Bug 1313491

Summary: SCAP Workbench scan issue
Product: Red Hat Enterprise Linux 7 Reporter: Chinmay Paradkar <cparadka>
Component: scap-security-guideAssignee: Jan Lieskovsky <jlieskov>
Status: CLOSED ERRATA QA Contact: Marek Haicman <mhaicman>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.3CC: jlieskov, mhaicman, mpreisle, openscap-maint, pvrabec
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: scap-security-guide-0.1.30-1.el7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-11-04 07:33:32 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Chinmay Paradkar 2016-03-01 17:11:12 UTC
Description of problem:

When viewing the scan results items marked as either "Not Scanned" or "Error" have one of the following lines:

Issue 1: Results listing "None of the check-content-ref elements was resolvable."

Issue 2: Results that list lines like the following: "/tmp/oscap.GUc5gs/fix-XXrUuujq: line 6: perform_audit_rules_privileged_commands_remediation: command not found"

Version details:

Kernel: 3.10.0-327.10.1.el7.x86_64
Following additional packages installed related to SCAP from the RHEL 7.2 Base repo: openscap, openscap-scanner, openscap-utils, openscap-python, scap-security-guide
Other utilities: Confirmed that grep, awk, and sed are all present as well
SCAP Workbench: Version 1.1.1 running on Windows 7
Profile: United States Government Configuration Baseline (USGCB / STIG)
Customizations: Yes, modification to configurable parameters for that baseline

Additional Information:

A bug has been filed with the OpenSCAP project: 

https://github.com/OpenSCAP/scap-security-guide/issues/590
https://github.com/OpenSCAP/scap-security-guide/issues/1055

Comment 3 Jan Lieskovsky 2016-06-01 09:59:30 UTC
Proposed upstream patch:
  https://github.com/OpenSCAP/scap-security-guide/pull/1270

Comment 12 Marek Haicman 2016-07-11 11:53:48 UTC
Confirmed version scap-security-guide-0.1.30-1.el7 together with openscap-1.2.10-1.el7.x86_64 allows remediation of remote machine even when no SSG is present there, or is unusable [via malformation of files].

Verified

Comment 14 errata-xmlrpc 2016-11-04 07:33:32 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2483.html