[Open-scap] Process58 - command_line

Šimon Lukašík slukasik at redhat.com
Mon Mar 16 13:04:52 UTC 2015


On 03/10/2015 04:40 PM, Trey Henefield wrote:
>
>
> Greetings,
>
> I am writing a SCAP check to capture the ps output for the X Server, in
> an effort to capture the actual parameters passed when starting the X
> Server. This is in reference to the RHEL5 STIG requirement
> GEN000000-LNX00360.
>
> I am using openscap v1.0.8, which shows to support OVAL 5.10.1.
>
> The problem I have is that the command_line test only returns the
> process command and not the full output of the parameters passed to the
> command.
>
> However, according to the OVAL specification for 5.10.1, it says that
> the full set of parameters should be returned.
>
> https://oval.mitre.org/language/version5.10.1/ovaldefinition/documentation/unix-definitions-schema.html#process58_test
>

Thank You for the report, Trey!

Indeed, this seems to be issue in OpenSCAP scanner. I have filed 
upstream ticket at

   https://fedorahosted.org/openscap/ticket/449

Please work with your product vendor if you want to prioritize a fix for 
this issue.

Thanks!

-- 
Šimon Lukašík
Security Technologies, Red Hat, Inc.




More information about the Open-scap-list mailing list