The SolidSyslog logo beside the words Release 0.2.0 in large orange type, over the thirteen supported platforms: POSIX, Windows, FreeRTOS, CMSIS-RTOS2, C11 atomics, FreeRTOS-Plus-TCP, the lwIP raw and sockets APIs, OpenSSL, Mbed TLS, FatFs, FreeRTOS-Plus-FAT and LittleFS, with the three new in 0.2.0 highlighted.

SolidSyslog 0.2.0: one TLS contract, whichever stack you run

Mbed TLS or OpenSSL, the audit channel now behaves the same way, to one written contract. Collector pinning for networks with no PKI, certificate renewal without a gap, and three new platforms.


Some product portfolios don’t run one TLS library. The newer controller has OpenSSL on embedded Linux; the older one has Mbed TLS on an RTOS. If the audit trail behaves differently on each, you have two security arguments to make, two sets of failures to understand and two stories for the technical file.

SolidSyslog 0.2.0 removes that difference. Both TLS platforms now implement one written TLS contract: the same checks, the same decisions about when to keep delivering and when to stop, and the same errors when something is wrong. That is tested, not asserted: an equivalence matrix of 27 TLS scenarios runs on every CI lane and requires both stacks to reach the same connect-or-refuse decision and report the same error. Choose the library for your product on its own merits; the audit channel on top of it is the same.

What is better

Pin the collector, no PKI required. Many control networks have no certificate authority, and never will. The device can now authorise its collector by certificate fingerprint, as RFC 5425 §5.1 provides, so TLS works on a closed network with nothing more than one hash to provision. Where a site does run a CA, the device can require it as well as the pin.

Renew certificates without stopping delivery. A device can hold the current pin and the next one side by side, so the collector’s certificate is renewed with no gap in the audit trail and no site visit to each device. New credentials issued while the device is running are used on its next connection, without a restart.

Credentials on your terms. The TLS stream asks for its trust anchors and client credential when it connects and says when it has finished with them. Where they live is your choice: a file, a secure element or an encrypted store.

The policy you set is the policy you get. The cipher policy you configure binds the connection that is negotiated, on both stacks. Mutual TLS checks the device’s key against its certificate before it is used.

Errors you can act on. Every platform now reports through one set of detail codes, so an error handler is written once for any combination of RTOS, network stack and TLS library. A refused handshake names the check that refused it, and a failed TCP connect says which step gave up.

The standards, met. By our own assessment, SolidSyslog now meets every applicable clause of all four syslog RFCs it implements, RFC 5424, 5425, 5426 and 6587, with none partial and none unmet. The compliance matrix shows the evidence clause by clause.

The TLS work closed with a security audit of the whole channel before the release was cut, traced into the OpenSSL and Mbed TLS sources. It found no path by which a failed check lets a record through, on either stack. That is the part a team building its own syslog client tends to skip, and it is the part an assessor will ask about.

Three new platforms

0.2.0 adds a LittleFS file adapter, the lwIP sockets API alongside the raw API, and CMSIS-RTOS2 for the mutex and uptime. Each runs for real in CI, not only against test doubles. That brings the reference adapters to thirteen, and the platforms guide shows what runs where.

What it costs

The first compliant record is unchanged at about 5.1 KB of flash and 1.9 KB of RAM. The whole path, with pinned TLS, certificate renewal, mutual TLS and encryption at rest, is about 16.4 KB of flash and 36.3 KB of RAM on the worked example, measured on the running target. The hardening path walks every step and what each one costs.

Moving from 0.1.0

This is a 0.x release, and the TLS API changed to make all of the above possible: the TLS streams now take a credentials source, and error names follow one convention. The release notes list every change, and both worked examples have been rebuilt against 0.2.0 one commit per stage, so the diff for your own build is already written.

Each release now also carries a signed offline copy of its documentation, so a technical file can hold the docs for exactly the version you ship.

Next

0.2.0 is one step on the way to 1.0.0 in Q4 2026, with more 0.x releases between now and then. If the platform you need isn’t on the list yet, now is the time to tell us. Any organisation can evaluate SolidSyslog free under the PolyForm Internal Use licence, with no time limit. Start from the product page or talk to us about your product.

David

View posts by David
David Cozens is a Chartered Engineer with nearly forty years in embedded systems, most of them in industrial and process control, automation, and test and measurement. He is named in the acknowledgements of MISRA C:2012 and is the founder of COSOSO.

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to top