<div dir="ltr"><div dir="ltr">Thanks Shawn, I have used NIST content validation and realized the test passed for ssg-rhel6-ds.xml (downloaded from
<span><a href="https://github.com/ComplianceAsCode/content/releases/download/v0.1.43/scap-security-guide-0.1.43-oval-510.zip" target="_blank">https://github.com/ComplianceAsCode/content/releases/download/v0.1.43/scap-security-guide-0.1.43-oval-510.zip</a></span>) However Nessus SCAP scanning gives error as "Default namespace not found in OVAL" I am checking with Nessus tech support team</div><div dir="ltr"><br></div><div>Thanks,</div><div>Riaz<br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Apr 30, 2019 at 12:16 AM Shawn Wells <<a href="mailto:shawn@redhat.com">shawn@redhat.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="auto"><div dir="ltr"></div><div dir="ltr">Would need to understand where the content is coming from. Perhaps scap-security-guide in RHEL, and if so, what RHEL and SSG version?</div><div dir="ltr"><br></div><div dir="ltr">Note red hat doesn’t publish rhel6 content in the National Checklist Program since rhel6 is out of active maintenance:</div><div dir="ltr"><br></div><div dir="ltr"><a href="https://nvd.nist.gov/ncp/repository?authority=Red+Hat&startIndex=0" target="_blank">https://nvd.nist.gov/ncp/repository?authority=Red+Hat&startIndex=0</a></div><div dir="ltr"><br></div><div dir="ltr">Once the content source/version version is identified , the content can be ran through the NIST content validator tooling to see if there are problems with the content itself.</div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br>On Apr 29, 2019, at 11:19 AM, Jan Cerny <<a href="mailto:jcerny@redhat.com" target="_blank">jcerny@redhat.com</a>> wrote:<br><br></div><blockquote type="cite"><div dir="ltr"><span>Hi,</span><br><span></span><br><span>I have no idea. Does Nessus have any "verbose" mode to get more</span><br><span>helpful error message?</span><br><span></span><br><span>Including scap-security-guide list in this conversation because there</span><br><span>might be people familiar with using SSG with Nessus.</span><br><span></span><br><span>Regards</span><br><span></span><br><span>On Mon, Apr 29, 2019 at 4:54 PM Riaz Ebrahim <<a href="mailto:mriazebrahim1@gmail.com" target="_blank">mriazebrahim1@gmail.com</a>> wrote:</span><br><blockquote type="cite"><span></span><br></blockquote><blockquote type="cite"><span>Hi Jan Cerny,</span><br></blockquote><blockquote type="cite"><span></span><br></blockquote><blockquote type="cite"><span>Thanks a lot for your response, Your answer was very useful to understand about SSG files. As per your advice i tried with scap-security-guide-0.1.43-oval-510.zip and XML validation error was gone, but encountering new error as below from nessus</span><br></blockquote><blockquote type="cite"><span></span><br></blockquote><blockquote type="cite"><span>"ssg-rhel6-ds-1.zip : Default namespace not found in OVAL"</span><br></blockquote><blockquote type="cite"><span></span><br></blockquote><blockquote type="cite"><span>Do you get any clue by seeing this error?. Thanks in advance :)</span><br></blockquote><blockquote type="cite"><span></span><br></blockquote><blockquote type="cite"><span>Thanks,</span><br></blockquote><blockquote type="cite"><span>Riaz</span><br></blockquote><blockquote type="cite"><span></span><br></blockquote><blockquote type="cite"><span>On Mon, Apr 29, 2019 at 2:44 PM Jan Cerny <<a href="mailto:jcerny@redhat.com" target="_blank">jcerny@redhat.com</a>> wrote:</span><br></blockquote><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>Hi,</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>I will try to answer, but I don't use Nessus, so I'm not sure what is</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>the exact reason of this fail.</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>In general, the SSG files are validated against SCAP XML schemas, so</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>they are valid SCAP content.</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>However, SCAP standard consist of multiple separate specifications.</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>Strictly speaking, the SSG datastream</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>doesn't conform to SCAP 1.2 specification, because the datastream</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>contains OVAL checks conforming to OVAL</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>version 5.11 which is a part of SCAP 1.3. For SCAP 1.2 conformance it</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>would need to use OVAL checks</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>in version 5.10 or older.</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>According to this forum thread, it seems that Nessus doesn't support</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>OVAL 5.11 it yet, but they say it's planned to be updated</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span><a href="https://community.tenable.com/s/question/0D5f200005hKRwqCAG/nessus-pro-7-trouble-getting-oval-scans-to-work" target="_blank">https://community.tenable.com/s/question/0D5f200005hKRwqCAG/nessus-pro-7-trouble-getting-oval-scans-to-work</a></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>It could be a problem that Nessus expects datastreams that contain</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>OVAL 5.10 only.</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>Try using the SSG datastreams that contain OVAL 5.10 only. They can be</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>downloaded from</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span><a href="https://github.com/ComplianceAsCode/content/releases/download/v0.1.43/scap-security-guide-0.1.43-oval-510.zip" target="_blank">https://github.com/ComplianceAsCode/content/releases/download/v0.1.43/scap-security-guide-0.1.43-oval-510.zip</a></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>I hope Nessus should be able to consume these files.</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>The reason why we use 5.11 is that it contains new checks that allows</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>us to check easily system services using systemd</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>and other new things introduced in RHEL 7. The aforementioned</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>datastreams that contain OVAL 5.10 only</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>have limited abilities in comparison with those containing OVAL 5.11.</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>Best Regards</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>Jan Černý</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>Security Technologies | Red Hat, Inc.</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><span>On Sat, Apr 27, 2019 at 6:34 AM Riaz Ebrahim <<a href="mailto:mriazebrahim1@gmail.com" target="_blank">mriazebrahim1@gmail.com</a>> wrote:</span><br></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span>I need help on openscap SSG project.</span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span>I am currently exploring SCAP Auditing feature from Nessus console. I understood that Nessus supports SCAP Content (1.0 or 1.1 or 1.2) which can be downloaded from NIST repository (<a href="https://nvd.nist.gov/ncp/repository" target="_blank">https://nvd.nist.gov/ncp/repository</a>) based on the target host version. This works great, However when i use SCAP from OpenSCAP SSG (example "ssg-rhel6-ds.xml”), i am getting error as “sg-rhel6-ds. .zip : sg-rhel6-ds.xml failed XML Schema validation” .</span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span>I would like to what is the difference between openSSG scap data stream & scap1.2 content downloaded from NIST repository. How i can convert openssg data stream (Example - ssg-rhel6-ds.xml) to NIST scap 1.2 format.</span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span>My objective - To use openscap SSG from Nessus. Nessus scap scanning expects SCAP 1.0, 1.1 or 1.2 content(in zip format).</span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span>Thanks in advance!</span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span></span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span>_______________________________________________</span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span>Open-scap-list mailing list</span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span><a href="mailto:Open-scap-list@redhat.com" target="_blank">Open-scap-list@redhat.com</a></span><br></blockquote></blockquote></blockquote><blockquote type="cite"><blockquote type="cite"><blockquote type="cite"><span><a href="https://www.redhat.com/mailman/listinfo/open-scap-list" target="_blank">https://www.redhat.com/mailman/listinfo/open-scap-list</a></span><br></blockquote></blockquote></blockquote><span></span><br><span></span><br><span></span><br><span>--</span><br><span>Jan Černý</span><br><span>Security Technologies | Red Hat, Inc.</span><br><span>_______________________________________________</span><br><span>scap-security-guide mailing list -- <a href="mailto:scap-security-guide@lists.fedorahosted.org" target="_blank">scap-security-guide@lists.fedorahosted.org</a></span><br><span>To unsubscribe send an email to <a href="mailto:scap-security-guide-leave@lists.fedorahosted.org" target="_blank">scap-security-guide-leave@lists.fedorahosted.org</a></span><br><span>Fedora Code of Conduct: <a href="https://getfedora.org/code-of-conduct.html" target="_blank">https://getfedora.org/code-of-conduct.html</a></span><br><span>List Guidelines: <a href="https://fedoraproject.org/wiki/Mailing_list_guidelines" target="_blank">https://fedoraproject.org/wiki/Mailing_list_guidelines</a></span><br><span>List Archives: <a href="https://lists.fedorahosted.org/archives/list/scap-security-guide@lists.fedorahosted.org" target="_blank">https://lists.fedorahosted.org/archives/list/scap-security-guide@lists.fedorahosted.org</a></span><br></div></blockquote></div></blockquote></div>