From 685f630a421c28e0f1863f9386c43b55fac36a8e Mon Sep 17 00:00:00 2001 From: root Date: Wed, 4 Mar 2009 20:03:11 +0100 Subject: Rename rsyslog config snippets for proper load ordering. --- rsyslog.d/local-gtls-client.conf | 6 ------ rsyslog.d/local-gtls-common.conf | 21 +++++++++++++++++++++ rsyslog.d/local-gtls-receive.conf | 5 +++++ rsyslog.d/local-gtls-send.conf | 6 ++++++ rsyslog.d/local-gtls-server.conf | 5 ----- rsyslog.d/local-gtls.conf | 21 --------------------- 6 files changed, 32 insertions(+), 32 deletions(-) delete mode 100644 rsyslog.d/local-gtls-client.conf create mode 100644 rsyslog.d/local-gtls-common.conf create mode 100644 rsyslog.d/local-gtls-receive.conf create mode 100644 rsyslog.d/local-gtls-send.conf delete mode 100644 rsyslog.d/local-gtls-server.conf delete mode 100644 rsyslog.d/local-gtls.conf (limited to 'rsyslog.d') diff --git a/rsyslog.d/local-gtls-client.conf b/rsyslog.d/local-gtls-client.conf deleted file mode 100644 index e692b07..0000000 --- a/rsyslog.d/local-gtls-client.conf +++ /dev/null @@ -1,6 +0,0 @@ -# restrict access based on server certificate -# (repeat all lines for each server) -#$ActionSendStreamDriverAuthMode x509/name -#$ActionSendStreamDriverMode 1 # run driver in TLS-only mode -#$ActionSendStreamDriverPermittedPeer central.example.net -#*.* @@central.example.net:514 # forward everything to remote server diff --git a/rsyslog.d/local-gtls-common.conf b/rsyslog.d/local-gtls-common.conf new file mode 100644 index 0000000..aef8117 --- /dev/null +++ b/rsyslog.d/local-gtls-common.conf @@ -0,0 +1,21 @@ +# enable gtls driver and make it the default +$ModLoad imtcp +$DefaultNetstreamDriver gtls + +# certificate files +$DefaultNetstreamDriverCAFile /etc/ssl/certs/ca-certificates.crt +$DefaultNetstreamDriverCertFile /etc/ssl/certs/rsyslog.pem +$DefaultNetstreamDriverKeyFile /etc/ssl/private/rsyslog.pem + +$InputTCPServerStreamDriverAuthMode x509/name +$InputTCPServerStreamDriverMode 1 # run driver in TLS-only mode + +# sample reception (repeat last line for each client) +#$InputTCPServerRun 514 +#$InputTCPServerStreamDriverPermittedPeer *.example.net + +# sample sending (repeat all lines for each server) +#$ActionSendStreamDriverAuthMode x509/name +#$ActionSendStreamDriverMode 1 # run driver in TLS-only mode +#$ActionSendStreamDriverPermittedPeer central.example.net +#*.* @@central.example.net:514 # forward everything to remote server diff --git a/rsyslog.d/local-gtls-receive.conf b/rsyslog.d/local-gtls-receive.conf new file mode 100644 index 0000000..b17d55a --- /dev/null +++ b/rsyslog.d/local-gtls-receive.conf @@ -0,0 +1,5 @@ +# enable gtls reception +$InputTCPServerRun 514 + +# restrict access based on client certificate +#$InputTCPServerStreamDriverPermittedPeer *.example.net diff --git a/rsyslog.d/local-gtls-send.conf b/rsyslog.d/local-gtls-send.conf new file mode 100644 index 0000000..e692b07 --- /dev/null +++ b/rsyslog.d/local-gtls-send.conf @@ -0,0 +1,6 @@ +# restrict access based on server certificate +# (repeat all lines for each server) +#$ActionSendStreamDriverAuthMode x509/name +#$ActionSendStreamDriverMode 1 # run driver in TLS-only mode +#$ActionSendStreamDriverPermittedPeer central.example.net +#*.* @@central.example.net:514 # forward everything to remote server diff --git a/rsyslog.d/local-gtls-server.conf b/rsyslog.d/local-gtls-server.conf deleted file mode 100644 index b17d55a..0000000 --- a/rsyslog.d/local-gtls-server.conf +++ /dev/null @@ -1,5 +0,0 @@ -# enable gtls reception -$InputTCPServerRun 514 - -# restrict access based on client certificate -#$InputTCPServerStreamDriverPermittedPeer *.example.net diff --git a/rsyslog.d/local-gtls.conf b/rsyslog.d/local-gtls.conf deleted file mode 100644 index aef8117..0000000 --- a/rsyslog.d/local-gtls.conf +++ /dev/null @@ -1,21 +0,0 @@ -# enable gtls driver and make it the default -$ModLoad imtcp -$DefaultNetstreamDriver gtls - -# certificate files -$DefaultNetstreamDriverCAFile /etc/ssl/certs/ca-certificates.crt -$DefaultNetstreamDriverCertFile /etc/ssl/certs/rsyslog.pem -$DefaultNetstreamDriverKeyFile /etc/ssl/private/rsyslog.pem - -$InputTCPServerStreamDriverAuthMode x509/name -$InputTCPServerStreamDriverMode 1 # run driver in TLS-only mode - -# sample reception (repeat last line for each client) -#$InputTCPServerRun 514 -#$InputTCPServerStreamDriverPermittedPeer *.example.net - -# sample sending (repeat all lines for each server) -#$ActionSendStreamDriverAuthMode x509/name -#$ActionSendStreamDriverMode 1 # run driver in TLS-only mode -#$ActionSendStreamDriverPermittedPeer central.example.net -#*.* @@central.example.net:514 # forward everything to remote server -- cgit v1.2.3