diff --git a/roles/web_server/molecule/default/prepare.yml b/roles/web_server/molecule/default/prepare.yml index d0023d88b42afe30f7dbfbbc44626c58b2e08757..839051ac71b2b67f93105ac540c9d89407dd1b71 100644 --- a/roles/web_server/molecule/default/prepare.yml +++ b/roles/web_server/molecule/default/prepare.yml @@ -18,6 +18,11 @@ update_cache: true changed_when: false + - name: Install tools for testing + apt: + name: gnutls-bin + state: present + - hosts: stretch become: true tasks: diff --git a/roles/web_server/molecule/default/tests/test_default.py b/roles/web_server/molecule/default/tests/test_default.py index 74be94bc9e4dbd460ffcb3f83dc645524e8d3c73..d9f7dd8ec593e33fe69dfb6b2f5386358774b934 100644 --- a/roles/web_server/molecule/default/tests/test_default.py +++ b/roles/web_server/molecule/default/tests/test_default.py @@ -234,3 +234,45 @@ def test_php_timezone_configuration(host, php_info): timezone = host.run("php --php-ini %s -r %s", "%s/fpm/php.ini" % php_info.base_config_dir, "echo ini_get('date.timezone');") assert timezone.rc == 0 assert timezone.stdout == server_timezone + + +def test_https_server_dh_parameters_file(host): + """ + Tests if the Diffie-Helman parameter file has been generated + correctly. + """ + + hostname = host.run('hostname').stdout.strip() + dhparam_file_path = '/etc/ssl/private/%s_https.dh.pem' % hostname + + with host.sudo(): + dhparam_file = host.file(dhparam_file_path) + assert dhparam_file.is_file + assert dhparam_file.user == 'root' + assert dhparam_file.group == 'root' + assert dhparam_file.mode == 0o640 + + dhparam_info = host.run("openssl dhparam -noout -text -in %s", dhparam_file_path) + + assert "DH Parameters: (2048 bit)" in dhparam_info.stdout + + +def test_https_server_uses_correct_dh_parameters(host): + """ + Tests if the HTTP server uses the generated Diffie-Helman parameter. + """ + + hostname = host.run('hostname').stdout.strip() + + with host.sudo(): + expected_dhparam = host.file('/etc/ssl/private/%s_https.dh.pem' % hostname).content_string.rstrip() + + connection = host.run("gnutls-cli --no-ca-verification --starttls-proto=https --port 443 " + "--priority 'NONE:+VERS-TLS1.2:+CTYPE-X509:+COMP-NULL:+SIGN-RSA-SHA384:+DHE-RSA:+SHA384:+AEAD:+AES-256-GCM' --verbose localhost") + + output = connection.stdout + begin_marker = "-----BEGIN DH PARAMETERS-----" + end_marker = "-----END DH PARAMETERS-----" + used_dhparam = output[output.find(begin_marker):output.find(end_marker) + len(end_marker)] + + assert used_dhparam == expected_dhparam diff --git a/roles/web_server/tasks/main.yml b/roles/web_server/tasks/main.yml index 95a12d3e10794454ebd7ee0b6777ac909de7e7fd..82a8c7949d40d52e0e545b1e9c20d24b0bfd364b 100644 --- a/roles/web_server/tasks/main.yml +++ b/roles/web_server/tasks/main.yml @@ -33,6 +33,16 @@ notify: - Restart nginx +- name: Generate the HTTPS server Diffie-Helman parameter + openssl_dhparam: + owner: root + group: root + mode: 0640 + path: "/etc/ssl/private/{{ ansible_fqdn }}_https.dh.pem" + size: 2048 + notify: + - Restart nginx + - name: Deploy configuration file for checking certificate validity via cron copy: content: "/etc/ssl/certs/{{ ansible_fqdn }}_https.pem" diff --git a/roles/web_server/templates/tls.conf.j2 b/roles/web_server/templates/tls.conf.j2 index 67c8ecc92251919bfa083c1f559194ea2304b533..804437921dbb9ab83dfbb842e391fe42340b0b67 100644 --- a/roles/web_server/templates/tls.conf.j2 +++ b/roles/web_server/templates/tls.conf.j2 @@ -1,2 +1,3 @@ ssl_protocols {{ web_server_tls_protocols | join(" ") }}; ssl_ciphers {{ web_server_tls_ciphers }}; +ssl_dhparam /etc/ssl/private/{{ ansible_fqdn }}_https.dh.pem;