summaryrefslogtreecommitdiff
path: root/rsyslog.d/local-gtls.conf
blob: aef8117c96f52453294f7d1fe48756aa5420dfc6 (plain)
  1. # enable gtls driver and make it the default
  2. $ModLoad imtcp
  3. $DefaultNetstreamDriver gtls
  4. # certificate files
  5. $DefaultNetstreamDriverCAFile /etc/ssl/certs/ca-certificates.crt
  6. $DefaultNetstreamDriverCertFile /etc/ssl/certs/rsyslog.pem
  7. $DefaultNetstreamDriverKeyFile /etc/ssl/private/rsyslog.pem
  8. $InputTCPServerStreamDriverAuthMode x509/name
  9. $InputTCPServerStreamDriverMode 1 # run driver in TLS-only mode
  10. # sample reception (repeat last line for each client)
  11. #$InputTCPServerRun 514
  12. #$InputTCPServerStreamDriverPermittedPeer *.example.net
  13. # sample sending (repeat all lines for each server)
  14. #$ActionSendStreamDriverAuthMode x509/name
  15. #$ActionSendStreamDriverMode 1 # run driver in TLS-only mode
  16. #$ActionSendStreamDriverPermittedPeer central.example.net
  17. #*.* @@central.example.net:514 # forward everything to remote server