Re: [CentOS] selinux policy with rsyslog and tls/certs

2018-02-13 Thread John Ratliff
On 2/13/2018 4:48 PM, John Ratliff wrote: I've setup my rsyslog server to forward traffic to another rsyslog server on my network. It's using gTLS to encrypt the messages in transit. selinux is not allowing rsyslogd to read the certificates. They are world readable, so I don't think that is

[CentOS] selinux policy with rsyslog and tls/certs

2018-02-13 Thread John Ratliff
I've setup my rsyslog server to forward traffic to another rsyslog server on my network. It's using gTLS to encrypt the messages in transit. selinux is not allowing rsyslogd to read the certificates. They are world readable, so I don't think that is the problem. When I turn selinux mode to