Information
When rsyslog forwards log data to a remote host over TLS, it uses a Certificate Authority (CA) certificate to verify the authenticity of the remote server's TLS certificate. The CA certificate is specified using the DefaultNetstreamDriverCAFile global option in rsyslog configuration.
Configuring a trusted CA certificate ensures that rsyslog only connects to log servers whose TLS certificates are signed by a known, trusted authority. Without a properly configured CA certificate, log forwarding may proceed without server identity verification, exposing the system to man-in-the-middle attacks that could intercept, tamper with, or silently discard forwarded log data. This could result in undetected data leakage or loss of audit trail integrity.
Solution
Edit /etc/rsyslog.conf or a .conf file in /etc/rsyslog.d/ to configure the correct path to the CA certificate file. Choose one of the three forms below.
Example 1 - global form, system CA bundle:
global(DefaultNetstreamDriverCAFile="/etc/ssl/certs/ca-certificates.crt")
Example 2 - global form, dedicated CA certificate:
global(DefaultNetstreamDriverCAFile="/etc/rsyslog/tls/ca.pem")
Example 3 - per-target form (rsyslog 8.2108.0+, Debian 12+ / Ubuntu 22.04+):
*.* action(type="omfwd" target="loghost.example.com" port="6514" protocol="tcp"
StreamDriver="gtls" StreamDriverMode="1" StreamDriverAuthMode="anon"
StreamDriver.CAFile="/etc/ssl/certs/ca-certificates.crt"
action.resumeRetryCount="100"
queue.type="LinkedList" queue.size="1000")
Note: Example 3 is preferred when forwarding to multiple targets with distinct CA chains; each action(...) block can carry its own StreamDriver.CAFile= . This form requires rsyslog 8.2108.0 or newer.
After editing, restart rsyslog to apply the change:
# systemctl restart rsyslog
Note: Ensure the chosen CA path is readable under AppArmor. /etc/ssl/certs/ and /etc/rsyslog.d/ are allowed by the default Debian rsyslog profile; a custom path (e.g. /etc/rsyslog/tls/ca.pem ) requires an AppArmor profile change (see Additional Information).
Impact:
Proper certificate management is required. If the CA certificate file is missing, expired, or points to an incorrect path, TLS-encrypted log forwarding will fail until the trust chain is restored. Self-signed certificates should not be used as the CA certificate for production environments.
Item Details
Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION
References: 800-53|AC-17(2), 800-53|AU-6(3), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|6.5, CSCv7|14.4
Control ID: ba7a54447c7eb040f83503d69ddd8e64227f97ccc00bd50753b6cc7d5c38cebf