syslog_tls_verify
Description
The syslog_tls_verify parameter controls whether Fluentd verifies the certificate of a tcp+tls endpoint set in syslog. When it is true, Fluentd checks the endpoint's certificate chain against the public certificate authorities trusted by the log forwarder image and does not send logs to an endpoint that fails the check. Set it to false to forward to an endpoint with a self-signed or private-CA certificate.
Default Value
The default value is true.
An endpoint whose certificate chains to a public certificate authority, and that sends its intermediate certificates, receives logs with no change. An endpoint with a self-signed or private-CA certificate, or one that sends only its leaf certificate, receives nothing until syslog_tls_verify is set to false.
Use Cases
- Public syslog services: leave the default so logs go only to an endpoint whose certificate is valid for its hostname.
- Self-signed or private-CA endpoints: set
falseto forward to a receiver inside your network that uses a certificate a public CA did not issue.
Setting Parameters
$ convox rack params set syslog_tls_verify=false -r rackName
Updating parameters... OK
The change rolls the Fluentd pods on every node. CloudWatch delivery continues throughout.
Viewing Current Configuration
$ convox rack params -r rackName
Additional Information
- Scope: applies only to
tcp+tlsendpoints. It has no effect ontcporudpendpoints, or whensyslogis not set. - Hostname check: with either value, the endpoint's certificate must name the host in the
syslogURL. Fluentd sends the hostname as SNI unless the URL uses an IP address, and connects with TLS 1.2 or later. - Intermediate certificates: verification uses only the certificate authorities in the image. An endpoint must send its intermediate certificates; one that sends only its leaf certificate fails even when its CA is public.
- Failing endpoint: an endpoint that fails verification receives nothing. Fluentd logs one warning per minute naming the TLS error and keeps writing to CloudWatch, so
convox logsandconvox rack logsare unaffected. - Validation: boolean. The CLI rejects other values with
param 'syslog_tls_verify' must be 'true' or 'false' (got "<value>"). - Version: requires Rack version
3.25.10or later and CLI version3.25.10or later. An older CLI rejects the parameter withunknown parameter 'syslog_tls_verify' for aws provider. - Downgrade: downgrading below
3.25.10removes the parameter withNOTICE: removing parameters not supported by version <version>: syslog_tls_verifyon stderr. A Rack managed through the Console keeps the stored value and applies it again on the next update to3.25.10or later. A self-managed Rack drops the value, so set it again after upgrading. - Providers: AWS only. GCP, Azure and DigitalOcean Racks do not have this parameter.
See Also
- syslog for the endpoint and what Fluentd forwards
- Logging for log forwarding on every provider
- fluentd_disable for turning Fluentd off