

p.s. the limit to TLS 1.2 was from another initial error that I was getting about a "tls: bad record MAC"


Title: Re: Remote logging to Alloy, over TLS, fails with unknown certificate authority
Post by: homelabber123 on October 07, 2026, 02:23:43 PM
Okay, after some more digging, it looks like the CA is actually loaded & hashed properly in `/etc/ssl/certs`

And when I get the issuer hash, from both the client & server pems, I get the same correct hash:

$ openssl x509 -in server.pem -noout -issuer_hash
17d48176

$ openssl x509 -in client.pem -noout -issuer_hash
17d48176

$ ls /etc/ssl/certs/17d48176.0
/etc/ssl/certs/17d48176.0

So it "should" be working :D But it's not.

So I'd love to get some direction, if anyone can spot anything.