Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
Red Hat Satellite engineering is moving the tracking of its product development work on Satellite to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "Satellite project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs will be migrated starting at the end of May. If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "Satellite project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/SAT-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
+++ This bug was initially created as a clone of Bug #1420439 +++
Description of problem: Updating SCAP content on an existing Compliance Policy does not result in synchronization of the new SCAP content on subsequent puppet runs. Content hosts continue to run openscap scans using the previous outdated SCAP content.
TRIAGE NOTES: This is request for 6.2 backport, we have both patches ready for backport.
QA NOTES: See #1420439 for more info about how to reproduce.
UPGRADE NOTES:
After applying the patch, the YAML output for host with a policy should change (classes -> foreman_scap_client -> policies -> download_path), see the attached screenshots.
It is necessary to run puppet on the openscap clients so that config changes are propagated. The patch will not be active until the config is updated on clients.
Steps to apply the patch:
1) apply patches for Satellite server, capsule(s)
2) restart Satellite, capsule(s)
3) run puppet on openscap clients
Steps to verify the patch works:
1) set up a host with openscap, run foreman_scap_client on host
2) update host's policy with a new scap content
3) apply patches, restart Satellite server and capsule(s)
4) check the YAML output for host, download_path should end with a hash as a screenshots suggest
5) run puppet on a host
6) observe changes made to /etc/foreman_scap_client/config.yaml on host. They should correspond to what is in YAML output.
7) run foreman_scap_client, newly generated report should be based on updated scap content
I am closing this out as next release. The fix for this will be available in satellite 6.3. If you are running 6.3 and still seeing this issue, please feel free to re-open and provide additional information.