Bug 2072987 - [Doc] Document DISA STIG installation and usage on RHV
Summary: [Doc] Document DISA STIG installation and usage on RHV
Keywords:
Status: CLOSED NEXTRELEASE
Alias: None
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: Documentation
Version: unspecified
Hardware: Unspecified
OS: Unspecified
urgent
high
Target Milestone: ovirt-4.5.0
: ---
Assignee: Eli Marcus
QA Contact: rhev-docs@redhat.com
URL:
Whiteboard: docscope 4.5, important
Depends On: 2015796 2015802
Blocks: 2073293
TreeView+ depends on / blocked
 
Reported: 2022-04-07 12:23 UTC by Ales Musil
Modified: 2022-06-13 13:10 UTC (History)
20 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
: 2073293 (view as bug list)
Environment:
Last Closed: 2022-05-18 12:51:02 UTC
oVirt Team: Docs
Target Upstream Version:
Embargoed:
emarcus: needinfo-


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github oVirt ovirt-site pull 2882 0 None open Update documentation for RHV security profiles 2022-05-04 09:01:10 UTC
Red Hat Issue Tracker RHV-45568 0 None None None 2022-04-07 12:42:49 UTC
Red Hat Knowledge Base (Solution) 6955078 0 None None None 2022-04-27 00:25:51 UTC

Description Ales Musil 2022-04-07 12:23:11 UTC
RHVH: 
Installation of DISA STIG profile on RHVH is not supported. 
Upgrade from DRAFT DISA STIG is not supported.

Host (not RHVH):
Installation is supported through anaconda by selecting DISA STIG security profile. 
Upgrade from DRAFT DISA STIG is not supported.

Standalone engine:
Installation is supported through anaconda by selecting DISA STIG security profile. 
Upgrade from DRAFT DISA STIG is not supported.

Hosted Engine:
Installation is supported through HE options, "he_apply_openscap_profile" as "True"
and "he_openscap_profile_name" as "stig" (which is the default value).
Upgrade from DRAFT DISA STIG is not supported.

Comment 1 Marina Kalinin 2022-04-07 16:00:59 UTC
How does one distinguish between DRAFT and non DRAFT profile?

Comment 4 Ales Musil 2022-04-08 04:57:30 UTC
(In reply to Marina Kalinin from comment #1)
> How does one distinguish between DRAFT and non DRAFT profile?

It is in the name of the old one. "[DRAFT] DISA STIG for Red Hat Virtualization Host (RHVH)".

Comment 10 Sandro Bonazzola 2022-05-02 13:47:12 UTC
(In reply to Ales Musil from comment #0)
> RHVH: 
> Installation of DISA STIG profile on RHVH is not supported. 
> Upgrade from DRAFT DISA STIG is not supported.
> 
> Host (not RHVH):
> Installation is supported through anaconda by selecting DISA STIG security
> profile. 
> Upgrade from DRAFT DISA STIG is not supported.

Is there any specific manual step here? DISA STIG security profile requires a special disk partitioning. Any recommendation for the size of the various partitions?
DISA STIG also disables root ssh access to the host. Any recommendation about this?
Within DISA STIG, which profile is going to be supported? xccdf_mil.disa.stig_profile_MAC-1_Classified ?


> Standalone engine:
> Installation is supported through anaconda by selecting DISA STIG security
> profile. 
> Upgrade from DRAFT DISA STIG is not supported.
> 
> Hosted Engine:
> Installation is supported through HE options, "he_apply_openscap_profile" as
> "True"
> and "he_openscap_profile_name" as "stig" (which is the default value).
> Upgrade from DRAFT DISA STIG is not supported.

Comment 11 Ales Musil 2022-05-02 13:57:12 UTC
(In reply to Sandro Bonazzola from comment #10)
> (In reply to Ales Musil from comment #0)
> > RHVH: 
> > Installation of DISA STIG profile on RHVH is not supported. 
> > Upgrade from DRAFT DISA STIG is not supported.
> > 
> > Host (not RHVH):
> > Installation is supported through anaconda by selecting DISA STIG security
> > profile. 
> > Upgrade from DRAFT DISA STIG is not supported.
> 
> Is there any specific manual step here?

There shouldn't be any manual step required.
 
> DISA STIG security profile requires
> a special disk partitioning. Any recommendation for the size of the various
> partitions?

We can discuss the partition size, I am not sure if there's any recommendation from RHEL.

> DISA STIG also disables root ssh access to the host. Any recommendation
> about this?

For RHV the profile does not disable root ssh access. 

> Within DISA STIG, which profile is going to be supported?
> xccdf_mil.disa.stig_profile_MAC-1_Classified ?

I am not sure what are you reffering to, the DISA STIG profile is xccdf_org.ssgproject.content_profile_stig.

> 
> 
> > Standalone engine:
> > Installation is supported through anaconda by selecting DISA STIG security
> > profile. 
> > Upgrade from DRAFT DISA STIG is not supported.
> > 
> > Hosted Engine:
> > Installation is supported through HE options, "he_apply_openscap_profile" as
> > "True"
> > and "he_openscap_profile_name" as "stig" (which is the default value).
> > Upgrade from DRAFT DISA STIG is not supported.

Comment 12 Eli Marcus 2022-05-10 19:00:02 UTC
new PR for changes to documentation
https://github.com/oVirt/ovirt-site/pull/2899
Changes proposed in this pull request:

    Remove instructions for adding DISAQ STIG profile to RHVH
    Remove mention of DISA STIG for RHVH
    Add notice to Removed Functionality table in Release Notes

Comment 13 Eli Marcus 2022-05-11 13:21:24 UTC
Closed previous PR - this new PR by Ales Musil addresses the DISA STIG as well as additional security profile updates

https://github.com/oVirt/ovirt-site/pull/2882

Comment 14 Eli Marcus 2022-05-18 12:51:02 UTC
Merged the PR https://github.com/oVirt/ovirt-site/pull/2899

Comment 15 Marina Kalinin 2022-05-24 20:32:23 UTC
(In reply to Eli Marcus from comment #14)
> Merged the PR https://github.com/oVirt/ovirt-site/pull/2899

Eli, when exactly this is going to be merged in documentation? With 4.5.0 or later?

Comment 16 Eli Marcus 2022-06-13 13:10:35 UTC
(In reply to Marina Kalinin from comment #15)
> (In reply to Eli Marcus from comment #14)
> > Merged the PR https://github.com/oVirt/ovirt-site/pull/2899
> 
> Eli, when exactly this is going to be merged in documentation? With 4.5.0 or
> later?

Hi Marina     The updates are visible in the current (RHV 4.4) documentation


Note You need to log in before you can comment on or make changes to this bug.