From 069c78425a2965856d756a37c077a5a4b625e1b7 2021-01-14 23:50:26 From: Branko Majic Date: 2021-01-14 23:50:26 Subject: [PATCH] MAR-151: Use 2048-bit DH parameter for IMAP server under Debian 10 Buster: - Deploy a statically-generated DH parameter. - Set-up DH parameter configuration based on Debian version. - Implemented test for newly-generated file. --- diff --git a/roles/mail_server/molecule/default/tests/test_default.py b/roles/mail_server/molecule/default/tests/test_default.py index 431dc6b865dfbb700ca22d2c55058b44ae7b3233..5c2ad4eb4334c96a240190df5a61c5a474425244 100644 --- a/roles/mail_server/molecule/default/tests/test_default.py +++ b/roles/mail_server/molecule/default/tests/test_default.py @@ -401,6 +401,27 @@ def test_smtp_server_uses_correct_dh_parameters(host): assert used_dhparam == expected_dhparam +def test_imap_server_dh_parameter_file(host): + """ + Tests if the Diffie-Hellman parameter file has been generated + correctly. + """ + + hostname = host.run('hostname').stdout.strip() + dhparam_file_path = '/etc/ssl/private/%s_imap.dh.pem' % hostname + + with host.sudo(): + dhparam_file = host.file(dhparam_file_path) + assert dhparam_file.is_file + assert dhparam_file.user == 'root' + assert dhparam_file.group == 'root' + assert dhparam_file.mode == 0o640 + + dhparam_info = host.run("openssl dhparam -noout -text -in %s", dhparam_file_path) + + assert "DH Parameters: (2048 bit)" in dhparam_info.stdout + + def test_imap_server_uses_correct_dh_parameters(host): """ Tests if the IMAP server uses correct Diffie-Hellman parameters. diff --git a/roles/mail_server/tasks/main.yml b/roles/mail_server/tasks/main.yml index 9a0529c2a8c057a26bce0aaed2736fbae5395b1d..cb61b241c13158d134d20e39896afb280129503c 100644 --- a/roles/mail_server/tasks/main.yml +++ b/roles/mail_server/tasks/main.yml @@ -89,6 +89,16 @@ notify: - Restart Dovecot +- name: Generate the IMAP server Diffie-Hellman parameter + openssl_dhparam: + owner: root + group: root + mode: 0640 + path: "/etc/ssl/private/{{ ansible_fqdn }}_imap.dh.pem" + size: 2048 + notify: + - Restart Dovecot + - name: Deploy configuration files for checking certificate validity via cron copy: content: "/etc/ssl/certs/{{ ansible_fqdn }}_{{ item }}.pem" diff --git a/roles/mail_server/templates/99-local.conf.j2 b/roles/mail_server/templates/99-local.conf.j2 index 6b34cb7e620c84c450a4ff602c91a376d2f2c888..c5239bce6f8aae8a7d7fd5e8f023120f8ef0314b 100644 --- a/roles/mail_server/templates/99-local.conf.j2 +++ b/roles/mail_server/templates/99-local.conf.j2 @@ -31,7 +31,13 @@ service auth { # TLS configuration. ssl_cert =