Files
ansible-testing/methodologies/ansible/playbooks/demo_target.yml
T

92 lines
3.7 KiB
YAML

---
- name: "Demo: Ubuntu SSH and nginx checks"
hosts: linux_vms
gather_facts: true
become: false
vars:
report_dir: "./artifacts/raw/ansible"
pre_tasks:
- name: "Ensure report directory exists"
ansible.builtin.file:
path: "{{ report_dir }}"
state: directory
mode: "0755"
delegate_to: localhost
run_once: true
tasks:
- name: "Gather SSH effective configuration"
ansible.builtin.shell: grep -Ei '^(PasswordAuthentication|PermitRootLogin)' /etc/ssh/sshd_config
register: sshd_config
changed_when: false
- name: "Record SSH password authentication result"
ansible.builtin.set_fact:
test_results: "{{ test_results | default([]) + [{
'test_id': 'DEMO-SSH-01',
'category': 'Secure remote administration',
'requirement': 'IEC 62443-3-3 SR 1.7',
'description': 'SSH password authentication shall be disabled',
'passed': ('passwordauthentication no' in sshd_config.stdout),
'expected': 'PasswordAuthentication no',
'actual': sshd_config.stdout_lines | select('match', '^passwordauthentication ') | first | default('not found'),
'severity': 'high',
'remediation': 'Disable SSH password authentication and use managed keys'
}] }}"
- name: "Gather nginx configuration"
ansible.builtin.shell: grep -E '^[[:space:]]*ssl_(protocols|ciphers)' /etc/nginx/sites-enabled/default
register: nginx_config
changed_when: false
- name: "Record obsolete TLS protocol result"
ansible.builtin.set_fact:
test_results: "{{ test_results + [{
'test_id': 'DEMO-TLS-01',
'category': 'Secure communications',
'requirement': 'IEC 62443-3-3 SR 4.1',
'description': 'The web server shall allow only TLS 1.2 and TLS 1.3',
'passed': ('TLSv1 ' not in nginx_config.stdout and 'TLSv1.1' not in nginx_config.stdout),
'expected': 'ssl_protocols TLSv1.2 TLSv1.3',
'actual': nginx_config.stdout_lines | select('search', 'ssl_protocols') | first | default('not found'),
'severity': 'high',
'remediation': 'Remove TLSv1 and TLSv1.1 from ssl_protocols'
}] }}"
- name: "Record weak CBC cipher result"
ansible.builtin.set_fact:
test_results: "{{ test_results + [{
'test_id': 'DEMO-TLS-02',
'category': 'Secure communications',
'requirement': 'IEC 62443-3-3 SR 4.1',
'description': 'The web server shall not enable legacy CBC cipher suites',
'passed': ('AES128-SHA' not in nginx_config.stdout),
'expected': 'Modern AEAD cipher suites only',
'actual': nginx_config.stdout_lines | select('search', 'ssl_ciphers') | first | default('not found'),
'severity': 'medium',
'remediation': 'Use a modern Mozilla intermediate TLS cipher configuration'
}] }}"
- name: "Check nginx process"
ansible.builtin.command: pgrep -x nginx
register: nginx_process
changed_when: false
failed_when: false
- name: "Record nginx availability result"
ansible.builtin.set_fact:
test_results: "{{ test_results + [{
'test_id': 'DEMO-SVC-01',
'category': 'Service availability',
'requirement': 'IEC 62443-3-3 SR 7.1',
'description': 'The nginx service shall be running',
'passed': (nginx_process.rc == 0),
'expected': 'At least one nginx process',
'actual': nginx_process.stdout | default('not running', true),
'severity': 'medium',
'remediation': 'Start nginx and configure service supervision'
}] }}"
- name: "Generate raw Ansible report"
ansible.builtin.include_tasks: library/report.yml