Bug 1500824 - scap rule claiming to not be enabled by rule checker script
Summary: scap rule claiming to not be enabled by rule checker script
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Appliance
Version: 5.9.0
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: GA
: cfme-future
Assignee: Nick Carboni
QA Contact: luke couzens
Andrew Dahms
URL:
Whiteboard: black
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-10-11 14:40 UTC by luke couzens
Modified: 2018-09-27 13:41 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: Known Issue
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-09-27 13:41:33 UTC
Category: ---
Cloudforms Team: CFME Core
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 1493193 0 high CLOSED [Regression] appliance_console not enabling all required SCAP rules. 2021-02-22 00:41:40 UTC

Internal Links: 1493193

Comment 2 luke couzens 2017-10-12 14:34:09 UTC
Nick could you add some more info to this bz wrt our discussion, you mentioned this potentially could be a bug with ssg. 

Basically this is a knock on affect from the previous scap bug fix #1493193

Comment 3 Nick Carboni 2017-10-12 14:54:37 UTC
Right, so we use the remediation scripts provided by the scap-security-guide package to fix the failed rules.

So, we are running the remediation for this rule, but then a subsequent check for the rule still lists it as failed.

Investigating the files that the rule is checking seems to show that the rule was, indeed, fixed.

These things together seem to indicate some issue with the checker rather than our code around fixing the particular rule.

I will try to find some time to reproduce this in a more targeted way and open a bug against scap-security-guide for this particular failure.

Comment 5 Nick Carboni 2017-11-29 20:41:01 UTC
This is an issue with a convenience script provided to check the scap rules, not the product itself.

As such I'm removing the regression keyword and blocker flag.

Comment 6 Dave Johnson 2017-12-08 15:16:50 UTC
Nick, this sounds like a problem with the scap package itself, can you reach out to that team and find out if its already written.

Comment 7 Dave Johnson 2018-01-11 15:02:27 UTC
Luke, is this still and issue for us?

Comment 8 luke couzens 2018-01-11 15:48:26 UTC
Yes so on 5.9.0.16 the checker script still says that this rule has failed to be applied even though I can see the rules are applied correctly to the relevant files.

Comment 10 Nick Carboni 2018-09-27 13:41:33 UTC
I'm going to close this as not a bug as the feature is working correctly, but the tool we're using to run tests is at fault.

If this continues to be an issue, please open a bug with the OpenScap team and see if they can help.


Note You need to log in before you can comment on or make changes to this bug.