[Open-scap] Issues with open-scap 0.9.1 and 0.9.2 on RHEL6 (UNCLASSIFIED)

Shaw, Ray V CTR (US) ray.v.shaw.ctr at mail.mil
Tue Nov 20 16:09:54 UTC 2012


Classification: UNCLASSIFIED
Caveats: NONE

> -----Original Message-----
> From: Spencer R. Shimko [mailto:sshimko at tresys.com]
> Is this really RHEL or is it CentOS?
> 
> Recently we had to start stripping out platform tags to get accurate
> results:
> sed -i -r -e "s/<platform.*//g" /usr/local/scap-security-
> guide/RHEL6/output/ssg-rhel6-xccdf.xml

It's really RHEL.  And thanks for the suggestion; modifying the content as
above allows me to scan with both sets of content using 0.9.2.  The scoring
seems to be working much better for the STIG content (over 0.9.0), and a few
checks that were incorrectly failing are now behaving as expected.

(Just saw the reply from Simon Lukasik; I'll have to try the --cpe option as
well.)

Thanks all,

--
Ray Shaw
Contractor, STG
Unix support, Army Research Labs

Classification: UNCLASSIFIED
Caveats: NONE


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 5621 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/open-scap-list/attachments/20121120/f1df64c8/attachment.bin>


More information about the Open-scap-list mailing list