[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]

Re: [Spacewalk-list] OpenScap/SSG and CentOS



Dear Uğur, good morning

Tnx for reply, I was in deep with the conf files and discovered a few hours ago.

Bellow some command to change conf files and turn available to CentOS

[root deskx content]# yum install scap-security-guide -y

[root deskx content]# sed -i -e "s#<platform>Red Hat Enterprise Linux 6</platform>#<platform>CentOS 6</platform>##g" /usr/share/xml/scap/ssg/content/ssg-rhel6-cpe-oval.xml
[root deskx content]# sed -i -e "s#cpe:/o:redhat:enterprise_linux:6#cpe:/o:centos:centos:6##g" /usr/share/xml/scap/ssg/content/ssg-rhel6-cpe-oval.xml
[root deskx content]# sed -i -e "s#cpe:/o:redhat:enterprise_linux#cpe:/o:centos:centos##g" /usr/share/xml/scap/ssg/content/ssg-rhel6-xccdf.xml

after this, just run the command, for example to server profile

[root deskx content]# oscap xccdf eval --profile server ssg-rhel6-xccdf.xml
...
Title   Mount Remote Filesystems with nosuid
Rule    use_nosuid_option_on_nfs_mounts
Ident   CCE-26972-0
Result  pass

Title   Require Client SMB Packet Signing, if using smbclient
Rule    require_smb_client_signing
Ident   CCE-26328-5
Result  fail

Title   Require Client SMB Packet Signing, if using mount.cifs
Rule    require_smb_client_signing_mount.cifs
Ident   CCE-26792-2
Result  pass

[root deskx content]# cat /etc/redhat-release
CentOS release 6.5 (Final)
[root deskx content]#

B'Regards


On Sun, Nov 2, 2014 at 9:12 AM, Uğur Engin <mail ugurengin com> wrote:

Hello,

Of course, you can use it properly.However you must be change some values in xml files where is stored in openscap directory.

For example CNT6:

Change these values "cpe:/o:redhat:enterprise_linux:6" to  cpe:/o:centos:centos:6
https://bugzilla.redhat.com/show_bug.cgi?id=1085977


On Sun, Nov 2, 2014 at 11:17 AM, Waldirio Manhães Pinheiro <waldirio gmail com> wrote:
Friends, good morning

Is it possible use SSG with CentOS ?!, I've this environment with rhel and works fine, although I would like to configure in CentOS.

Thanks in advanced!

_______________________________________________
Spacewalk-list mailing list
Spacewalk-list redhat com
https://www.redhat.com/mailman/listinfo/spacewalk-list


_______________________________________________
Spacewalk-list mailing list
Spacewalk-list redhat com
https://www.redhat.com/mailman/listinfo/spacewalk-list


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]