Browse Source

concierge-permaudit: new rules for postfix, wireguard

guillaume 6 years ago
parent
commit
875eeae9b8
1 changed files with 5 additions and 0 deletions
  1. 5 0
      src/concierge-permaudit

+ 5 - 0
src/concierge-permaudit

@@ -37,7 +37,11 @@ disRules.append({'pathname': '/etc/apache2/sites-available/*', 're': 'SSLCertifi
 disRules.append({'pathname': '/etc/dovecot/conf.d/10-ssl.conf', 're': 'ssl_key\s*=\s*<(\S+)'})
 disRules.append({'pathname': '/etc/nginx/sites-available/*', 'cwd': '/etc/nginx', 're': 'ssl_certificate_key\s+"?([^;]+)"?;'})
 disRules.append({'pathname': '/etc/nginx/sites-available/*', 'cwd': '/etc/nginx', 're': 'auth_basic_user_file\s+"?([^;]+)"?'})
+disRules.append({'pathname': '/etc/postfix/main.cf', 're': 'smtpd_tls_dkey_file\s*=\s*(\S+)'})
 disRules.append({'pathname': '/etc/postfix/main.cf', 're': 'smtpd_tls_key_file\s*=\s*(\S+)'})
+disRules.append({'pathname': '/etc/postfix/main.cf', 're': 'smtpd_tls_eckey_file\s*=\s*(\S+)'})
+disRules.append({'pathname': '/etc/postfix/main.cf', 're': 'smtpd_tls_dh512_param_file\s*=\s*(\S+)'})
+disRules.append({'pathname': '/etc/postfix/main.cf', 're': 'smtpd_tls_dh1024_param_file\s*=\s*(\S+)'})
 
 readPatterns = [
   '/etc/shadow',
@@ -93,6 +97,7 @@ readPatterns = [
   '/etc/letsencrypt/keys/*.pem',
   '/etc/cups/ssl/*.key',
   '/etc/unbound/*.key',
+  '/etc/wireguard/*.conf',
   ]
 
 writePatterns = [