Bug 1500824

Summary: scap rule claiming to not be enabled by rule checker script
Product: Red Hat CloudForms Management Engine Reporter: luke couzens <lcouzens>
Component: ApplianceAssignee: Nick Carboni <ncarboni>
Status: CLOSED NOTABUG QA Contact: luke couzens <lcouzens>
Severity: medium Docs Contact: Andrew Dahms <adahms>
Priority: medium    
Version: 5.9.0CC: abellott, cpelland, dajohnso, jhardy, jprause, lcouzens, ncarboni, obarenbo, simaishi
Target Milestone: GAKeywords: TestOnly
Target Release: cfme-future   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: black
Fixed In Version: Doc Type: Known Issue
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-09-27 13:41:33 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: CFME Core Target Upstream Version:
Embargoed:

Comment 2 luke couzens 2017-10-12 14:34:09 UTC
Nick could you add some more info to this bz wrt our discussion, you mentioned this potentially could be a bug with ssg. 

Basically this is a knock on affect from the previous scap bug fix #1493193

Comment 3 Nick Carboni 2017-10-12 14:54:37 UTC
Right, so we use the remediation scripts provided by the scap-security-guide package to fix the failed rules.

So, we are running the remediation for this rule, but then a subsequent check for the rule still lists it as failed.

Investigating the files that the rule is checking seems to show that the rule was, indeed, fixed.

These things together seem to indicate some issue with the checker rather than our code around fixing the particular rule.

I will try to find some time to reproduce this in a more targeted way and open a bug against scap-security-guide for this particular failure.

Comment 5 Nick Carboni 2017-11-29 20:41:01 UTC
This is an issue with a convenience script provided to check the scap rules, not the product itself.

As such I'm removing the regression keyword and blocker flag.

Comment 6 Dave Johnson 2017-12-08 15:16:50 UTC
Nick, this sounds like a problem with the scap package itself, can you reach out to that team and find out if its already written.

Comment 7 Dave Johnson 2018-01-11 15:02:27 UTC
Luke, is this still and issue for us?

Comment 8 luke couzens 2018-01-11 15:48:26 UTC
Yes so on 5.9.0.16 the checker script still says that this rule has failed to be applied even though I can see the rules are applied correctly to the relevant files.

Comment 10 Nick Carboni 2018-09-27 13:41:33 UTC
I'm going to close this as not a bug as the feature is working correctly, but the tool we're using to run tests is at fault.

If this continues to be an issue, please open a bug with the OpenScap team and see if they can help.