6.1.2.9 Ensure rsyslog-gnutls is installed

Information

TLS protocol support for rsyslog (GnuTLS). This netstream plugin allows rsyslog to send and receive encrypted syslog messages via the syslog-transport-tls IETF standard protocol using GnuTLS.

Traditional syslog is a clear-text protocol that means anyone with a sniffer can have a peek at your data. rsyslog-gnutls is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them, and provides an easy way to encrypt syslog communication.

Solution

Run the following command to install rsyslog-gnutls :

# apt install rsyslog-gnutls

Impact:

Enabling TLS support using rsyslog-gnutls requires certificate management to ensure reliable encrypted logging. If misconfigured, remote log forwarding may fail until valid certificates and trusted CAs are applied.

See Also

https://workbench.cisecurity.org/benchmarks/24932

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, CSCv7|6.2, CSCv7|6.3

Plugin: Unix

Control ID: 856edc43f55ad8b5ad8f9dd58f28549e75846b71384e7005a06ae015156033cb