mirror of https://github.com/CISOfy/lynis.git
Tweaked nginx protocol check so it actually works. Added insecure protocol detection.
This commit is contained in:
parent
3d0fb8d529
commit
111097506f
|
@ -824,6 +824,7 @@
|
|||
if [ "${VALUE}" = "on" ]; then NGINX_SSL_PREFER_SERVER_CIPHERS=1; fi
|
||||
;;
|
||||
ssl_protocols)
|
||||
NGINX_SSL_PROTOCOLS=1
|
||||
;;
|
||||
ssl_session_cache)
|
||||
;;
|
||||
|
|
|
@ -501,6 +501,12 @@
|
|||
|
||||
if [ ${NGINX_SSL_PROTOCOLS} -eq 1 ]; then
|
||||
Display --indent 8 --text "- Protocols configured" --result "YES" --color GREEN
|
||||
FIND=`${GREPBINARY} "ssl_protocols" ${NGINX_CONF_LOCATION} | ${GREPBINARY} "SSLv[12]"`
|
||||
if [ "${FIND}" = "" ]; then
|
||||
Display --indent 10 --text "- Insecure protocols found" --result "NO" --color GREEN
|
||||
else
|
||||
Display --indent 10 --text "- Insecure protocols found" --result "YES" --color RED
|
||||
fi
|
||||
else
|
||||
Display --indent 8 --text "- Protocols configured" --result "NO" --color RED
|
||||
NGINX_SSL_SUGGESTION=1
|
||||
|
|
Loading…
Reference in New Issue