logMsgToConfigSysLog "ERROR""ERROR: selinux status is 'Enforcing'. Please disable it and start the rsyslog daemon manually."
logMsgToConfigSysLog "ERROR""ERROR: selinux status is 'Enforcing'. Please manually restart the rsyslog daemon or turn off selinux by running 'setenforce 0' and then rerun the script."
logMsgToConfigSysLog "ERROR""ERROR: The rsyslog-gnutls package could not be installed automatically. Please install it and then run the script again. Manual instructions to configure rsyslog are available at https://www.loggly.com/docs/rsyslog-tls-configuration/. Rsyslog troubleshooting instructions are available at https://www.loggly.com/docs/troubleshooting-rsyslog/."
exit 1
fi
else
fi
elif [ "$FORCE_SECURE"=="true" ];then
logMsgToConfigSysLog "WARN""WARN: The rsyslog-gnutls package could not be download automatically because your package manager could not be found. Please install it and restart the rsyslog service to send logs to Loggly."
else
DEPENDENCIES_INSTALLED="false";
fi
inputStr=$inputStrTls
fi
}
logMsgToConfigSysLog "WARN""WARN: The rsyslog-gnutls package could not be download automatically because your package manager couldn't be found. Please download it manually for your distribution and then run the script again."
fi
inputStr=$inputStrTls
#prompt users if they want to switch to insecure mode on gnutls-package download failure
switchToInsecureModeIfTLSNotFound()
{
if [ "$DEPENDENCIES_INSTALLED"=="false" ];then
if [ "$SUPPRESS_PROMPT"=="false" ];then
logMsgToConfigSysLog "WARN""WARN: The rsyslog-gnutls package could not be download automatically because your package manager could not be found."
whiletrue;
do
read -p "Do you wish to continue with insecure mode? (yes/no)" yn
case$ynin
[Yy]* )
logMsgToConfigSysLog "INFO""INFO: Going to overwrite the conf file: $LOGGLY_RSYSLOG_CONFFILE with insecure configuration";
@mostlyjason This code will be executed whenever rsyslog-gnutls package couldn't be download or package manager is not found in the system. It will prompt the user to switch to insecure mode. For example, if I am in SUSE environment where the package manager is different from yum and apt-get so the rsyslog-gnutls package will not be downloaded. In that case, the script will prompt the user to switch to insecure mode.
LOGGLY_SYSLOG_PORT=514
break;;
[Nn]* )
logMsgToConfigSysLog "INFO""INFO: Since the rsyslog-gnutls package could not be installed automatically, please install it yourself and then re-run the script using the --force-secure flag. This option will force the secure TLS configuration instead of falling back on insecure mode. It is useful for Linux distributions where this script cannot automatically detect the dependency using yum or apt-get.";
exit 1;;
* ) echo"Please answer yes or no.";;
esac
done
else
logMsgToConfigSysLog "WARN""WARN: The rsyslog-gnutls package could not be download automatically because your package manager could not be found, continuing with insecure mode."
@mchaudhary and @mostlyjason, Here I have replaced the wget command wth curl. I looked in differents environments to check if curl is present or not and I found it installed in almost each distribution listed below
Amazon AMI 2017.03
Ubuntu 14
RedHat
SUSE
Fedora
CentOS
I have also tested the configure-linux.sh script with this updated code and everything looked fine to me.
@mchaudhary I just created a new Ubuntu 12.04 instance on Amazon and I could see that curl is pre-installed on it and there is no need to install it manually.
usage: configure-linux [-a loggly auth account or subdomain] [-r to remove]
usage: configure-linux [-h for help]
EOF
@@ -949,6 +999,11 @@ if [ "$1" != "being-invoked" ]; then
LOGGLY_TLS_SENDING="false"
LOGGLY_SYSLOG_PORT=514
;;
--force-secure )
FORCE_SECURE="true"
LOGGLY_TLS_SENDING="true"
LOGGLY_SYSLOG_PORT=6514
;;
-h | --help)
usage
exit
@@ -978,6 +1033,3 @@ fi
########## Get Inputs from User - End ########## -------------------------------------------------------
# End of Syslog Logging Directives for Loggly
#
ProTip!
Use n and p to navigate between commits in a pull request.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.
We use optional third-party analytics cookies to understand how you use GitHub.com so we can build better products.
Learn more.
We use optional third-party analytics cookies to understand how you use GitHub.com so we can build better products.
You can always update your selection by clicking Cookie Preferences at the bottom of the page.
For more information, see our Privacy Statement.
Essential cookies
We use essential cookies to perform essential website functions, e.g. they're used to log you in.
Learn more
Always active
Analytics cookies
We use analytics cookies to understand how you use our websites so we can make them better, e.g. they're used to gather information about the pages you visit and how many clicks you need to accomplish a task.
Learn more
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
switch-to-insecure-mode-if-tlsdownload-fails #97
switch-to-insecure-mode-if-tlsdownload-fails #97
Changes from all commits
8822c1b3a0d922e1e10bd62d6302f382bba3f7db5cc00b9d83443d25File filter...
Jump to…
mostlyjasonJun 14, 2017
•
edited
Contributor
Does it display this if they are installing for the first time?
Shwetajain148Jun 15, 2017
Author
Contributor
@mostlyjason This code will be executed whenever rsyslog-gnutls package couldn't be download or package manager is not found in the system. It will prompt the user to switch to insecure mode. For example, if I am in SUSE environment where the package manager is different from yum and apt-get so the rsyslog-gnutls package will not be downloaded. In that case, the script will prompt the user to switch to insecure mode.
Shwetajain148Jun 23, 2017
Author
Contributor
@mchaudhary and @mostlyjason, Here I have replaced the wget command wth curl. I looked in differents environments to check if curl is present or not and I found it installed in almost each distribution listed below
Amazon AMI 2017.03
Ubuntu 14
RedHat
SUSE
Fedora
CentOS
I have also tested the configure-linux.sh script with this updated code and everything looked fine to me.
mchaudharyJul 19, 2017
Contributor
@Shwetajain148 Can we try this on Ubuntu 12.04. I am almost certain that 12.04 doesn't have curl in it
Shwetajain148Jul 19, 2017
Author
Contributor
@mchaudhary I just created a new Ubuntu 12.04 instance on Amazon and I could see that curl is pre-installed on it and there is no need to install it manually.
mostlyjasonJul 19, 2017
Contributor
We have had curl built into our script for a long time and haven't heard any complaints. I'm guessing it's common or easy to install.