Bug 922209

Summary: RFE: spacewalk-oscap shall enable new features of OpenSCAP.
Product: Red Hat Satellite 5 Reporter: Stephen Herr <sherr>
Component: ClientAssignee: Stephen Herr <sherr>
Status: CLOSED CURRENTRELEASE QA Contact: Martin Minar <mminar>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 550CC: bsaylor, cperry, daobrien, degts, dyordano, gbarros, ggainey, mkoci, mminar, nbronson, pcfe, pgustafs, slukasik, ssekidde, swells, yjog
Target Milestone: ---Keywords: FutureFeature
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of: 872248 Environment:
Last Closed: 2013-10-01 19:59:05 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 829349, 871120, 872248, 1007428    
Bug Blocks: 924171    

Description Stephen Herr 2013-03-15 17:56:58 UTC
Previous bug tracked the release of this RFE for RHEL 6, this bug tracks the release of this RFE for RHEL 5. This update requires openscap-utils >= 0.9.2 to be available, which is not yet true for RHEL 5. When an updated openscap-utils is available we can release this bug on RHEL 5.

+++ This bug was initially created as a clone of Bug #872248 +++

Description of problem:
oscap tool takes several command-line arguments, but spacewalk-oscap
package whitelists only a few of them (it enables only those, which do
not posse security risk for client system scanned by Satellite). New
oscap tool brings couple of new features which might be benefitial for
Satellite user running scan.

Newly added command-line options are:
(1) --cpe-dict and --cpe-dict2 
These enable scanning with CPE dictionary. This is required growing
number of SCAP contents. (To name few: STIG, USGCB, scap-security-guide)
(2) --fetch-remote-resources
This one enables fetching remote content from network. This
is basically reqiured to scan USGCB conten
(3) --datastream-id, --xccdf-id
These are usefull when assising complex SCAP 1.2 DataStreams documents.
These are not immediatelly benefitial as SDS documents with multiple
xccdf-s or datastastreams are not yet common.

Version-Release number of selected component (if applicable):
spacewalk-oscap 0.0.10-1

How reproducible:
deterministic

Steps to Reproduce:
1. Schedule new OpenSCAP scan for machine.
2. Specify some of the new arguments
3.
  
Actual results:
New command-line options are forbiden. OpenSCAP scan proceeds wihout them

Expected results:
New command-line options are allowed. OpenSCAP scan proceeds with them.

--- Additional comment from Šimon Lukašík on 2012-11-01 12:16:55 EDT ---

spacewalk.git 365a4b0135985795e16fee0122a3ed87e9afbbf1

--- Additional comment from Šimon Lukašík on 2012-12-11 15:47:10 EST ---

spacewalk.git 1a3f72077e3ec5bbaa786a4b9755e8f1be53357c

Comment 4 Shawn Wells 2013-05-26 00:16:50 UTC
Is there a (public) update to this? Currently neither Satellite or RHEL5 have the ability to perform security scans mandated by the U.S. Government, many customers are interested in the roadmap to get this fixed. Thanks!

Comment 9 Clifford Perry 2013-10-01 19:59:05 UTC
This bug was fixed with updated packages being released within the RHN Tools channels. 


RHN Tools (for Sat 5.6 GA) Errata text:

https://rhn.redhat.com/errata/RHEA-2013-1391.html