#this variable will hold the existing syslog port of 22-loggly.conf
EXISTING_SYSLOG_PORT=
#this variable will hold the host name
HOST_NAME=
#this variable will hold the name of the linux distribution
@@ -659,8 +662,8 @@ fi
#write the contents to 22-loggly.conf file
writeContents()
{
checkIfTLS
confString
checkScriptRunningMode
installTLSDependencies
switchToInsecureModeIfTLSNotFound
WRITE_SCRIPT_CONTENTS="false"
@@ -924,33 +927,82 @@ getPassword()
echo
}
#Change TLS settings
checkIfTLS()
#function to switch system logging to insecure mode if user runs the modular script in insecure mode
switchSystemLoggingToInsecure()
{
if [[ $LOGGLY_SYSLOG_PORT== 514 ]];then
if [ "$SUPPRESS_PROMPT"=="false" ];then
whiletrue;
do
read -p "Hey you are going to setup system logs in insecure mode. Do you want to overwrite this with secure mode? (yes/no)" yn
case$ynin
[Yy]* )
logMsgToConfigSysLog "INFO""INFO: Going to overwrite the conf file: $LOGGLY_RSYSLOG_CONFFILE with secure configuration";
LOGGLY_TLS_SENDING="true"
LOGGLY_SYSLOG_PORT=6514
break;;
[Nn]* )
break;;
* ) echo"Please answer yes or no.";;
esac
done
else
logMsgToConfigSysLog "WARN""WARN: Your system logs are being send insecurely. We prefer to send system logs securely so switching to secure configuration."
@mostlyjason Actually the TLS configuration for rsyslog version less than 7 and greater than 8 is different and since I need to grep the port 6514 from the TLS configuration of 22-loggly.conf file, I had to use two grep commands to grep port 6514 from different places in both the configurations.
read -p "You are running the script using insecure mode, but your system logs are using secure mode. The script only supports a single mode for both, so would you like to switch your system logs to insecure mode? (yes/no)" yn
case$ynin
[Yy]* )
logMsgToConfigSysLog "INFO""INFO: Going to overwrite the conf file: $LOGGLY_RSYSLOG_CONFFILE with insecure configuration";
Please fix the indentation for the next PR. @Shweta-jain please create JIRA for it.
LOGGLY_SYSLOG_PORT=514
break;;
[Nn]* )
logMsgToConfigSysLog "INFO""INFO: Please re-run the script in secure mode if you want to setup secure logging"
exit 1;;
* ) echo"Please answer yes or no.";;
esac
done
else
logMsgToConfigSysLog "WARN""WARNING: You are running the script using insecure mode, but your system logs are using secure mode. The script only supports a single mode for both, so we are switching the system logs to insecure mode as well."
LOGGLY_TLS_SENDING="false"
LOGGLY_SYSLOG_PORT=514
fi
fi
fi
}
#function to switch system logging to secure mode if user runs the modular script in secure mode
read -p "You are running the script using secure mode, but your system logs are using insecure mode. The script only supports a single mode for both, so would you like to switch your system logs to secure mode? (yes/no)" yn
case$ynin
[Yy]* )
logMsgToConfigSysLog "INFO""INFO: Going to overwrite the conf file: $LOGGLY_RSYSLOG_CONFFILE with secure configuration";
LOGGLY_TLS_SENDING="true"
LOGGLY_SYSLOG_PORT=6514
break;;
[Nn]* )
logMsgToConfigSysLog "INFO""INFO: Please re-run the script in insecure mode if you want to setup insecure logging"
exit 1;;
* ) echo"Please answer yes or no.";;
esac
done
else
logMsgToConfigSysLog "WARN""WARNING: You are running the script using secure mode, but your system logs are using insecure mode. The script only supports a single mode for both, so we are switching the system logs to secure mode as well."
LOGGLY_TLS_SENDING="true"
LOGGLY_SYSLOG_PORT=6514
fi
fi
fi
}
#check whether the user is running the script in secure or insecure mode and then switch system logging accordingly.
checkScriptRunningMode()
{
if [ "$FORCE_SECURE"=="false" ];then
if [[ $LOGGLY_SYSLOG_PORT== 514 ]];then
switchSystemLoggingToInsecure
else
switchSystemLoggingToSecure
fi
fi
}
#display usage syntax
ProTip!
Use n and p to navigate between commits in a pull request.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.
We use optional third-party analytics cookies to understand how you use GitHub.com so we can build better products.
Learn more.
We use optional third-party analytics cookies to understand how you use GitHub.com so we can build better products.
You can always update your selection by clicking Cookie Preferences at the bottom of the page.
For more information, see our Privacy Statement.
Essential cookies
We use essential cookies to perform essential website functions, e.g. they're used to log you in.
Learn more
Always active
Analytics cookies
We use analytics cookies to understand how you use our websites so we can make them better, e.g. they're used to gather information about the pages you visit and how many clicks you need to accomplish a task.
Learn more
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Check and switch existing logging mode #104
Check and switch existing logging mode #104
Changes from 1 commit
3c2e7d8592084ccd1f7a0e4a4390File filter...
Jump to…
Check and switch existing logging mode
mostlyjasonSep 18, 2017
Contributor
I'm not sure you should switch this off the version number, since the newer versions are also compatible with the legacy syntax
Shwetajain148Sep 19, 2017
Author
Contributor
@mostlyjason Actually the TLS configuration for rsyslog version less than 7 and greater than 8 is different and since I need to grep the port 6514 from the TLS configuration of 22-loggly.conf file, I had to use two grep commands to grep port 6514 from different places in both the configurations.
TLS configuration for rsyslog version less than 7 can be see here- https://github.com/loggly/install-script/blob/master/Linux%20Script/configure-linux.sh#L521-L546
TLS configuration for rsyslog version greater than 8 can be see here- https://github.com/loggly/install-script/blob/master/Linux%20Script/configure-linux.sh#L549-L569
That is why I used two different commands to grep the 6514 port based on rsyslog versions.
Also, the NON-TLS configuration is same for any rsyslog version so I used only one grep command to pick the port 514 from 22-loggly.conf file.
mchaudharyOct 10, 2017
•
edited
Contributor
Please fix the indentation for the next PR. @Shweta-jain please create JIRA for it.