For example, after updating an expired TLS certificate and checking that the certificate is valid (Signed by correct Certificate authority and shows correct Subject name), Syslog-ng Store Box was still showing a TLS error.
Such as:
ERROR (admin@xxx.xxx.xxx.xxx) SSL certificate problem - The certificate is not a valid CA certificate; cert='XX', subject='/X=XX/ST=XXXXX/L=XXXXXX/O=XXX/OU=XXXXX/CN=xxxxxxx'
ERROR (admin@xx.xxx.xx.xx) SSL certificate problem - Missing extendedKeyUsage field values; cert='TSA', subject='/C=XX/ST=XXXXXX/L=XXXXXX/O=XXXX/OU=XXXXX/CN=xxxxxxxxxxxxx', required_extendedKeyUsage='Time Stamping'
WORKAROUND:
If the peer verification option is changed than it is mandatory to manually restart the syslog-ng component of SSB in Basic Settings > System > Service Control > Restart syslog-ng.
STATUS:
Waiting for a fix in a future release of Syslog-ng Store Box.
© 2024 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center