mozilla-ssl-config-generator v1.0.0
Mozilla SSL Configuration Generator
The Mozilla SSL Configuration Generator is a tool which builds configuration files to help you follow the Mozilla Server Side TLS configuration guidelines.
Installation
$ npm installDevelopment
Once you've installed, you can simply run:
$ npm run watchThis starts a local webserver that will automatically reload your changes.
Adding new software
There are two places that need to be updated in order to add support for a new piece of software:
src/js/configs.js, which sets the supported features for your software, andsrc/templates/partials/your-software.hbs, a Handlebars.js template that mirrors your software's configuration
Creating templates
All of the templates are written in Handlebars.js, and so therefore support all of its standard features. This includes if/else/unless conditionals and each loops, for example. In addition, the configuration generator supports the following helpers:
eq(item, value)-trueifitemequalsvalueincludes(item, stringOrArray)-trueifstringOrArraycontainsitemjoin(array, joiner)- split a array into a string based onjoiner{{{join output.ciphers ":"}}}
last(array)- returns the last item in the arrayminpatchver(minimumver, curver)-trueifcurveris greater than or equal tominimumver, and both versions are the same patch version, e.g.2.2{{#if (minpatchver "2.4.3" form.serverVersion)}}
minver(minimumver, curver)-trueifcurveris greater than or equal tominver{{#if (minver "1.9.5" form.serverVersion)}}
replace(string, whattoreplace, replacement)- replaces whatToReplace with replacementreplace(protocol, "TLSv", "TLS ")
reverse(array)- reverses the order of an array{{#each (reverse output.protocols)}
sameminorver(version, otherVersion)- returnstrueifversionandotherVersionare of the same minor version, e.g.2.2{{#if (sameminorver "2.4.0" form.serverVersion)}}
split(string, splitter)- split a string into an array based onsplitter{{#each (split somearray ":")}}
Building
To publish to GitHub Pages, simply run:
$ npm run buildHistory
The SSL Config Generator was kept in the mozilla/server-side-tls repository
prior to mid 2019 at which point it was moved to this dedicated repository. It
was initially created at the end of 2014
and started out supporting Apache HTTP, Nginx and HAProxy.
Authors
License
- Mozilla Public License Version 2.0
4 years ago