From a7cd31c6886d7d8b89e35117edd9de313355325e 2020-05-18 16:45:24 From: Branko Majic Date: 2020-05-18 16:45:24 Subject: [PATCH] MAR-153: Use custom Diffie-Helman parameters for SMTP server in the mail_server role. --- diff --git a/roles/mail_server/molecule/default/tests/test_default.py b/roles/mail_server/molecule/default/tests/test_default.py index c7774ed477724fe5f8f291a5d4a869539ebc9488..f3a2e71b5faedc4bcfdf22bd6a9f710aaa08f8e9 100644 --- a/roles/mail_server/molecule/default/tests/test_default.py +++ b/roles/mail_server/molecule/default/tests/test_default.py @@ -355,3 +355,44 @@ def test_firewall_configuration_file(host): assert config.user == 'root' assert config.group == 'root' assert config.mode == 0o640 + + +def test_smtp_server_dh_parameter_file(host): + """ + Tests if the Diffie-Helman parameter file has been generated + correctly. + """ + + hostname = host.run('hostname').stdout.strip() + dhparam_file_path = '/etc/ssl/private/%s_smtp.dh.pem' % hostname + + with host.sudo(): + dhparam_file = host.file(dhparam_file_path) + assert dhparam_file.is_file + assert dhparam_file.user == 'root' + assert dhparam_file.group == 'root' + assert dhparam_file.mode == 0o640 + + dhparam_info = host.run("openssl dhparam -noout -text -in %s", dhparam_file_path) + + assert "DH Parameters: (2048 bit)" in dhparam_info.stdout + + +def test_smtp_server_uses_correct_dh_parameters(host): + """ + Tests if the SMTP server uses the generated Diffie-Helman parameter. + """ + + hostname = host.run('hostname').stdout.strip() + + with host.sudo(): + expected_dhparam = host.file('/etc/ssl/private/%s_smtp.dh.pem' % hostname).content_string.rstrip() + + connection = host.run("gnutls-cli --no-ca-verification --starttls-proto=smtp --port 25 --priority 'NONE:+VERS-TLS1.2:+CTYPE-X509:+COMP-NULL:+SIGN-RSA-SHA384:+DHE-RSA:+SHA384:+AEAD:+AES-256-GCM' --verbose localhost") + + output = connection.stdout + begin_marker = "-----BEGIN DH PARAMETERS-----" + end_marker = "-----END DH PARAMETERS-----" + used_dhparam = output[output.find(begin_marker):output.find(end_marker) + len(end_marker)] + + assert used_dhparam == expected_dhparam diff --git a/roles/mail_server/tasks/main.yml b/roles/mail_server/tasks/main.yml index 3d01ef702fd067a5a530ef264146e365bd2ec95f..5858871cbebeb0f76eea8af77f0dbea58ac8300f 100644 --- a/roles/mail_server/tasks/main.yml +++ b/roles/mail_server/tasks/main.yml @@ -59,6 +59,16 @@ notify: - Restart Postfix +- name: Generate the SMTP server Diffie-Helman parameter + openssl_dhparam: + owner: root + group: root + mode: 0640 + path: "/etc/ssl/private/{{ ansible_fqdn }}_smtp.dh.pem" + size: 2048 + notify: + - Restart Postfix + - name: Deploy IMAP TLS private key copy: dest: "/etc/ssl/private/{{ ansible_fqdn }}_imap.key" diff --git a/roles/mail_server/templates/main.cf.j2 b/roles/mail_server/templates/main.cf.j2 index ad273cd8dd2de92d92cce6ce81a19bf093391f71..b3ab8923ce9e29cd6743e52ae5d5a328290233ca 100644 --- a/roles/mail_server/templates/main.cf.j2 +++ b/roles/mail_server/templates/main.cf.j2 @@ -54,6 +54,8 @@ smtpd_tls_security_level = may smtpd_tls_auth_only = yes smtpd_tls_cert_file = /etc/ssl/certs/{{ ansible_fqdn }}_smtp.pem smtpd_tls_key_file = /etc/ssl/private/{{ ansible_fqdn }}_smtp.key +smtpd_tls_dh1024_param_file = /etc/ssl/private/{{ inventory_hostname }}_smtp.dh.pem +smtpd_tls_dh512_param_file = /etc/ssl/private/{{ inventory_hostname }}_smtp.dh.pem smtpd_use_tls=yes smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache