Skip to content

Commit 155ddbd

Browse files
authored
Merge pull request #1701 from alexandr-san4ez/T4251-current-fix2
syslog: T4251: Rename "permitted-peers" to "permitted-peer"
2 parents af8c829 + 85a097b commit 155ddbd

File tree

1 file changed

+6
-6
lines changed

1 file changed

+6
-6
lines changed

docs/configuration/system/syslog.rst

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -151,19 +151,19 @@ if you attempt to enable TLS while using UDP, the system will issue a warning.
151151
* **anon** - allow encrypted connection without verifying peer identity
152152
(not recommended, vulnerable to :abbr:`MITM (Man-in-the-Middle)`).
153153
* **fingerprint** - verify the peer certificate against an explicitly
154-
configured fingerprint list (set with ``permitted-peers``).
154+
configured fingerprint list (set with ``permitted-peer``).
155155
* **certvalid** - validate that the peer presents a certificate signed by
156156
a trusted CA, but do not check the certificate subject name
157157
(:abbr:`CN (Common Name)`).
158158
* **name** - validate that the peer presents a certificate signed by a
159159
trusted CA and that the certificate’s CN matches the value configured in
160-
``permitted-peers``. This is the recommended secure mode for production.
160+
``permitted-peer``. This is the recommended secure mode for production.
161161

162162
.. note:: The default value for the authentication mode is ``anon``.
163163

164-
.. cfgcmd:: set system syslog remote <address> tls permitted-peers <peer_list>
164+
.. cfgcmd:: set system syslog remote <address> tls permitted-peer <peer>
165165

166-
Comma-separated list of permitted peers or certificate’s subject names (CN).
166+
Allowed peer certificate fingerprint or subject name (CN).
167167

168168
* In ``fingerprint`` authentication mode: provide one or more peer
169169
certificate fingerprints (SHA1 or SHA256).
@@ -195,7 +195,7 @@ Examples:
195195
set system syslog remote syslog.example.com protocol tcp
196196
set system syslog remote syslog.example.com tls ca-certificate my-ca
197197
set system syslog remote syslog.example.com tls auth-mode fingerprint
198-
set system syslog remote syslog.example.com tls permitted-peers 'SHA1:10:C4:26:...,SHA256:7B:4B:10:...'
198+
set system syslog remote syslog.example.com tls permitted-peer 'SHA1:10:C4:26:...'
199199
200200
# Example of 'name' authentication mode
201201
set system syslog remote graylog.example.com facility all level debug
@@ -204,7 +204,7 @@ Examples:
204204
set system syslog remote graylog.example.com tls ca-certificate my-ca
205205
set system syslog remote graylog.example.com tls certificate syslog-client
206206
set system syslog remote graylog.example.com tls auth-mode name
207-
set system syslog remote graylog.example.com tls permitted-peers 'graylog.example.com'
207+
set system syslog remote graylog.example.com tls permitted-peer 'graylog.example.com'
208208
209209
Security Notes
210210
^^^^^^^^^^^^^^

0 commit comments

Comments
 (0)