1.11.1 Assign a custom certificate to syslog-client

Information

Syslog-client will default to using the "local-cert". The "local-cert" is a self-signed certificate generated internally by the switch at first boot.

The syslog-server can enforce more stringent checks on the syslog-client if both share a trusted certificate authority

Solution

The 'crypto pki application' command can be used to assign a certificate to the syslog-client:

switch(config)# crypto pki application syslog-client certificate <CERT-NAME>

Impact:

Use of the "local-cert" may result in the inability of the syslog-client to form a TLS connection to the syslog-server.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: ArubaOS

Control ID: 0b00cd14a0b5486947d52de6991b433e5c4c7397c0473c480802e5c41307c93a