MAR-132: Added support for Debian 9 (Stretch) to wsgi_website role:

- Set the shell for application system account explicitly (workaround
for Debian bug 865762 in Stretch).
- Updated Molecule tests to cover Debian 9.
- Updated Molecule test preparation playbook to account for a number
of differences between Jessie and Stretch (mainly related to mailing
- Renamed a couple of variables in test for sending out mails to make
it clearer what is being looked up as part of regex matching.
- Updated Molecule tests where certain paths depend on what Debian
release they are ran against.
- Split-up Jessie-specific tests into separate file.
- Remove the /bin/ss utility instead of renaming it (testinfra socket
tests do not work with /bin/ss).
import os

import testinfra.utils.ansible_runner

testinfra_hosts = testinfra.utils.ansible_runner.AnsibleRunner(

def test_base_entry(host):
    Tests if the base entry has been created correctly.

    with host.sudo():

        base_dn ="ldapsearch -H ldapi:/// -Q -LLL -Y EXTERNAL -b dc=local -s base")

        assert base_dn.rc == 0
        assert "dc: local" in base_dn.stdout.split("\n")
        assert "o: Private" in base_dn.stdout.split("\n")

def test_log_level(host):
    Tests if the logging level has been set correctly.

    with host.sudo():

        log_level ='ldapsearch -H ldapi:/// -Q -LLL -Y EXTERNAL -b cn=config -s base olcLogLevel')

        assert log_level.rc == 0
        assert 'olcLogLevel: 256' in log_level.stdout

def test_ldap_tls_private_key_file(host):
    Tests if the TLS private key has been deployed correctly.

    with host.sudo():

        inventory_hostname = host.ansible.get_variables()['inventory_hostname']

        key = host.file('/etc/ssl/private/%s_ldap.key' % inventory_hostname)

        assert key.is_file
        assert key.user == 'root'
        assert == 'openldap'
        assert key.mode == 0o640
        assert key.content == open('tests/data/x509/%s_ldap.key' % inventory_hostname).read().rstrip()

def test_ldap_tls_certificate_file(host):
    Tests if the TLS certificate has been deployed correctly.

    with host.sudo():

        inventory_hostname = host.ansible.get_variables()['inventory_hostname']

        cert = host.file('/etc/ssl/certs/%s_ldap.pem' % inventory_hostname)

        assert cert.is_file
        assert cert.user == 'root'
        assert == 'root'
        assert cert.mode == 0o644
        assert cert.content == open('tests/data/x509/%s_ldap.pem' % inventory_hostname).read().rstrip()

def test_certificate_validity_check_configuration(host):
    Tests if certificate validity check configuration file has been deployed

    inventory_hostname = host.ansible.get_variables()['inventory_hostname']

    config = host.file('/etc/check_certificate/%s_ldap.conf' % inventory_hostname)

    assert config.is_file
    assert config.user == 'root'
    assert == 'root'
    assert config.mode == 0o644
    assert config.content == "/etc/ssl/certs/%s_ldap.pem" % inventory_hostname

def test_tls_configuration(host):
    Tests if the TLS has been configured correctly and works.

    starttls ='ldapwhoami -Z -x -H ldap://parameters-mandatory.local/')
    assert starttls.rc == 0
    assert starttls.stdout == 'anonymous'

    tls ='ldapwhoami -x -H ldaps://parameters-mandatory.local/')
    assert tls.rc == 0
    assert tls.stdout == 'anonymous'

    old_tls_versions_disabled ="echo 'Q' | openssl s_client -no_tls1_2 -connect parameters-mandatory.local:636")
    assert old_tls_versions_disabled.rc != 0
    assert "CONNECTED" in old_tls_versions_disabled.stdout

    cipher ="echo 'Q' | openssl s_client -cipher ECDHE-RSA-AES128-SHA256 -connect parameters-mandatory.local:636")
    assert cipher.rc == 0
    assert "ECDHE-RSA-AES128-SHA256" in cipher.stdout

    cipher ="echo 'Q' | openssl s_client -cipher ECDHE-RSA-AES128-SHA -connect parameters-mandatory.local:636")
    assert cipher.rc != 0
    assert "CONNECTED" in cipher.stdout
    assert "ECDHE-RSA-AES128-SHA" not in cipher.stdout

def test_ssf_configuration(host):
    Tests if the SSF olcSecurity configuration has been set-up correctly.

    with host.sudo():
        ssf ='ldapsearch -H ldapi:/// -Q -LLL -Y EXTERNAL -b cn=config olcSecurity')

        assert ssf.rc == 0
        assert "olcSecurity: ssf=128" in ssf.stdout

def test_permissions(host):
    Tests if LDAP directory permissions have been set-up correctly.

    with host.sudo():
        permissions ="ldapsearch -o ldif-wrap=no -H ldapi:/// -Q -LLL -Y EXTERNAL -b 'olcDatabase={1}mdb,cn=config' -s base olcAccess olcAccess")

        expected_permissions = """olcAccess: {0}to * by dn.exact=gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth manage by dn="cn=admin,dc=local" manage by * break
olcAccess: {1}to attrs=userPassword,shadowLastChange by self write by anonymous auth by * none
olcAccess: {2}to dn.base="" by * read
olcAccess: {3}to * by self write by dn="cn=admin,dc=local" write by users read by * none"""

        assert permissions.rc == 0
        assert expected_permissions in permissions.stdout

def test_services_login_entries(host):
    Tests if the service/consumer login entries have been set correctly.

    with host.sudo():

        entries ="ldapsearch -H ldapi:/// -Q -LLL -Y EXTERNAL -s one -b ou=services,dc=local '(objectClass=simpleSecurityObject)'")

        assert entries.rc == 0
        assert entries.stdout == ""

def test_group_entries(host):
    Tests that no group entries have been created out-of-the-box.

    with host.sudo():

        entries ="ldapsearch -H ldapi:/// -Q -LLL -Y EXTERNAL -s one -b ou=groups,dc=local '(objectClass=groupOfUniqueNames)'")

        assert entries.rc == 0
        assert entries.stdout == ""