To implement RFC 5848 (Signed Syslog Messages)?

Garrett Cooper yanegomi at gmail.com
Thu Dec 1 09:46:46 UTC 2011


On Thu, Dec 1, 2011 at 1:01 AM, Zhihao Yuan <lichray at gmail.com> wrote:
> Hi, hackers:
>
> Red Hat's "star" developer, Lennart Poettering, is porting Windows
> Event Log to GNU/Linux :)
> https://docs.google.com/document/pub?id=1IC9yOXj7j6cdLLxWEBAGRL6wl97tFxgjLUEHIX3MSTs&pli=1
>
> Regardless of his stupid arguments, let's talk about something
> trivial. How about to implement RFC 5848 in our syslogd? It adds the
> encryption to the existing syslog message layer, and increase the
> security in transferring.
> http://tools.ietf.org/html/rfc5848
>
> Albert Mietus made a nice presentation in 2002
> http://www.slideshare.net/SoftwareBeterMaken.nl/securing-syslog-on-freebsd
>
> Not sure whether his code is accessible or not.

I agree that encryption and tcp (reliable) transport of logs should be
a must for syslogd in FreeBSD.

It's going to be interesting how things with Lennart's 'journald' play
out -- without defining an industry standard for how messages are
presented and categorized, I predict that things will turn into a mess
(I could be proved wrong, but given past experience, this is how
things evolve unless framework adoption lags standardization).

Thanks :),
-Garrett


More information about the freebsd-hackers mailing list