Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions docs/configuration/system/syslog.rst
Original file line number Diff line number Diff line change
Expand Up @@ -151,19 +151,19 @@ if you attempt to enable TLS while using UDP, the system will issue a warning.
* **anon** - allow encrypted connection without verifying peer identity
(not recommended, vulnerable to :abbr:`MITM (Man-in-the-Middle)`).
* **fingerprint** - verify the peer certificate against an explicitly
configured fingerprint list (set with ``permitted-peers``).
configured fingerprint list (set with ``permitted-peer``).
* **certvalid** - validate that the peer presents a certificate signed by
a trusted CA, but do not check the certificate subject name
(:abbr:`CN (Common Name)`).
* **name** - validate that the peer presents a certificate signed by a
trusted CA and that the certificate’s CN matches the value configured in
``permitted-peers``. This is the recommended secure mode for production.
``permitted-peer``. This is the recommended secure mode for production.

.. note:: The default value for the authentication mode is ``anon``.

.. cfgcmd:: set system syslog remote <address> tls permitted-peers <peer_list>
.. cfgcmd:: set system syslog remote <address> tls permitted-peer <peer>

Comma-separated list of permitted peers or certificate’s subject names (CN).
Allowed peer certificate fingerprint or subject name (CN).

* In ``fingerprint`` authentication mode: provide one or more peer
certificate fingerprints (SHA1 or SHA256).
Expand Down Expand Up @@ -195,7 +195,7 @@ Examples:
set system syslog remote syslog.example.com protocol tcp
set system syslog remote syslog.example.com tls ca-certificate my-ca
set system syslog remote syslog.example.com tls auth-mode fingerprint
set system syslog remote syslog.example.com tls permitted-peers 'SHA1:10:C4:26:...,SHA256:7B:4B:10:...'
set system syslog remote syslog.example.com tls permitted-peer 'SHA1:10:C4:26:...'

# Example of 'name' authentication mode
set system syslog remote graylog.example.com facility all level debug
Expand All @@ -204,7 +204,7 @@ Examples:
set system syslog remote graylog.example.com tls ca-certificate my-ca
set system syslog remote graylog.example.com tls certificate syslog-client
set system syslog remote graylog.example.com tls auth-mode name
set system syslog remote graylog.example.com tls permitted-peers 'graylog.example.com'
set system syslog remote graylog.example.com tls permitted-peer 'graylog.example.com'

Security Notes
^^^^^^^^^^^^^^
Expand Down