[Open-scap] OVAL content authoring tool

Martin Preisler mpreisle at redhat.com
Tue Mar 29 16:18:50 UTC 2016


----- Original Message -----
> From: "Pravin Goyal" <pravin.goyal at outlook.com>
> To: open-scap-list at redhat.com
> Sent: Tuesday, March 29, 2016 1:32:53 AM
> Subject: [Open-scap] OVAL content authoring tool
> 
> Hi Team,
> I am sure this is a FAQ. Do you know of a well-maintained content authoring
> tool?

We have tried several times to come up with some fancy GUI tool to help with
the development but never succeeded. The GUI tool ends up having too many
options or it's not powerful enough. I recommend looking at how SSG is built,
how we use templates to generate the boilerplate.

The tools I suggest are git, a text editor and SSG build scripts.

> I am aware of
> https://git.fedorahosted.org/cgit/scap-security-guide.git/tree/RHEL/6/transforms
> that we use to develop SSG content.
> 
> Is this still valid -
> http://blog-shawndwells.rhcloud.com/wp-content/uploads/2013/07/SCAP-Workshop-Coursebook-v2.pdf
> ?

Looks like it is except for the repository URIs. Change them to github URIs
and this will work.

> Do you have any other suggestions in this regard? I am beginning a project
> that would require the development of some 500+ OVAL rules. So, I am just
> ensuring that I can make the best use of tools or processes already known to
> the community.

I recommend leveraging this community. I don't know if the project you will
be working on is an open source project but if so we will be able (and happy)
to help you review the patches and work on the project.

-- 
Martin Preisler
Identity Management and Platform Security | Red Hat, Inc.




More information about the Open-scap-list mailing list