This service will be undergoing maintenance at 00:00 UTC, 2016-08-01. It is expected to last about 1 hours
Bug 872248 - RFE: spacewalk-oscap shall enable new features of OpenSCAP.
RFE: spacewalk-oscap shall enable new features of OpenSCAP.
Status: CLOSED ERRATA
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Client (Show other bugs)
550
Unspecified Unspecified
unspecified Severity unspecified
: ---
: ---
Assigned To: Michael Mráka
Lukas Pramuk
: FutureFeature
: 889010 (view as bug list)
Depends On: 1007428 829349 871120
Blocks: 819027 922209
  Show dependency treegraph
 
Reported: 2012-11-01 12:06 EDT by Šimon Lukašík
Modified: 2013-09-12 09:20 EDT (History)
12 users (show)

See Also:
Fixed In Version:
Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of:
: 922209 (view as bug list)
Environment:
Last Closed: 2013-03-25 02:29:15 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Šimon Lukašík 2012-11-01 12:06:42 EDT
Description of problem:
oscap tool takes several command-line arguments, but spacewalk-oscap
package whitelists only a few of them (it enables only those, which do
not posse security risk for client system scanned by Satellite). New
oscap tool brings couple of new features which might be benefitial for
Satellite user running scan.

Newly added command-line options are:
(1) --cpe-dict and --cpe-dict2 
These enable scanning with CPE dictionary. This is required growing
number of SCAP contents. (To name few: STIG, USGCB, scap-security-guide)
(2) --fetch-remote-resources
This one enables fetching remote content from network. This
is basically reqiured to scan USGCB conten
(3) --datastream-id, --xccdf-id
These are usefull when assising complex SCAP 1.2 DataStreams documents.
These are not immediatelly benefitial as SDS documents with multiple
xccdf-s or datastastreams are not yet common.

Version-Release number of selected component (if applicable):
spacewalk-oscap 0.0.10-1

How reproducible:
deterministic

Steps to Reproduce:
1. Schedule new OpenSCAP scan for machine.
2. Specify some of the new arguments
3.
  
Actual results:
New command-line options are forbiden. OpenSCAP scan proceeds wihout them

Expected results:
New command-line options are allowed. OpenSCAP scan proceeds with them.
Comment 2 Šimon Lukašík 2012-11-01 12:16:55 EDT
spacewalk.git 365a4b0135985795e16fee0122a3ed87e9afbbf1
Comment 4 Šimon Lukašík 2012-12-11 15:47:10 EST
spacewalk.git 1a3f72077e3ec5bbaa786a4b9755e8f1be53357c
Comment 7 Šimon Lukašík 2013-01-31 11:12:53 EST
*** Bug 889010 has been marked as a duplicate of this bug. ***
Comment 15 Stephen Herr 2013-03-15 14:00:13 EDT
Bug 922209 has been created as a clone of this RFE to track the release of updated packages for RHEL 5. This bug will track the release of updated packages for RHEL 6.

This update requires openscap-utils >= 0.9.2, which is currently available in RHEL 6 but not RHEL 5.
Comment 20 errata-xmlrpc 2013-03-25 02:29:15 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHEA-2013-0676.html

Note You need to log in before you can comment on or make changes to this bug.