You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Rsyslog服务器TLS配置异常:s_client连接无证书且挂起

Troubleshooting Rsyslog TLS Configuration with Domain CA on Amazon Linux 2017.09

Let's break down the issues you're facing with rsyslog TLS setup and walk through actionable steps to fix the certificate retrieval hang and connection problem.

First, Validate Core Configuration & Permissions

Rsyslog is picky about file paths, permissions, and certificate chain format—start here, since this is the most common root cause.

  1. Verify Rsyslog TLS Module & Config Params
    Make sure you've loaded the required modules and set the correct global TLS directives in your rsyslog config (usually /etc/rsyslog.conf or a file in /etc/rsyslog.d/):

    # Load necessary modules
    module(load="imtcp")
    module(load="gnutls")
    
    # Global TLS settings
    global(
        DefaultNetstreamDriver="gtls"
        DefaultNetstreamDriverCAFile="/path/to/your/ca-chain.pem"
        DefaultNetstreamDriverCertFile="/path/to/your/server-cert.pem"
        DefaultNetstreamDriverKeyFile="/path/to/your/server-key.pem"
    )
    
    # TLS-enabled TCP input on port 6514
    input(type="imtcp" port="6514"
        streamdriver.name="gtls"
        streamdriver.mode="1"  # Enforce TLS (no plaintext fallback)
        streamdriver.authmode="x509/name"
    )
    

    Double-check that all file paths are absolute and point to the correct files—typos here will silently break TLS.

  2. Fix File Permissions
    Rsyslog runs as the root or rsyslog user, so it needs read access to your certs/keys. Lock down the private key tightly:

    chown root:root /path/to/your/server-key.pem
    chmod 600 /path/to/your/server-key.pem
    chown root:root /path/to/your/server-cert.pem /path/to/your/ca-chain.pem
    chmod 644 /path/to/your/server-cert.pem /path/to/your/ca-chain.pem
    

Validate Your CA Certificate Chain

Domain-signed certs require a properly formatted chain file—if this is malformed, rsyslog can't present the cert to clients, leading to hangs.

  1. Check Chain Format
    Your CA chain file should be a single PEM file containing:

    • Intermediate CA certificate(s) (in order, starting with the one that signed your server cert)
    • Root CA certificate
      Each cert must be wrapped in -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- blocks, with no extra whitespace or invalid characters.
  2. Verify Chain Validity
    Use OpenSSL to confirm the chain works with your server cert:

    openssl verify -CAfile /path/to/your/ca-chain.pem /path/to/your/server-cert.pem
    

    You should see OK as output. If not, you're missing an intermediate cert or have the order wrong—reach out to your domain CA to get the correct chain.

Troubleshoot the OpenSSL s_client Test

The hang you're seeing often comes from incorrect TLS version negotiation or missing firewall rules.

  1. Run a Specific TLS Version Test
    Rsyslog 8.33.1 might not support newer TLS versions by default, so specify TLS 1.2 (a widely compatible option) in your s_client command:

    openssl s_client -connect your-server-ip:6514 -tls1_2 -CAfile /path/to/your/ca-chain.pem
    

    This avoids negotiation failures that cause hangs.

  2. Check Firewall & EC2 Security Groups
    Don't forget the basics:

    • Ensure your EC2 security group allows inbound TCP traffic on port 6514
    • Verify Amazon Linux's firewall (iptables or firewalld) has a rule permitting port 6514:
      sudo iptables -L | grep 6514
      

    If no rule exists, add it and save the config.

Check Rsyslog Logs for Hidden Errors

Rsyslog logs TLS issues to system logs (usually /var/log/messages or /var/log/rsyslog.log). Run this to filter for relevant entries:

tail -f /var/log/messages | grep -i "tls\|gnutls\|cert"

Look for errors like:

  • error loading certificate file: Indicates a path/permissions issue
  • gnutls_handshake failed: Points to a chain or TLS version problem
  • streamdriver not found: Means you forgot to load the gnutls module

Final Steps

After fixing any issues found above, restart rsyslog to apply changes:

sudo systemctl restart rsyslog

Re-run the s_client test—you should see the server certificate presented, and the connection should complete without hanging.

内容的提问来源于stack exchange,提问作者lowly_junior_sysadmin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:03:45