6.1.2.10 Ensure rsyslog CA certificates are configured

Information

When rsyslog forwards log data to a remote host over TLS, it uses a Certificate Authority (CA) certificate to verify the authenticity of the remote server's TLS certificate. The CA certificate is specified using the DefaultNetstreamDriverCAFile global option in rsyslog configuration.

Configuring a trusted CA certificate ensures that rsyslog only connects to log servers whose TLS certificates are signed by a known, trusted authority. Without a properly configured CA certificate, log forwarding may proceed without server identity verification, exposing the system to man-in-the-middle attacks that could intercept, tamper with, or silently discard forwarded log data. This could result in undetected data leakage or loss of audit trail integrity.

Solution

Edit /etc/rsyslog.conf or a .conf file in /etc/rsyslog.d/ to configure the correct path to the CA certificate file. Choose one of the three forms below.

Example 1 - global form, system CA bundle:

global(DefaultNetstreamDriverCAFile="/etc/ssl/certs/ca-certificates.crt")

Example 2 - global form, dedicated CA certificate:

global(DefaultNetstreamDriverCAFile="/etc/rsyslog/tls/ca.pem")

Example 3 - per-target form (rsyslog 8.2108.0+, Debian 12+ / Ubuntu 22.04+):

*.* action(type="omfwd" target="loghost.example.com" port="6514" protocol="tcp"
StreamDriver="gtls" StreamDriverMode="1" StreamDriverAuthMode="anon"
StreamDriver.CAFile="/etc/ssl/certs/ca-certificates.crt"
action.resumeRetryCount="100"
queue.type="LinkedList" queue.size="1000")

Note: Example 3 is preferred when forwarding to multiple targets with distinct CA chains; each action(...) block can carry its own StreamDriver.CAFile= . This form requires rsyslog 8.2108.0 or newer.

After editing, restart rsyslog to apply the change:

# systemctl restart rsyslog

Note: Ensure the chosen CA path is readable under AppArmor. /etc/ssl/certs/ and /etc/rsyslog.d/ are allowed by the default Debian rsyslog profile; a custom path (e.g. /etc/rsyslog/tls/ca.pem ) requires an AppArmor profile change (see Additional Information).

Impact:

Proper certificate management is required. If the CA certificate file is missing, expired, or points to an incorrect path, TLS-encrypted log forwarding will fail until the trust chain is restored. Self-signed certificates should not be used as the CA certificate for production environments.

See Also

https://workbench.cisecurity.org/benchmarks/27797

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|AU-6(3), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|6.5, CSCv7|14.4

Plugin: Unix

Control ID: ba7a54447c7eb040f83503d69ddd8e64227f97ccc00bd50753b6cc7d5c38cebf