Skip to content

Unexpected skipped audits after hardening apache #12

@NickRycar

Description

@NickRycar

Background:

I have been using the ssl-baseline profile to demonstrate a simple failure/remediation story using this cookbook to configure apache for ssl: https://github.com/chef-cft/bjc/tree/master/cookbooks/bjc-ecommerce

Recent updates look to produce an edge case where the profile produces an unexpected edge case, where the profile passes, but because it doesn't think any ports are listening on SSL, and skips all of the functional tests (e.g. there's one passed test for inspec version. The rest are skipped). Older versions of the profile do not appear to be affected.

Details & Reproduction Steps:

Initial revisions configured apache with the following settings to remediate detected errors:

SSLProtocol -all +TLSv1.2
SSLCipherSuite HIGH:!kRSA:!kDHr:!kDHd:!kSRP:!aNULL:!3DES:!MD5

Recent updates included a check for CBC ciphers (b5fd0ff), which the above settings do not alleviate. To address, we updated our CipherSuite to look like so:

SSLCipherSuite EECDH+AESGCM:EDH+AESGCM

Initial testing (done 4/17/17 - 4/18/17) seemed to validate that this fixed our remaining audits, and got a clean bill of health across the board. However, on Friday 4/21, we started seeing the above described behavior. Before enforcing the cipher suite, our tests fail as expected. After making the above change, tests now no longer detect that SSL is running, and all tests are skipped. Reverting back to an earlier version (on our case, from a 1.1.1 snapshot on our compliance server) produced the expected passing tests.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions