Thanks to visit codestin.com
Credit goes to github.com

Skip to content

RFE: Include the connection type and remote Subject of a TLS connection in relevant log lines #164

@jiscfoo

Description

@jiscfoo

The subject is logged during connection:

tlsservernew: TLS connection from 192.168.1.2, client testclients, subject CN=4CDEBD8C-659A-48D8-A3E3-C526EA880CD4 up
tlsservernew: TLS connection from 192.168.1.2, client testclients, subject CN=050A23FC-DA2E-4590-9241-D4E674B917C4 up

But subsequent lines when multiple connections are in-play from the same IP do not include that reference:

Access-Reject for user [email protected] stationid FF-EE-DD-CC-BB-AA from freerad-1 to testclients (192.168.1.2)

Propose:

Include the connection type (eg. udp, tls), remote port number, and, if relevant, the client's TLS Subject in the log line for better auditing - something like:

Access-Reject for user [email protected] stationid FF-EE-DD-CC-BB-AA from freerad-1 to testclients (udp:192.168.1.3:38382)
Access-Reject for user [email protected] stationid FF-EE-DD-CC-BB-AA from freerad-1 to testclients (tls:192.168.1.2:55232/CN=4CDEBD8C-659A-48D8-A3E3-C526EA880CD4)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions