Bug 2224448 - [DDF] If you use "--profile" it will create a playbook based on the profile, not the results scan. This is a corrected
Summary: [DDF] If you use "--profile" it will create a playbook based on the profile, ...
Keywords:
Status: CLOSED COMPLETED
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: Documentation
Version: 8.0
Hardware: All
OS: All
high
unspecified
Target Milestone: rc
: ---
Assignee: Jan Fiala
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-07-20 21:00 UTC by Direct Docs Feedback
Modified: 2023-07-25 16:06 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2023-07-25 16:06:46 UTC
Type: ---
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-162925 0 None None None 2023-07-20 21:01:41 UTC

Description Direct Docs Feedback 2023-07-20 21:00:59 UTC
If you use "--profile" it will create a playbook based on the profile, not the results scan. This is a corrected example:

oscap xccdf generate fix --fix-type ansible --result-id
"" --output hipaa-remediations.yml hipaa-results.xml

Took me like, 2 hours to find this answer. Here's the blog post that helped me. http://redhatgov.io/workshops/rhel_8/exercise1.7/

Try it yourself. The profile ansible playbook will have:
# This Ansible Playbook is generated from an OpenSCAP profile without preliminary evaluation.
# It attempts to fix every selected rule, even if the system is already compliant.
at the top.

Reported by: xhk416x

https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/security_hardening/scanning-the-system-for-configuration-compliance-and-vulnerabilities_security-hardening#annotations:fb7b6d6a-51e9-4aad-8c23-036fcd798ce4

Comment 1 radrao 2023-07-21 09:27:36 UTC
Annotation: Chapter 8. Scanning the system for configuration compliance and vulnerabilities of the "Security Hardening" title


Note You need to log in before you can comment on or make changes to this bug.