Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1459189 - [RFE] Allow to specify per Provider the location of OpenSCAP CVEs and Image-Inspector image
[RFE] Allow to specify per Provider the location of OpenSCAP CVEs and Image-I...
Status: CLOSED ERRATA
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Providers (Show other bugs)
5.8.0
Unspecified Unspecified
unspecified Severity unspecified
: MVP
: 5.9.0
Assigned To: Erez Freiberger
brahmani
: FutureFeature
Depends On: 1378007 1379185 1462835
Blocks:
  Show dependency treegraph
 
Reported: 2017-06-06 09:43 EDT by Loic Avenel
Modified: 2018-04-09 08:31 EDT (History)
14 users (show)

See Also:
Fixed In Version: 5.9.0.4
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-03-01 08:12:59 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: Container Management


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:0380 normal SHIPPED_LIVE Moderate: Red Hat CloudForms security, bug fix, and enhancement update 2018-03-01 13:37:12 EST

  None (edit)
Description Loic Avenel 2017-06-06 09:43:38 EDT
Description of problem: Allow to specify by Provider Location of OpenStack file and ImageScan, this is important for customers with OpenShift that has not access to Internet
Comment 2 Loic Avenel 2017-06-06 09:45:05 EDT
Shout (In reply to Loic Avenel from comment #0)
> Description of problem: Allow to specify by Provider Location of OpenStack
> file and ImageScan, this is important for customers with OpenShift that has
> not access to Internet

Please read OpenScap file and not OpenStack
Comment 3 Federico Simoncelli 2017-06-06 13:22:57 EDT
(In reply to Loic Avenel from comment #0)
> Description of problem: Allow to specify by Provider Location of OpenStack
> file and ImageScan, this is important for customers with OpenShift that has
> not access to Internet

Loic, we already have:

- bug 1379185 for the CVE definitions URL (open ATM)
- bug 1378007 for the image-inspector configuration (verified)

I am OK to keep this BZ as well but it may need a slight different connotation I suppose.

So I am transforming this into the UI side (having a page to configure the above settings).
Feel free to re-arrange this BZ if you think otherwise.
Comment 4 Beni Paskin-Cherniavsky 2017-06-06 14:43:19 EDT
I think from title this talks about configuring image-inspector differently per provider?  bug 1378007 was one global setting.

Assuming that's the goal:
I hope we can stop kludging provider custom attributes.  We need a generic mechanism for per-provider setting overrides.
Comment 5 Federico Simoncelli 2017-06-19 12:18:19 EDT
This requires the per-provider instance advanced settings.
Comment 6 Federico Simoncelli 2017-07-12 03:50:34 EDT
Erez can you add the relevant PRs here?
Please move to ON_DEV if you have all the PRs up for review.
Comment 7 Erez Freiberger 2017-07-12 03:55:16 EDT
The main PR in the UI, still WIP:
https://github.com/ManageIQ/manageiq-ui-classic/pull/1652

It depends on:
ManageIQ/manageiq#15398
ManageIQ/manageiq-schema#23
ManageIQ/manageiq-providers-kubernetes#45
ManageIQ/manageiq-providers-openshift#32
Comment 8 brahmani 2017-11-12 08:09:42 EST
Verify on cfme 5.9.0.8.
update CVE location with value https://www.redhat.com/security/data/metrics/ds --> SSA work OK.

update CVE location with wrong value  https://www.redhat.com/security/data/metrics --> SSA fail with Unable to run OpenSCAP: OpenSCAP error as expected.

Update image_inspector_registry with wrong value: docker (instead of docker.io) --> SSA fail with "job timed out after 1250.265938917 seconds of inactivity" error as expected.
Comment 11 brahmani 2017-11-12 14:33:37 EST
The error message that I get is different, no mention problem with CVE file :

“Unable to run OpenSCAP: OpenSCAP error: 1: exit status 1 Input: [xccdf eval --results-arf /var/tmp/image-inspector-scan-results-274495225/results-arf.xml /tmp/com.redhat.rhsa-RHEL7.ds.xml.bz2] Output: OpenSCAP Error: xmlParseEntityRef: no name [oscap_source.c:278] Entity: line 79: parser error : Entity 'copy' not defined <li>Copyright &copy;2014 Red Hat, Inc.</li> ^ Entity: line 124: parser error : EntityRef: expecting ';' ="https://smtrcs.redhat.com/b/ss/redhatcom,redhatglobal/1/H.25.4--NS/0?[AQB]&cdp ^ Entity: line 124: parser error : xmlParseEntityRef: no name ttps://smtrcs.redhat.com/b/ss/redhatcom,redhatglobal/1/H.25.4--NS/0?[AQB]&cdp=3& ^ Unable to parse XML at: '/tmp/com.redhat.rhsa-RHEL7.ds.xml.bz2' [oscap_source.c:280]”

Erez lets look at that tomorrow.
Comment 14 brahmani 2017-11-13 09:19:26 EST
Erez do you need me to open BZ on that?
Comment 15 brahmani 2017-11-14 03:41:36 EST
BZ 1512824 - Error message correction in case of wrong CVE Loaction value on provider advance settings
https://bugzilla.redhat.com/show_bug.cgi?id=1512824

have been open for track the error message issue.
Comment 18 errata-xmlrpc 2018-03-01 08:12:59 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2018:0380

Note You need to log in before you can comment on or make changes to this bug.