Rsyslog TLS配置启用后TCP 6514端口无法监听的问题求助
概述
我有一台接收外部客户端Syslog数据的服务器,但没有这些客户端的管理权限。目标是通过在TCP 6514端口上实现Syslog的TLS加密,将现有配置迁移到传输中数据加密。所有网络、防火墙规则和SELinux配置都已验证,并且我已成功测试通过TCP 6514端口接收未加密的Syslog消息。我还下载了rsyslog-gnutls作为TLS驱动。
Syslog服务器详情
$ cat /etc/os-release NAME="CentOS Linux" VERSION="7 (Core)" $ rsyslogd -v rsyslogd 8.24.0-57.el7_9.3, compiled with: PLATFORM: x86_64-redhat-linux-gnu PLATFORM (lsb_release -d): FEATURE_REGEXP: Yes GSSAPI Kerberos 5 support: Yes FEATURE_DEBUG (debug build, slow code): No 32bit Atomic operations supported: Yes 64bit Atomic operations supported: Yes memory allocator: system default Runtime Instrumentation (slow code): No uuid support: Yes Number of Bits in RainerScript integers: 64 $ yum list installed | grep rsyslog-gnutls rsyslog-gnutls.x86_64 8.24.0-57.el7_9.3
基础Syslog配置(/etc/rsyslog.conf)
这部分从之前TCP 514端口的未加密工作配置保留未修改,这里完整列出作为参考:
# rsyslog configuration file # For more information see /usr/share/doc/rsyslog-*/rsyslog_conf.html # If you experience problems, see http://www.rsyslog.com/doc/troubleshoot.html #### MODULES #### # The imjournal module bellow is now used as a message source instead of imuxsock. $ModLoad imuxsock # provides support for local system logging (e.g. via logger command) $ModLoad imjournal # provides access to the systemd journal #$ModLoad imklog # reads kernel messages (the same are read from journald) #$ModLoad immark # provides --MARK-- message capability # Provides UDP syslog reception #$ModLoad imudp #$UDPServerRun 514 # Provides TCP syslog reception #$ModLoad imtcp #$InputTCPServerRun 514 #### GLOBAL DIRECTIVES #### # Where to place auxiliary files $WorkDirectory /var/lib/rsyslog # Use default timestamp format $ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat # File syncing capability is disabled by default. This feature is usually not required, # not useful and an extreme performance hit #$ActionFileEnableSync on # Include all config files in /etc/rsyslog.d/ $IncludeConfig /etc/rsyslog.d/*.conf # Turn off message reception via local log socket; # local messages are retrieved through imjournal now. $OmitLocalLogging on # File to store the position in the journal $IMJournalStateFile imjournal.state $FileCreateMode 0640 #### RULES #### # Log all kernel messages to the console. # Logging much else clutters up the screen. #kern.* /dev/console # Log anything (except mail) of level info or higher. # Don't log private authentication messages! #*.info;mail.none;authpriv.none;cron.none /var/log/messages *.* /var/log/messages # The authpriv file has restricted access. authpriv.* /var/log/secure # Log all the mail messages in one place. mail.* -/var/log/maillog # Log all user comands local3.* /var/log/userCommands.log # Log cron stuff cron.* /var/log/cron # Everybody gets emergency messages *.emerg :omusrmsg:* # Save news errors of level crit and higher in a special file. uucp,news.crit /var/log/spooler # Save boot messages also to boot.log local7.* /var/log/boot.log
自定义包含配置(/etc/rsyslog.d/syslog-tls.conf)
这是我创建的自定义配置文件。下面的配置显示了当前在TCP 6514端口上未加密的工作状态。这是/etc/rsyslog.d目录中唯一的.conf文件,所以不会导入其他配置。之前有三个其他.conf文件,我已经重命名为.conf.bak,所以我认为rsyslogd不会读取这些文件,因为扩展名改变了:
######################################################################## # # This file is included from /etc/rsyslog.conf as long as it is located # in /etc/rsyslog.d/. # ######################################################################## $umask 0000 #not supported in global() for rsyslog versions < 8.26 global( preserveFQDN="on" parser.escapeControlCharactersOnReceive="off" #Prevent escaping of new lines #defaultNetstreamDriver="gtls" #defaultNetstreamDriverCAFile="/etc/rsyslog.d/certs/myCertAuthCertificate.pem" #defaultNetstreamDriverCertFile="/etc/rsyslog.d/certs/mySyslogUfServerChainedCertificate.pem" #defaultNetstreamDriverKeyFile="/etc/rsyslog.d/certs/mySyslogUfServerPrivKey.key" ) module( load="imtcp" maxSessions="500" disableLFDelimiter="off" #streamDriver.Name="gtls" #streamDriver.Mode="1" #streamDriver.Authmode="x509/certvalid" #streamDriver.PermittedPeers="172.16.32.155" ) module( load="builtin:omfile" dirCreateMode="0750" dirOwner="splunk" dirGroup="splunk" fileCreateMode="0640" fileOwner="splunk" fileGroup="splunk" ) template(name="foo_test" type="string" string="/var/log/foo_test/%HOSTNAME%/%$year%_%$month%_%$day%.log") ruleset(name="foo"){ if ($fromhost-ip != '127.0.0.1') then action(type="omfile" dynaFile="foo_test") stop } input(type="imtcp" port="6514")
问题描述
如果我取消syslog-tcp.conf中与TLS相关的配置参数(DefaultNetstreamDriver和StreamDriver)的注释并重启rsyslog,TCP 6514端口不再出现在netstat中。这说明我选择的配置参数和/或定义的顺序有问题。
对配置文件运行语法验证检查显示没有问题,但根据我的研究,这仅表示语法正确,运行时仍可能存在问题。
相关命令输出:
$ sudo systemctl restart rsyslog $ sudo systemctl status rsyslog ● rsyslog.service - System Logging Service Loaded: loaded (/usr/lib/systemd/system/rsyslog.service; enabled; vendor preset: enabled) Active: active (running) since Wed 2023-08-09 18:46:52 GMT; 3s ago Docs: man:rsyslogd(8) http://www.rsyslog.com/doc/ Main PID: 22327 (rsyslogd) CGroup: /system.slice/rsyslog.service └─22327 /usr/sbin/rsyslogd -n Aug 09 18:46:52 testbox01 systemd[1]: Starting System Logging Service... Aug 09 18:46:52 testbox01 systemd[1]: Started System Logging Service. $ rsyslogd -f /etc/rsyslog.conf -N1 rsyslogd: version 8.24.0-57.el7_9.3, config validation run (level 1), master config /etc/rsyslog.conf rsyslogd: End of config validation run. Bye. $ rsyslogd -f /etc/rsyslog.d/syslog-tls.conf -N3 rsyslogd: version 8.24.0-57.el7_9.3, config validation run (level 3), master config /etc/rsyslog.d/syslog-tls.conf rsyslogd: End of config validation run. Bye.
这是我第一次尝试配置带TLS的rsyslog,在此之前我对rsyslog也没有太多经验。希望熟悉rsyslog的大佬能帮我指出问题所在,提前感谢!
更新记录
8/9/23
我以调试模式运行rsyslogd,得到了大量输出。下面是我认为与问题相关的截断版本,如果需要可以提供更多输出。我注意到当rsyslogd以前台调试模式运行时,TCP 6514端口会作为监听端口出现。一旦我终止调试模式并以正常方式重启rsyslogd,TCP 6514端口就会保持关闭状态,即不会出现在netstat的LISTEN状态中。
调试输出片段:
3144.701090845:main thread : imtcp: trying to add port *:6514 3144.701096552:main thread : ratelimit:tcperver:new ratelimiter:bReduceRepeatMsgs 0 3144.701103144:main thread : caller requested object 'nsd_gtls', not found (iRet -3003) 3144.701107289:main thread : Requested to load module 'lmnsd_gtls' 3144.701112377:main thread : loading module '/usr/lib64/rsyslog/lmnsd_gtls.so' 3144.704593252:main thread : source file nsd_gtls.c requested reference for module 'lmnet', reference count now 6 3144.704601962:main thread : caller requested object 'nsd_ptcp', not found (iRet -3003) 3144.704606370:main thread : Requested to load module 'lmnsd_ptcp' 3144.704613121:main thread : loading module '/usr/lib64/rsyslog/lmnsd_ptcp.so' 3144.704740556:main thread : source file nsd_ptcp.c requested reference for module 'lmnetstrms', reference count now 4 3144.704750825:main thread : module lmnsd_ptcp of type 2 being loaded (keepType=0). 3144.704754868:main thread : entry point 'isCompatibleWithFeature' not present in module 3144.704758844:main thread : entry point 'setModCnf' not present in module 3144.704762675:main thread : entry point 'getModCnfName' not present in module 3144.704766304:main thread : entry point 'beginCnfLoad' not present in module 3144.704770744:main thread : source file nsd_gtls.c requested reference for module 'lmnsd_ptcp', reference count now 1 3144.704785499:main thread : GTLS CA file: '/etc/rsyslog.d/certs/myCertAuthCertificate.pem' 3144.705337400:main thread : source file nsdsel_gtls.c requested reference for module 'lmnsd_ptcp', reference count now 2 3144.705344715:main thread : module lmnsd_gtls of type 2 being loaded (keepType=1). 3144.705348930:main thread : entry point 'isCompatibleWithFeature' not present in module 3144.705352660:main thread : entry point 'setModCnf' not present in module 3144.705356421:main thread : entry point 'getModCnfName' not present in module 3144.705360038:main thread : entry point 'beginCnfLoad' not present in module 3144.705365118:main thread : source file netstrms.c requested reference for module 'lmnsd_gtls', reference count now 1 3144.705373376:main thread : GTLS certificate file: '/etc/rsyslog.d/certs/mySyslogUfServerChainedCertificate.pem' 3144.705377299:main thread : GTLS key file: '/etc/rsyslog.d/certs/mySyslogUfServerPrivKey.key' 3144.716630033:main thread : creating tcp listen socket on port 6514 3144.723178541:main thread : We could initialize 1 TCP listen sockets out of 2 we received - this may or may not be an error indication. 3144.723190317:main thread : Allocating buffer for 500 TCP sessions. 3144.723201696:main thread : telling modules to activate config 0x55b2e2beaa20 3144.723206050:main thread : activating config 0x55b2e2beaa20 for module builtin:omfile 3144.723210213:main thread : activating config 0x55b2e2beaa20 for module builtin:ompipe 3144.723214794:main thread : activating config 0x55b2e2beaa20 for module builtin:omfwd 3144.723219318:main thread : activating config 0x55b2e2beaa20 for module imuxsock 3144.723223556:main thread : activating config 0x55b2e2beaa20 for module imjournal 3144.723227739:main thread : activating config 0x55b2e2beaa20 for module imtcp 3144.724453266:main thread : Allowed TCP Senders: 3144.724459171:main thread : No restrictions set. 3144.724465166:main thread : iterateAllActions calling into action 0x55b2e2c03ec0 3144.724472897:main thread : action 1 queue: starting queue
8/10/23
我在/etc/sysconfig/rsyslog中添加了SYSLOGD_OPTIONS="-d"选项,如下所示。这里有个疑问:这个选项从rsyslog v3开始就被弃用了,加上它会不会导致无法按照文件注释中指定的兼容模式运行?
# Options for rsyslogd # Syslogd options are deprecated since rsyslog v3. # If you want to use them, switch to compatibility mode 2 by "-c 2" # See rsyslogd(8) for more details SYSLOGD_OPTIONS="-d"
现在我在rsyslog启动时看到了错误消息:
$ sudo systemctl status rsyslog ● rsyslog.service - System Logging Service Loaded: loaded (/usr/lib/systemd/system/rsyslog.service; enabled; vendor preset: enabled) Active: active (running) since Thu 2023-08-10 13:21:36 GMT; 6s ago Docs: man:rsyslogd(8) http://www.rsyslog.com/doc/ Main PID: 9362 (rsyslogd) CGroup: /system.slice/rsyslog.service └─9362 /usr/sbin/rsyslogd -n -d Aug 10 13:21:36 testbox01 systemd[1]: Starting System Logging Service... Aug 10 13:21:36 testbox01 rsyslogd[9362]: [origin software="rsyslogd" swVersion="8.24.0-57.el7_9.3" x-pid="9362" x-info="http://www.rsyslog.com"] start Aug

