Apache httpd, One TLS Site And A Cipher List That Holds
httpd with mod_ssl from AppStream on EL 10: one TLS site, an explicit protocol floor and cipher list, HSTS, and the plain port doing nothing but redirecting. The live test reads the site with the certificate the role installed, checks the headers, and is refused when it asks for a cipher outside the list. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-26 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-httpd-tls?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [Apache httpd, One TLS Site And A Cipher List That Holds](https://www.iac-bazaar.com/catalog/ansible-httpd-tls?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# Apache httpd, One TLS Site And A Cipher List That Holds: https://www.iac-bazaar.com/catalog/ansible-httpd-tls (download from your IaC Bazaar account)
```Preview:
Documentation
httpd-tls
A TLS site on the distribution's own httpd. The role installs httpd and
mod_ssl, writes one drop-in that serves a single TLS vhost with an explicit
protocol floor and cipher list, sends the plain port to it with a permanent
redirect, and removes the sample vhost and welcome page that would otherwise
answer for anything unmatched.
No download, and no version to pin. EL 10 packages httpd and mod_ssl, so the
role installs them by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the site's TLS configuration and the proof that it holds.
The distribution's unit, our configuration. The role installs httpd,
mod_ssl and openssl, writes one drop-in under /etc/httpd/conf.d, owns the
single Listen line in httpd.conf, and enables the unit the package ships:
systemctl cat httpd shows the distribution's own unit, not one this role
invented.
The defaults are 8443 and 8080 on loopback, and a public site changes both.
A role that bound 443 on every address the moment it was applied would be a
surprise, so the defaults are deliberately local: set httpd_tls_port to 443,
httpd_tls_http_port to 80 and httpd_tls_listen_address to the address to
serve. The package's unit already carries CAP_NET_BIND_SERVICE, so the
privileged ports need nothing else.
What can be proven about a protocol floor on EL 10, and what cannot. An
openssl 3.5 client refuses TLS 1.1 by its own crypto policy and sends no
packet, so a test asserting "TLS 1.1 was refused" passes against a server that
allows it - measured twice, once against a vhost deliberately configured to
accept 1.1. The verify therefore proves the restriction with a cipher instead:
AES128-SHA is answered with a handshake_failure alert by the server, and the
same request is accepted as soon as SSLCipherSuite is removed.
No LoadModule lines. conf.modules.d already loads ssl, headers and
socache_shmcb; a role that loads them again makes httpd log AH01574 on every
start, which trains an operator to read warnings as normal.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-caddy-https
Caddy with HTTPS on: the package serves plain HTTP with a Server header and an admin API any local process can use. This role gives private names a certificate from Caddy's own CA (public ones get Let's Encrypt), redirects HTTP, sends HSTS and the security headers, drops Server, turns the admin API off, and serves files or proxies an upstream. Original role, live-tested on Rocky Linux 10.
ansible-nginx
Verified wrapper around geerlingguy.nginx pinned at 3.3.0 plus an IaC Bazaar hardening overlay (server_tokens off, security headers, default-vhost removal); live-tested for idempotence and functionally verified: systemd unit active, HTTP 200, headers present, no version leak.
ansible-php-fpm
php-fpm from AppStream on EL 10: one pool on a unix socket, open_basedir closed around its own tree, and the process-spawning functions removed. The live test runs PHP through the socket, is refused a read outside the tree, watches a call to a removed function stop the request, and finds nothing listening on TCP. Original role, live-tested on Rocky Linux 10.