6.1.2.9 Ensure rsyslog forwarding uses gtls

Information

Network stream drivers are a layer between various parts of rsyslogd (e.g. the imtcp module) and the transport layer. They provide sequenced delivery, authentication and confidentiality to the upper layers. Drivers implement different capabilities.

Note: While gtls (GnuTLS) is used in this recommendation, ossl (OpenSSL via rsyslog-openssl) is an acceptable alternative stream driver. Replace DefaultNetstreamDriver gtls with DefaultNetstreamDriver ossl and ensure rsyslog-openssl is installed if using the OpenSSL driver.

StreamDriver must be set to gtls to enable TLS for encrypting syslog traffic.

Solution

Edit rsyslog.conf or a .conf file in /etc/rsyslog.d/ to use gtls :

Example /etc/rsyslog.d/40-forward.conf

# certificate files - just CA for a client
global(DefaultNetstreamDriverCAFile="/path/to/contrib/gnutls/ca.pem")

# set up the action for all messages
action(type="omfwd" protocol="tcp" target="s.example.net" port="6514"
StreamDriver="gtls" StreamDriverMode="1" StreamDriverAuthMode="anon")

Impact:

If the TLS stream driver is not configured, syslog traffic is transmitted in cleartext and is susceptible to interception. Certificate management overhead is required; if the CA certificate expires or the path is misconfigured, encrypted log forwarding will fail until the trust chain is restored.

See Also

https://workbench.cisecurity.org/benchmarks/27797

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: 856edc43f55ad8b5ad8f9dd58f28549e75846b71384e7005a06ae015156033cb