Bug 922209 - RFE: spacewalk-oscap shall enable new features of OpenSCAP.
Summary: RFE: spacewalk-oscap shall enable new features of OpenSCAP.
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Client
Version: 550
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Stephen Herr
QA Contact: Martin Minar
URL:
Whiteboard:
Depends On: 829349 871120 872248 1007428
Blocks: sat560-blockers
TreeView+ depends on / blocked
 
Reported: 2013-03-15 17:56 UTC by Stephen Herr
Modified: 2018-12-01 17:35 UTC (History)
16 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of: 872248
Environment:
Last Closed: 2013-10-01 19:59:05 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Stephen Herr 2013-03-15 17:56:58 UTC
Previous bug tracked the release of this RFE for RHEL 6, this bug tracks the release of this RFE for RHEL 5. This update requires openscap-utils >= 0.9.2 to be available, which is not yet true for RHEL 5. When an updated openscap-utils is available we can release this bug on RHEL 5.

+++ This bug was initially created as a clone of Bug #872248 +++

Description of problem:
oscap tool takes several command-line arguments, but spacewalk-oscap
package whitelists only a few of them (it enables only those, which do
not posse security risk for client system scanned by Satellite). New
oscap tool brings couple of new features which might be benefitial for
Satellite user running scan.

Newly added command-line options are:
(1) --cpe-dict and --cpe-dict2 
These enable scanning with CPE dictionary. This is required growing
number of SCAP contents. (To name few: STIG, USGCB, scap-security-guide)
(2) --fetch-remote-resources
This one enables fetching remote content from network. This
is basically reqiured to scan USGCB conten
(3) --datastream-id, --xccdf-id
These are usefull when assising complex SCAP 1.2 DataStreams documents.
These are not immediatelly benefitial as SDS documents with multiple
xccdf-s or datastastreams are not yet common.

Version-Release number of selected component (if applicable):
spacewalk-oscap 0.0.10-1

How reproducible:
deterministic

Steps to Reproduce:
1. Schedule new OpenSCAP scan for machine.
2. Specify some of the new arguments
3.
  
Actual results:
New command-line options are forbiden. OpenSCAP scan proceeds wihout them

Expected results:
New command-line options are allowed. OpenSCAP scan proceeds with them.

--- Additional comment from Šimon Lukašík on 2012-11-01 12:16:55 EDT ---

spacewalk.git 365a4b0135985795e16fee0122a3ed87e9afbbf1

--- Additional comment from Šimon Lukašík on 2012-12-11 15:47:10 EST ---

spacewalk.git 1a3f72077e3ec5bbaa786a4b9755e8f1be53357c

Comment 4 Shawn Wells 2013-05-26 00:16:50 UTC
Is there a (public) update to this? Currently neither Satellite or RHEL5 have the ability to perform security scans mandated by the U.S. Government, many customers are interested in the roadmap to get this fixed. Thanks!

Comment 9 Clifford Perry 2013-10-01 19:59:05 UTC
This bug was fixed with updated packages being released within the RHN Tools channels. 


RHN Tools (for Sat 5.6 GA) Errata text:

https://rhn.redhat.com/errata/RHEA-2013-1391.html


Note You need to log in before you can comment on or make changes to this bug.