Red Hat Bugzilla – Bug 872248
RFE: spacewalk-oscap shall enable new features of OpenSCAP.
Last modified: 2013-09-12 09:20:33 EDT
Description of problem:
oscap tool takes several command-line arguments, but spacewalk-oscap
package whitelists only a few of them (it enables only those, which do
not posse security risk for client system scanned by Satellite). New
oscap tool brings couple of new features which might be benefitial for
Satellite user running scan.
Newly added command-line options are:
(1) --cpe-dict and --cpe-dict2
These enable scanning with CPE dictionary. This is required growing
number of SCAP contents. (To name few: STIG, USGCB, scap-security-guide)
This one enables fetching remote content from network. This
is basically reqiured to scan USGCB conten
(3) --datastream-id, --xccdf-id
These are usefull when assising complex SCAP 1.2 DataStreams documents.
These are not immediatelly benefitial as SDS documents with multiple
xccdf-s or datastastreams are not yet common.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. Schedule new OpenSCAP scan for machine.
2. Specify some of the new arguments
New command-line options are forbiden. OpenSCAP scan proceeds wihout them
New command-line options are allowed. OpenSCAP scan proceeds with them.
*** Bug 889010 has been marked as a duplicate of this bug. ***
Bug 922209 has been created as a clone of this RFE to track the release of updated packages for RHEL 5. This bug will track the release of updated packages for RHEL 6.
This update requires openscap-utils >= 0.9.2, which is currently available in RHEL 6 but not RHEL 5.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.