DevSec SSL/TLS Baseline - InSpec Profile
Switch branches/tags
Clone or download
Latest commit 45152ca Oct 23, 2018

README.md

ssl-baseline

This Compliance Profile demonstrates the use of InSpec's SSL resource by enforcing strong TLS configuration.

The tests are based on

Standalone Usage

Requires InSpec 1.21.0 or newer for execution:

$ git clone https://github.com/dev-sec/ssl-baseline
$ inspec exec ssl-baseline

You can also execute the profile directly from Github:

$ inspec exec https://github.com/dev-sec/ssl-baseline

Covered Attacks / Weaknesses

Contributors + Kudos

License and Author

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.