Bug 1883793 - [RFE] RHV installation with PCI DSS compliance
Summary: [RFE] RHV installation with PCI DSS compliance
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: scap-security-guide-rhv
Version: 4.4.2
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ovirt-4.4.7
: 4.4.7
Assignee: Sandro Bonazzola
QA Contact: cshao
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-09-30 09:18 UTC by Shruti
Modified: 2023-12-15 19:35 UTC (History)
17 users (show)

Fixed In Version: scap-security-guide-0.1.54-2.el8ev redhat-virtualization-host-4.4.7-20210624.0.el8_4
Doc Type: Enhancement
Doc Text:
Red Hat Virtualization Host now includes an updated scap-security-guide-rhv which allows you to apply a PCI DSS security profile to the system during installation,
Clone Of:
Environment:
Last Closed: 2021-07-22 15:07:11 UTC
oVirt Team: Node
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2021:2736 0 None None None 2021-07-22 15:08:55 UTC

Description Shruti 2020-09-30 09:18:29 UTC
Description of problem:


Ability to deploy PCI DSS compliant RHV infrastructure to protect PCI production complexes.

Looking for something similar to this which is available for RHEL servers - https://www.redhat.com/cms/managed-files/cm-red-hat-product-applicability-guide-pci-dss-analyst-paper-f16584-201903-en.pdf

Comment 8 Sandro Bonazzola 2020-12-18 15:26:06 UTC
Tried applying PCI-DSS v3.2.1 and the first thing RHV-H is missing is libreswan package included within the image.

Comment 18 Watson Yuuma Sato 2021-04-22 09:12:37 UTC
A PCI-DSS profile without libreswan was introduced for RHV product in upstream:
https://github.com/ComplianceAsCode/content/pull/6867

Comment 19 Sandro Bonazzola 2021-05-13 07:39:16 UTC
Watson can you build a rpm including it?

Comment 36 errata-xmlrpc 2021-07-22 15:07:11 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Important: Red Hat Virtualization Host security and bug fix update [ovirt-4.4.7]), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2021:2736

Comment 37 Red Hat Bugzilla 2023-09-15 00:48:58 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 500 days


Note You need to log in before you can comment on or make changes to this bug.