8.0

Table Of Contents
Table 4-23. Syslog Options Available Starting from ESXi 7.0 Update 1 (continued)
Option ESXCLI command Description
Syslog.global.certificate.chec
kCRL
esxcli system syslog config
set --crl-check=<bool>
Enables checking the revocation
status of all the certificates in an SSL
certificate chain.
Enables verification of X.509 CRLs,
which are not checked by default in
compliance with industry conventions.
A NIAP-validated configuration
requires CRL checks. Due to
implementation limitations, if CRL
checks are enabled, then all
certificates in a certificate chain must
provide a CRL link.
Do not enable the crl-check
option for installations not related
to certification, because of the
difficulty in properly configuring an
environment that uses CRL checks.
Syslog.global.certificate.stri
ctX509Compliance
esxcli system syslog config
set --x509-strict=<bool>
Enables strict compliance with
X.509. Performs additional validity
checks on CA root certificates
during verification. These checks are
generally not performed, as CA roots
are inherently trusted, and might
cause incompatibilities with existing,
misconfigured CA roots. A NIAP-
validated configuration requires even
CA roots to pass validations.
Do not enable the x509-strict
option for installations not related
to certification, because of the
difficulty in properly configuring an
environment that uses CRL checks.
Syslog.global.droppedMsgs.file
Rotate
esxcli system syslog config
set --drop-log-rotate=<long>
Specifies the number of old dropped
message log files to keep.
Syslog.global.droppedMsgs.file
Size
esxcli system syslog config
set --drop-log-size=<long>
Specifies the size of each dropped
message log file before switching to
a new one, in KiB.
Syslog.global.logCheckSSLCerts esxcli system syslog config
set --check-ssl-certs=<bool>
Enforces checking of SSL certificates
when transmitting messages to
remote hosts.
Note Deprecated. Use
Syslog.global.certificate.chec
kSSLCerts in ESXi 7.0 Update 1 and
later.
VMware ESXi Installation and Setup
VMware, Inc. 237