# RSyslog over TLS

**URL:** <https://community.graylog.org/t/rsyslog-over-tls/263>\
**Category:** Graylog Central (peer support)\
**Created:** [February 27, 2017, 4:01pm UTC](https://community.graylog.org/t/rsyslog-over-tls/263 "2017-02-27T16:01:29Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![OlympiaLady](https://avatars.discourse-cdn.com/v4/letter/o/8491ac/32.png) [@OlympiaLady](https://community.graylog.org/u/OlympiaLady)\
**Post date:** [February 27, 2017, 9:10pm UTC](https://community.graylog.org/t/rsyslog-over-tls/263/4 "2017-02-27T21:10:27Z")

</div>

Hi,

I have been trying to figure out how to contribute to the documentation, but this is how we do it on CentOS6.

**On the Graylog Server, configure an input:**

allow\_override\_date: true  
bind\_address: 0.0.0.0  
expand\_structured\_data: false  
force\_rdns: false  
max\_message\_size: 2097152  
override\_source:   
port: 12450  
recv\_buffer\_size: 1048576  
store\_full\_message: false  
tcp\_keepalive: false

# We bundled the root and intermediate, order in the file is important.

tls\_cert\_file: /etc/ssl/your\_CA.pem  
tls\_client\_auth: disabled  
tls\_client\_auth\_cert\_file:   
tls\_enable: true  
tls\_key\_file: /etc/ssl/private/your\_private.key  
tls\_key\_password: \*\*\*\*\*\*\*\*  
use\_null\_delimiter: false

**On the Graylog client:**

**Install packages:**

yum install rsyslog-gnutls  
yum install libsemanage-python  
yum install policycoreutils-python

**Create Spool Directory**

mkdir /var/spool/rsyslog  
chown root /var/spool/rsyslog

Add rsyslogd Configuration File

Create graylog.conf file in /etc/rsyslog.d directory

**Add contents to graylog.conf**

# Setup disk assisted queues

$WorkDirectory /var/spool/rsyslog # where to place spool files  
$ActionQueueFileName fwdRule1 # unique name prefix for spool files  
$ActionQueueMaxDiskSpace 1g # 1gb space limit (use as much as possible)  
$ActionQueueSaveOnShutdown on # save messages to disk on shutdown  
$ActionQueueType LinkedList # run asynchronously  
$ActionResumeRetryCount -1 # infinite retries if host is down

#RsyslogGnuTLS  
$DefaultNetstreamDriverCAFile /etc/ssl/your\_CA.pem  
$ActionSendStreamDriver gtls  
$ActionSendStreamDriverMode 1  
$ActionSendStreamDriverAuthMode x509/name  
$ActionSendStreamDriverPermittedPeer \*.your.company.lcl

_._ @@111.55.200.24:12450;RSYSLOG\_SyslogProtocol23Format

**Set permissions so root can read**

chown root /var/rsyslog.d/10-graylogp.conf

**Add your root CA to /etc/ssl**

cp your\_CA.pem /etc/ssl/your\_CA.pem

**Make sure root owns file**

chown root /etc/ssl/your\_CA.pem

**If you have SELinux**

**View SELinux status**

getenforce  
Enforcing

**View SELinux ports allowed for rsyslog**

semanage port -l | grep syslog  
syslogd\_port\_t tcp 6514, 601  
syslogd\_port\_t udp 514, 6514, 601

**Add SELinux port**  
semanage port -a -t syslogd\_port\_t -p tcp 12450

View SELinux ports allowed for rsyslog and verify your port was added.

semanage port -l | grep syslog  
syslogd\_port\_t tcp 12450, 6514, 601  
syslogd\_port\_t udp 514, 6514, 601

**Authorize directories**

semanage fcontext -a -t syslog\_conf\_t "/var/spool/rsyslog/"  
semanage fcontext -a -t syslog\_conf\_t "/etc/rsyslog.d/"  
semanage fcontext -a -t syslog\_conf\_t "/etc/ssl/"  
restorecon -R -v /var/spool/rsyslog  
restorecon -R -v /etc/rsyslog.d  
restorecon -R -v /etc/ssl

Restart rsyslog  
service rsyslog restart

**Test:**

logger TestWithSELinux

**Warning!!!**

We had a nightmare with our Microsoft certificate authority. You have to make sure that the root CA is added to the Java keystore on the Graylog server, and I also added it to the server’s root CA’s.

To import the root certificate, we decided to “pollute” the default Java keystore for Graylog.

1. Make sure the public certificate is in pem format and Linux file (no Windows characters)
2. The default trust store of an installed Java runtime environment can be found at $JAVA\_HOME/jre/lib/security/cacerts or /etc/ssl/certs/java/cacerts (due to all the symbolic links).
3. Import:
4. keytool -importcert -keystore /etc/ssl/certs/cacerts -storepass changeit -alias YourCompany -file your\_CA.pem
5. View the YourCompany root certificate:  
keytool -list -v -keystore /etc/ssl/certs/java/cacerts | grep [your.company.com](http://your.company.com)

---

_[View the full topic](https://community.graylog.org/t/rsyslog-over-tls/263)._
