summaryrefslogtreecommitdiffstats
path: root/doc/imgssapi.html
blob: a44af8edb513a3b2748d5c899e1faea900f7b6d7 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html><head>
<meta http-equiv="Content-Language" content="en"><title>GSSAPI Syslog Input Module</title>

</head>
<body>
<h1>GSSAPI Syslog Input Module</h1>
<p><b>Module Name:&nbsp;&nbsp;&nbsp; imtcp</b></p>
<p><b>Author: </b>varmojfekoj</p>
<p><b>Description</b>:</p>
<p>Provides the ability to receive syslog messages from the
network protected via Kerberos 5 encryption and authentication. This
module also contains the functionality found in <a href="imtcp.html">imtcp</a>,
which can not be used if imgssapi is used.</p>
<p><b>Configuration Directives</b>:</p>
<ul>
<li>InputGSSServerRun &lt;port&gt;<br>
Starts a GSSAPI server on selected port - note that this runs
independently from the TCP server.</li>
<li>InputGSSServerServiceName &lt;name&gt;<br>
The service name to use for the GSS server.</li>
<li>$InputGSSServerPermitPlainTCP on|<span style="font-weight: bold;">off</span><br>
Permits the server to receive plain tcp syslog (without GSS) on the
same port</li>
<li>$InputTCPMaxSessions &lt;number&gt;<br>
Sets the maximum number of sessions supported</li>
</ul>
<b>Caveats/Known Bugs:</b>
<ul>
<li>module always binds to all interfaces</li>
<li>only a single listener can be bound (one each for GSS and
plain TCP)</li>
<li>duplicates <a href="imtcp.html">imtcp</a>
functionality and thus conflicts with it. This will change in the
future. Unfortunately, that also means that&nbsp;your config files
probably&nbsp;need &nbsp;to be changed in the future when that
change happens.</li>
</ul>
<p><b>Sample:</b></p>
<p>This sets up a GSS server on port 1514 that also permits to
receive plain tcp syslog messages (on the same port):<br>
</p>
<textarea rows="15" cols="60">$ModLoad imtcp.so # needs to be done just once
$InputGSSServerRun 1514
$InputGSSServerPermitPlainTCP on
</textarea>
<p>[<a href="rsyslog_conf.html">rsyslog.conf overview</a>]
[<a href="manual.html">manual index</a>] [<a href="http://www.rsyslog.com/">rsyslog site</a>]</p>
<p><font size="2">This documentation is part of the
<a href="http://www.rsyslog.com/">rsyslog</a>
project.<br>
Copyright © 2008 by <a href="http://www.gerhards.net/rainer">Rainer
Gerhards</a> and
<a href="http://www.adiscon.com/">Adiscon</a>.
Released under the GNU GPL version 3 or higher.</font></p>
</body></html>