|
@@ -84,3 +84,44 @@ def test_firewall_configuration_file(host):
|
|
|
assert config.user == 'root'
|
|
|
assert config.group == 'root'
|
|
|
assert config.mode == 0o640
|
|
|
|
|
|
|
|
|
def test_smtp_server_dh_parameter_file(host):
|
|
|
"""
|
|
|
Tests if the Diffie-Helman parameter file has been generated
|
|
|
correctly.
|
|
|
"""
|
|
|
|
|
|
hostname = host.run('hostname').stdout.strip()
|
|
|
dhparam_file_path = '/etc/ssl/private/%s_smtp.dh.pem' % hostname
|
|
|
|
|
|
with host.sudo():
|
|
|
dhparam_file = host.file(dhparam_file_path)
|
|
|
assert dhparam_file.is_file
|
|
|
assert dhparam_file.user == 'root'
|
|
|
assert dhparam_file.group == 'root'
|
|
|
assert dhparam_file.mode == 0o640
|
|
|
|
|
|
dhparam_info = host.run("openssl dhparam -noout -text -in %s", dhparam_file_path)
|
|
|
|
|
|
assert "DH Parameters: (2048 bit)" in dhparam_info.stdout
|
|
|
|
|
|
|
|
|
def test_smtp_server_uses_correct_dh_parameters(host):
|
|
|
"""
|
|
|
Tests if the SMTP server uses the generated Diffie-Helman parameter.
|
|
|
"""
|
|
|
|
|
|
hostname = host.run('hostname').stdout.strip()
|
|
|
|
|
|
with host.sudo():
|
|
|
expected_dhparam = host.file('/etc/ssl/private/%s_smtp.dh.pem' % hostname).content_string.rstrip()
|
|
|
|
|
|
connection = host.run("gnutls-cli --no-ca-verification --starttls-proto=smtp --port 25 --priority 'NONE:+VERS-TLS1.2:+CTYPE-X509:+COMP-NULL:+SIGN-RSA-SHA384:+DHE-RSA:+SHA384:+AEAD:+AES-256-GCM' --verbose localhost")
|
|
|
|
|
|
output = connection.stdout
|
|
|
begin_marker = "-----BEGIN DH PARAMETERS-----"
|
|
|
end_marker = "-----END DH PARAMETERS-----"
|
|
|
used_dhparam = output[output.find(begin_marker):output.find(end_marker) + len(end_marker)]
|
|
|
|
|
|
assert used_dhparam == expected_dhparam
|