-
Story
-
Resolution: Done-Errata
-
Undefined
-
CentOS Stream 8
-
rsyslog-8.2310.0-3.el9
-
Rebase
-
rhel-sst-security-special-projects
-
ssg_security
-
None
-
QE ack, Dev ack
-
False
-
-
Yes
-
None
-
Enhancement
-
-
Done
-
-
Unspecified
-
None
Description of problem:
Rsyslog 8.2108.0 introduced a setting `streamDriver.CAFile` which allows setting a CA for a specific connection. This drastically cleans up streams using TLS.
Without this, you are required to set the global default ca which is inherited by everyone
Version-Release number of selected component (if applicable):rsyslog-8.2102.0-104.el9.x86_64
How reproducible: 100%
Steps to Reproduce:
1. Try to use streamDriver.CAFile
2.
3.
Actual results:
version of rsyslog is too old
Expected results:
Able to set the CA on the stream I'm telling to encrypt.
Additional info:
- external trackers
- links to
-
RHBA-2023:124274 rsyslog bug fix and enhancement update