-
Notifications
You must be signed in to change notification settings - Fork 23
Description
Background:
I have been using the ssl-baseline profile to demonstrate a simple failure/remediation story using this cookbook to configure apache for ssl: https://github.com/chef-cft/bjc/tree/master/cookbooks/bjc-ecommerce
Recent updates look to produce an edge case where the profile produces an unexpected edge case, where the profile passes, but because it doesn't think any ports are listening on SSL, and skips all of the functional tests (e.g. there's one passed test for inspec version. The rest are skipped). Older versions of the profile do not appear to be affected.
Details & Reproduction Steps:
Initial revisions configured apache with the following settings to remediate detected errors:
SSLProtocol -all +TLSv1.2
SSLCipherSuite HIGH:!kRSA:!kDHr:!kDHd:!kSRP:!aNULL:!3DES:!MD5
Recent updates included a check for CBC ciphers (b5fd0ff), which the above settings do not alleviate. To address, we updated our CipherSuite to look like so:
SSLCipherSuite EECDH+AESGCM:EDH+AESGCM
Initial testing (done 4/17/17 - 4/18/17) seemed to validate that this fixed our remaining audits, and got a clean bill of health across the board. However, on Friday 4/21, we started seeing the above described behavior. Before enforcing the cipher suite, our tests fail as expected. After making the above change, tests now no longer detect that SSL is running, and all tests are skipped. Reverting back to an earlier version (on our case, from a 1.1.1 snapshot on our compliance server) produced the expected passing tests.