Rsyslog服务器TLS配置异常:s_client连接无证书且挂起
Let's break down the issues you're facing with rsyslog TLS setup and walk through actionable steps to fix the certificate retrieval hang and connection problem.
First, Validate Core Configuration & Permissions
Rsyslog is picky about file paths, permissions, and certificate chain format—start here, since this is the most common root cause.
Verify Rsyslog TLS Module & Config Params
Make sure you've loaded the required modules and set the correct global TLS directives in your rsyslog config (usually/etc/rsyslog.confor a file in/etc/rsyslog.d/):# Load necessary modules module(load="imtcp") module(load="gnutls") # Global TLS settings global( DefaultNetstreamDriver="gtls" DefaultNetstreamDriverCAFile="/path/to/your/ca-chain.pem" DefaultNetstreamDriverCertFile="/path/to/your/server-cert.pem" DefaultNetstreamDriverKeyFile="/path/to/your/server-key.pem" ) # TLS-enabled TCP input on port 6514 input(type="imtcp" port="6514" streamdriver.name="gtls" streamdriver.mode="1" # Enforce TLS (no plaintext fallback) streamdriver.authmode="x509/name" )Double-check that all file paths are absolute and point to the correct files—typos here will silently break TLS.
Fix File Permissions
Rsyslog runs as therootorrsysloguser, so it needs read access to your certs/keys. Lock down the private key tightly:chown root:root /path/to/your/server-key.pem chmod 600 /path/to/your/server-key.pem chown root:root /path/to/your/server-cert.pem /path/to/your/ca-chain.pem chmod 644 /path/to/your/server-cert.pem /path/to/your/ca-chain.pem
Validate Your CA Certificate Chain
Domain-signed certs require a properly formatted chain file—if this is malformed, rsyslog can't present the cert to clients, leading to hangs.
Check Chain Format
Your CA chain file should be a single PEM file containing:- Intermediate CA certificate(s) (in order, starting with the one that signed your server cert)
- Root CA certificate
Each cert must be wrapped in-----BEGIN CERTIFICATE-----and-----END CERTIFICATE-----blocks, with no extra whitespace or invalid characters.
Verify Chain Validity
Use OpenSSL to confirm the chain works with your server cert:openssl verify -CAfile /path/to/your/ca-chain.pem /path/to/your/server-cert.pemYou should see
OKas output. If not, you're missing an intermediate cert or have the order wrong—reach out to your domain CA to get the correct chain.
Troubleshoot the OpenSSL s_client Test
The hang you're seeing often comes from incorrect TLS version negotiation or missing firewall rules.
Run a Specific TLS Version Test
Rsyslog 8.33.1 might not support newer TLS versions by default, so specify TLS 1.2 (a widely compatible option) in your s_client command:openssl s_client -connect your-server-ip:6514 -tls1_2 -CAfile /path/to/your/ca-chain.pemThis avoids negotiation failures that cause hangs.
Check Firewall & EC2 Security Groups
Don't forget the basics:- Ensure your EC2 security group allows inbound TCP traffic on port 6514
- Verify Amazon Linux's firewall (iptables or firewalld) has a rule permitting port 6514:
sudo iptables -L | grep 6514
If no rule exists, add it and save the config.
Check Rsyslog Logs for Hidden Errors
Rsyslog logs TLS issues to system logs (usually /var/log/messages or /var/log/rsyslog.log). Run this to filter for relevant entries:
tail -f /var/log/messages | grep -i "tls\|gnutls\|cert"
Look for errors like:
error loading certificate file: Indicates a path/permissions issuegnutls_handshake failed: Points to a chain or TLS version problemstreamdriver not found: Means you forgot to load thegnutlsmodule
Final Steps
After fixing any issues found above, restart rsyslog to apply changes:
sudo systemctl restart rsyslog
Re-run the s_client test—you should see the server certificate presented, and the connection should complete without hanging.
内容的提问来源于stack exchange,提问作者lowly_junior_sysadmin

