<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";
        color:black;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor="white" lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Adding the ‘—oval-results’ flag to my run gave me more data. My output looks more like yours in format now.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Thx.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Chris.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:windowtext">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:windowtext"> open-scap-list-bounces@redhat.com [mailto:open-scap-list-bounces@redhat.com]
<b>On Behalf Of </b>Shawn Wells<br>
<b>Sent:</b> Wednesday, January 30, 2013 12:58 PM<br>
<b>To:</b> open-scap-list@redhat.com<br>
<b>Subject:</b> Re: [Open-scap] Need help understanding RHEL STIG findings<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal">On 1/30/13 11:38 AM, Snyder, Chris wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">I’m trying to understand my findings from applying the latest RHEL5 STIG Benchmark against one of my RHEL5 hosts.  The results appear to indicate some false positives and I don’t
 know how to determine if that is indeed the case or not.  Ultimately, I would love to gain more insight into how to determine what tests are being performed by openscap for a given STIG/XCCDF/OVAL item or at least how to find out the results of the tests being
 run, i.e. I want to understand WHY openscap is reporting these items as failed.<o:p></o:p></p>
</blockquote>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
To make things a bit more consumable you can utilize OpenSCAP's "generate guide," turning the STIG into something that is actually readable:<br>
<br>
$ oscap xccdf generate guide \<br>
/tmp/U_RedHat_5-V1R1_STIG_Benchmark-xccdf.xml \ <br>
> /tmp/U_RedHat_5-V1R1_STIG_Benchmark.html<br>
<br>
Pull up /tmp/U_RedHat_5-V1R1_STIG_Benchmark.html in your favorite browser and look around.<br>
<br>
<br>
When you run a scan you can have OpenSCAP generate an HTML report which gives more details around failures:<br>
<br>
$ sudo sh -c "oscap xccdf eval --profile MAC-1_Public \<br>
--results stig-xccdf-results.xml \<br>
--report /tmp/`hostname`-stigscanresults.html \<br>
--oval-results \<br>
--cpe-dict /tmp/U_RedHat_5-V1R1_STIG_Benchmark-cpe-dictionary.xml \<br>
/tmp/U_RedHat_5-V1R1_STIG_Benchmark-xccdf.xml"<br>
<br>
View /tmp/`hostname`-stigscanresults.html in your browser and click on some of the failed items. Many give you details under the "Remediation Script" section.<br>
<br>
Here is my report against a generic RHEL 5.8 install, for example:<br>
<a href="https://blog-shawndwells.rhcloud.com/wp-content/uploads/2012/10/stigscanresults-beforeaqueduct.html">https://blog-shawndwells.rhcloud.com/wp-content/uploads/2012/10/stigscanresults-beforeaqueduct.html</a><br>
<br>
Here is the process that I use for STIGing a RHEL5 box, using OpenSCAP+Aqueduct:<br>
<a href="https://blog-shawndwells.rhcloud.com/2012/10/how-to-stig-a-red-hat-enterprise-linux-rhel5-machine/">https://blog-shawndwells.rhcloud.com/2012/10/how-to-stig-a-red-hat-enterprise-linux-rhel5-machine/</a><br>
<br>
<o:p></o:p></p>
</div>
</body>
</html>