Re: [OPSAWG] Syslog message to Remote Rerver
"ietfdbh" <[email protected]> Mon, 25 Feb 2013 01:54:14 -0500
| Newsgroups | gmane.ietf.syslog,gmane.ietf.opsawg |
|---|---|
| Message-ID | <[email protected]> |
This is a multipart message in MIME format. --===============6548515804875041247== Content-Type: multipart/alternative; boundary="----=_NextPart_000_0044_01CE12FB.03DF4C20" Content-Language: en-us This is a multipart message in MIME format. ------=_NextPart_000_0044_01CE12FB.03DF4C20 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit From: [email protected] [mailto:[email protected]] On Behalf Of Aditya Dogra (addogra) Sent: Thursday, February 21, 2013 11:25 AM To: [email protected]; [email protected] Subject: [OPSAWG] Syslog message to Remote Rerver Hi All , Currently syslog messages collected locally on the network device are transmitted to the remote syslog servers as per RFC 5424 (UDP protocol used for transmission) and RFC 3195 (TCP protocol used for transmission) [dbh>] RFC5424 defines the IETF version of the syslog protocol message format (not the UDP transport). RFC5424 RECOMMENDS using a TLS-based transport (RFC5425) rather than a UDP-based or plain-TCP-based transport for syslog. If you use a UDP-based transport for interoperability, it should probably follow RFC5426. The IETF standard for syslog over UDP (RFC5426) states: " Network administrators and architects should be aware of the significant reliability and security issues of this transport, which stem from the use of UDP." Note that RFC6587 (plain TCP transport for syslog) is Historic, and contains an IESG Note: The IESG does not recommend implementing or deploying syslog over plain tcp, which is described in this document, because it lacks the ability to enable strong security [RFC3365]. Implementation of the TLS transport [RFC5425] is recommended so that appropriate security features are available to operators who want to deploy secure syslog. Similarly, those security features can be turned off for those who do not want them. However, we have observed that increasingly, customers are using syslog messages archived in the remote server for business logic . [dbh>] If customers are using archived messages, they might want to consider using signing syslog messages. RFC5848, Signed syslog, describes a mechanism to add origin authentication, message integrity, replay resistance, message sequencing, and detection of missing messages to the transmitted syslog messages. Signed syslog helps ensure integrity of messages both in-transit and in archived storage. I think that would be a valuable feature in support of business logic. David Harrington [email protected] +1-603-828-1401 co-chair, syslog WG In some networks, it is possible that some of the syslog messages may be dropped due to link failure or other network conditions. However, the customers are expecting much higher resiliency for the syslog messages. The questions we seek clarification are: a) What are the expectations from the external syslog delivery? b) Should we rely on syslog's alone ? Please note that SNMP traps functionality for network management is also there.? Your thoughts and suggestions much appreciated. Regards, Aditya dogra ------=_NextPart_000_0044_01CE12FB.03DF4C20 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" = xmlns:o=3D"urn:schemas-microsoft-com:office:office" = xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" = xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta = http-equiv=3DContent-Type content=3D"text/html; = charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 14 = (filtered medium)"><style><!-- /* Font Definitions */ @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Tahoma; panose-1:2 11 6 4 3 5 4 4 2 4;} @font-face {font-family:Consolas; panose-1:2 11 6 9 2 2 4 3 2 4;} @font-face {font-family:"Book Antiqua"; panose-1:2 4 6 2 5 3 5 3 3 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:11.0pt; font-family:"Calibri","sans-serif";} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:purple; text-decoration:underline;} p.MsoPlainText, li.MsoPlainText, div.MsoPlainText {mso-style-priority:99; mso-style-link:"Plain Text Char"; margin:0in; margin-bottom:.0001pt; font-size:10.5pt; font-family:Consolas;} span.PlainTextChar {mso-style-name:"Plain Text Char"; mso-style-priority:99; mso-style-link:"Plain Text"; font-family:Consolas;} span.EmailStyle19 {mso-style-type:personal; font-family:"Book Antiqua","serif"; color:windowtext;} span.EmailStyle20 {mso-style-type:personal-reply; font-family:"Calibri","sans-serif"; color:#1F497D;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt;} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue = vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><a = name=3D"_MailEndCompose"><span = style=3D'color:#1F497D'><o:p> </o:p></span></a></p><p = class=3DMsoNormal><span = style=3D'color:#1F497D'><o:p> </o:p></span></p><div><div = style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in = 0in 0in'><p class=3DMsoNormal><b><span = style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>= </b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> = [email protected] [mailto:[email protected]] <b>On Behalf Of = </b>Aditya Dogra (addogra)<br><b>Sent:</b> Thursday, February 21, 2013 = 11:25 AM<br><b>To:</b> [email protected]; = [email protected]<br><b>Subject:</b> [OPSAWG] Syslog message to Remote = Rerver<o:p></o:p></span></p></div></div><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book Antiqua","serif"'>Hi All = ,<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'><o:p> </o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book Antiqua","serif"'>Currently = syslog messages collected locally on the network device are transmitted = to the remote syslog servers as per RFC 5424 (UDP protocol used for = transmission) and RFC 3195 (TCP protocol used for transmission) = <o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif";color:#1F497D'><o:p> </o:p></span></p><p = class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><b><i><span = style=3D'color:#1F497D'>[dbh>] </span></i></b><span = style=3D'font-size:10.0pt;font-family:"Courier New"'>RFC5424 defines the = IETF version of the syslog protocol message format (not the UDP = transport).<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'>RFC5424 RECOMMENDS = using a TLS-based transport (RFC5425) rather than a UDP-based or = plain-TCP-based transport for syslog.<o:p></o:p></span></p><p = class=3DMsoNormal style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier = New"'><o:p> </o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'>If you use a = UDP-based transport for interoperability, it should probably follow = RFC5426.<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'>The IETF standard = for syslog over UDP (RFC5426) states:<o:p></o:p></span></p><p = class=3DMsoNormal style=3D'line-height:14.4pt'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'>“ = Network administrators and architects should be aware of = the<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> = significant reliability and security issues of this transport, = which<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> stem = from the use of UDP.”<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier = New"'><o:p> </o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'>Note that RFC6587 = (plain TCP transport for syslog) is Historic, and contains an IESG = Note:<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier = New"'><o:p> </o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> The = IESG does not recommend implementing or deploying syslog = over<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> plain = tcp, which is described in this document, because it lacks = the<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> = ability to enable strong security [RFC3365].<o:p></o:p></span></p><p = class=3DMsoNormal style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier = New"'><o:p> </o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> = Implementation of the TLS transport [RFC5425] is recommended so = that<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> = appropriate security features are available to operators who want = to<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> deploy = secure syslog. Similarly, those security features can = be<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> turned = off for those who do not want them.<o:p></o:p></span></p><p = class=3DMsoNormal style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier = New"'><o:p> </o:p></span></p><p class=3DMsoNormal><span = style=3D'color:#1F497D'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'>However, we have observed that increasingly, customers = are using syslog messages archived in the remote server for business = logic .<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'color:#1F497D'><o:p> </o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><b><i><span = style=3D'color:#1F497D'>[dbh>] </span></i></b><span = style=3D'font-size:10.0pt;font-family:"Courier New"'>If customers are = using archived messages, they might want to consider using signing = syslog messages.<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><b><i><span = style=3D'color:#1F497D'> = </span></i></b><span style=3D'color:#1F497D'> </span>RFC5848, = Signed syslog<b><i>, </i></b><span = style=3D'font-size:10.0pt;font-family:"Courier New"'>describes a = mechanism to add origin authentication,<o:p></o:p></span></p><p = class=3DMsoNormal style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> = message integrity, replay resistance, message sequencing, = and<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'> = detection of missing messages to the transmitted syslog = messages.<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'>Signed syslog helps = ensure integrity of messages both in-transit and in archived = storage.<o:p></o:p></span></p><p class=3DMsoNormal = style=3D'line-height:14.4pt;background:white'><span = style=3D'font-size:10.0pt;font-family:"Courier New"'>I think that would = be a valuable feature in support of business = logic.<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'color:#1F497D'><o:p> </o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'= >David Harrington</span><span = style=3D'font-size:12.0pt;font-family:"Times New = Roman","serif";color:#1F497D'><o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'= ><a = href=3D"mailto:[email protected]">[email protected]</a></span><span = style=3D'font-size:12.0pt;font-family:"Times New = Roman","serif";color:#1F497D'><o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'= >+1-603-828-1401</span><span = style=3D'color:#1F497D'><o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif";color:#1F497D'>co-chair, syslog = WG<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'color:#1F497D'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'>In some networks, it is possible that some of the = syslog messages may be dropped due to link failure or other network = conditions. <o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book Antiqua","serif"'>However, = the customers are expecting much higher resiliency for the syslog = messages. <span style=3D'color:#1F497D'><o:p></o:p></span></span></p><p = class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'><o:p> </o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book Antiqua","serif"'>The = questions we seek clarification are: <o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'><o:p> </o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'>a) = What are the expectations from the external syslog delivery? = <o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'><o:p> </o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'>b) = Should we rely on syslog's alone ? Please note that SNMP traps = functionality for network management is also = there.?<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'><o:p> </o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'><o:p> </o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'> <o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book Antiqua","serif"'>Your = thoughts and suggestions much appreciated. <o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'><o:p> </o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:12.0pt;font-family:"Book = Antiqua","serif"'><o:p> </o:p></span></p><p = class=3DMsoNormal>Regards,<o:p></o:p></p><p class=3DMsoNormal>Aditya = dogra<o:p></o:p></p><p class=3DMsoNormal><o:p> </o:p></p><p = class=3DMsoNormal><o:p> </o:p></p></div></body></html> ------=_NextPart_000_0044_01CE12FB.03DF4C20-- --===============6548515804875041247== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Syslog mailing list [email protected] https://www.ietf.org/mailman/listinfo/syslog --===============6548515804875041247==--