import os import defusedxml.ElementTree as ElementTree import testinfra.utils.ansible_runner testinfra_hosts = testinfra.utils.ansible_runner.AnsibleRunner( os.environ['MOLECULE_INVENTORY_FILE']).get_hosts('parameters-optional') def test_tls_version_and_ciphers(host): """ Tests if the correct TLS version and ciphers have been enabled. """ expected_tls_versions = ["TLSv1.1", "TLSv1.2"] expected_tls_ciphers = [ "TLS_DHE_RSA_WITH_AES_128_CBC_SHA256", "TLS_DHE_RSA_WITH_AES_128_GCM_SHA256", "TLS_DHE_RSA_WITH_AES_256_CBC_SHA256", "TLS_DHE_RSA_WITH_AES_256_GCM_SHA384", "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA", "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256", "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256", "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384", "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384", ] # Run the nmap scanner against the LDAP server, and fetch the # results. nmap = host.run("nmap -sV --script ssl-enum-ciphers -p 443 localhost -oX /tmp/report.xml") assert nmap.rc == 0 report_content = host.file('/tmp/report.xml').content_string report_root = ElementTree.fromstring(report_content) tls_versions = [] tls_ciphers = set() for child in report_root.findall("./host/ports/port/script/table"): tls_versions.append(child.attrib['key']) for child in report_root.findall(".//table[@key='ciphers']/table/elem[@key='name']"): tls_ciphers.add(child.text) tls_versions.sort() tls_ciphers = sorted(list(tls_ciphers)) assert tls_versions == expected_tls_versions assert tls_ciphers == expected_tls_ciphers def test_default_vhost_index_page(host): """ Tests content of default vhost index page. """ hostname = host.ansible.get_variables()['inventory_hostname'] page = host.run('curl https://%s/', hostname) assert page.rc == 0 assert "Optional Welcome" in page.stdout assert "

Optional Welcome

" in page.stdout assert "

Welcome to default virtual host.

" in page.stdout def test_environment_indicator(host): """ Tests if environment indicator is applied correctly. """ hostname = host.ansible.get_variables()['inventory_hostname'] page = host.run('curl https://%s/' % hostname) expected_content = """
🞀🞂
parameters-optional
""" assert page.rc == 0 assert expected_content in page.stdout