OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Syslog over TLS
« previous next »
  • Print
Pages: [1]

Author Topic: Syslog over TLS  (Read 3753 times)

erickufrin

  • Newbie
  • *
  • Posts: 18
  • Karma: 1
    • View Profile
Syslog over TLS
« on: April 19, 2018, 01:48:06 pm »
Is it possible to configure TLS for syslog? Is anything special needed beyond just defining the TLS port number for my syslog target? want to secure that traffic.
« Last Edit: April 19, 2018, 01:55:35 pm by erickufrin »
Logged

Alphakilo

  • Newbie
  • *
  • Posts: 49
  • Karma: 6
    • View Profile
Re: Syslog over TLS
« Reply #1 on: April 19, 2018, 02:02:11 pm »
And do authentication for that matter?

That's one of my reoccurring nightmares: A compromised / spoofed syslog sink that gives adversaries real time feedback on their moves.
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: Syslog over TLS
« Reply #2 on: April 20, 2018, 01:37:15 pm »
FreeBSD's syslog doesn't support TCP... which means we can't do TLS as well.

I have imported syslog-ng into the development version a few months ago intending to work on using that for syslog export, which would allow TCP and TLS.

Other things got in the way since, but it's still planned for 18.7.


Cheers,
Franco
Logged

erickufrin

  • Newbie
  • *
  • Posts: 18
  • Karma: 1
    • View Profile
Re: Syslog over TLS
« Reply #3 on: April 20, 2018, 10:15:07 pm »
Excellent. thank you for working on/towards this. I will watch for it in 18.7.
Logged

kapara

  • Jr. Member
  • **
  • Posts: 97
  • Karma: 3
    • View Profile
Re: Syslog over TLS
« Reply #4 on: April 22, 2019, 07:41:12 am »
What is the status of this?  Was it added?  I looked in the logging section of the GUI but found no mention of TLS as an option.
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: Syslog over TLS
« Reply #5 on: April 22, 2019, 12:31:00 pm »
We do not have any contributor's time allocated for this still.


Cheers,
Franco
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Syslog over TLS
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2