Web Server audit fixes
TLS Configuration: fixing all 6 checks
The TLS audit reads the ssl directives in the nginx and Apache config and the certificate files they name, so a failure means traffic can be downgraded, decrypted or served on an expired certificate.
Certificate Expiry skips when the config names no certificate file the audit can actually open, which is what an unprivileged run against /etc/letsencrypt produces, and HTTPS Redirect skips when nothing answers on plain http://127.0.0.1/ for it to test. The other four skip only when no web server is detected.
Transcribed from the web-server-security-tls-configuration audit script.
Find your finding
Listed in the order the audit runs them. Take the check name from the third field of the result line and open its page.
HTTPS Enabled
SoonChecks whether the web server has any TLS configuration at all
HighNo root3 resultsTLS Protocols
SoonChecks the configured protocol directives for TLS 1.0 and 1.1, and flags an absent explicit list
HighNo root4 resultsTLS Ciphers
SoonChecks the configured cipher list for weak families that enable downgrade and decryption attacks
MediumNo root4 resultsCertificate Expiry
SoonChecks every certificate referenced in the config for expiry within 30 days
HighNeeds root3 resultsHTTPS Redirect
SoonProbes whether plain HTTP redirects to HTTPS rather than answering unencrypted
MediumNo root3 resultsOCSP Stapling
SoonChecks whether OCSP stapling is enabled so clients skip a direct query to the CA
LowNo root3 results
How the TLS Configuration audit reads your server
Every check in this audit runs after the same preamble, and several of its results only make sense once you know what that preamble could and could not see.
Config-based checks read the effective nginx config (nginx -T as root) and the Apache config tree.
All web-server scripts share one preamble. It detects nginx, Apache (apache2/httpd, APROOT = /etc/apache2 or /etc/httpd), Caddy and lighttpd. NGT is nginx -T output (effective config with every include expanded) when root, otherwise a concatenation of nginx.conf, conf.d/*.conf, sites-enabled/*. APC is the concatenated Apache config tree (main file, ports.conf, conf.d, conf-enabled, sites-enabled, mods-enabled, conf.modules.d), comments stripped; APM is apachectl -M (root) or the mods-enabled/*.load names. WROOTS are all root/DocumentRoot values. A live probe curls https://127.0.0.1/, http://127.0.0.1/, http://127.0.0.1:8080/ with the first real server_name/ServerName as Host:. hdr NAME reads a response header; code URL returns the HTTP status. Caddy and lighttpd are detected but their configs are not parsed, so most checks on those hosts rely on the live probe only. Messages ending in "(no live response, config only)" or "(default vhost only - no server_name found to probe)" mean the probe could not be used.
A SKIP is never a pass
A skipped check verified nothing at all. The most common cause is privilege: 1 of the 6 checks in this audit need root for a complete result. Before every run, each script works out which of four privilege modes it is in.
| Mode | How it is reached | What it means for your results |
|---|---|---|
root | The audit runs as UID 0. | Every privileged branch runs directly. No check skips for lack of permission. |
nopass | sudo -n true succeeds, so the account has passwordless sudo. | Privileged commands run through sudo -n. |
pass | A sudo password was supplied in the CtrlOps audit settings and accepted. | Privileged commands run through sudo -S. |
none | None of the above worked. | CAN_ROOT=0. Every privileged branch returns SKIP with a "Need root" message rather than guessing. |
If many checks skip with a “need root” message, run the audit as root, grant the audit account sudo (with or without NOPASSWD), or supply the sudo password in the CtrlOps audit settings.
TLS Configuration questions
Run all 6 TLS Configuration checks, in one click
CtrlOps runs this audit over your existing SSH connection - no agents, no scripts to manage. $7/user/month after a 1 month free trial - no credit card required.
✓ Start instantly·✓ No credit card·✓ No sneaky autorenewals