<div dir="ltr"><div>Please have a look at <a href="https://github.com/ComplianceAsCode/content/issues/7034">https://github.com/ComplianceAsCode/content/issues/7034</a></div><div><br></div><div>Amazon content is not officially supported in the scap-security-guide as far as I know, someone has probably forked the official repo and made some extraordinary modifications. I suggest you take a look at the issue and get acquainted with the documentation of the project in general to understand how you could contribute to make things available.</div><div><br></div><div>Regards.<br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Mar 9, 2023 at 9:19 PM Quick, Bernie <<a href="mailto:baquick@amazon.com">baquick@amazon.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="msg-5756817362790773891"><div lang="EN-US"><div class="m_-5756817362790773891WordSection1"><p class="MsoNormal">Hi,<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">I have successfully run other profiles, but I really want to run this one:<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Helvetica Neue";color:rgb(51,51,51);background:white">xccdf_org.ssgproject.content_profile_ncp<u></u><u></u></span></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">Documented here:<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><a>http://static.open-scap.org/ssg-guides/ssg-rhel7-guide-ncp.html</a><u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">My current use case is an Amazon Linux 2 instance.<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">I have successfully ran:<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">sudo yum install openscap-scanner<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">sudo yum install scap-security-guide<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">sudo oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_ncp --results-arf arf.xml --report report.html /usr/share/xml/scap/ssg/content/ssg-rhel7-ds.xml<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">Report generates and I can see, but nothing is relevant.<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">When I run<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">ls -1 /usr/share/xml/scap/ssg/content/*.xml<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">I get:<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><b>/usr/share/xml/scap/ssg/content/ssg-amzn2-ds.xml<u></u><u></u></b></p><p class="MsoNormal"><b>/usr/share/xml/scap/ssg/content/ssg-amzn2-xccdf.xml<u></u><u></u></b></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-centos6-ds.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-centos6-xccdf.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-centos7-ds.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-centos7-xccdf.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-firefox-cpe-dictionary.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-firefox-cpe-oval.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-firefox-oval.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-firefox-xccdf.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-jre-cpe-dictionary.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-jre-cpe-oval.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-jre-ds.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-jre-ocil.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-jre-oval.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-jre-xccdf.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel6-cpe-dictionary.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel6-cpe-oval.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel6-ds.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel6-ocil.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel6-oval.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel6-xccdf.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel7-cpe-dictionary.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel7-cpe-oval.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel7-ds.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel7-ocil.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel7-oval.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-rhel7-xccdf.xml<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">The only two that seem relevant are the first two:<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-amzn2-ds.xml<u></u><u></u></p><p class="MsoNormal">/usr/share/xml/scap/ssg/content/ssg-amzn2-xccdf.xml<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">But neither of them offers this scan:<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><a>http://static.open-scap.org/ssg-guides/ssg-rhel7-guide-ncp.html</a><u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">I really want this scan:<br><br><span style="font-size:10.5pt;font-family:"Helvetica Neue";color:rgb(119,119,119);background:white">NIST 800-53 control selections for MODERATE impact systems (NIST 800-53)<u></u><u></u></span></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">But if I can get the rest that would great.<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">Thanks,<u></u><u></u></p><p class="MsoNormal">-Bernie<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><b><span style="color:rgb(230,104,38)">bernie</span></b><b><span style="color:black">quick </span></b><span style="color:black">| Senior </span><span style="font-size:9pt;font-family:"Open Sans",sans-serif;color:rgb(34,34,34);background:rgb(249,249,249)">Cloud Infra Architect</span><span style="color:black"><u></u><u></u></span></p><p class="MsoNormal"><span style="color:black">Aerospace and Satellite Professional Services<u></u><u></u></span></p><p class="MsoNormal"><span style="color:black"><a title="http://aws.amazon.com/government-education/"><span style="color:rgb(11,76,180)">Worldwide Public Sector</span></a> | <a><span style="color:rgb(11,76,180)">Amazon Web Services</span></a><u></u><u></u></span></p><p class="MsoNormal"><b><span style="color:black">E: </span></b><span style="color:black"><a>baquick@amazon.com</a> | <b>M: </b>612-963-7742<u></u><u></u></span></p><p class="MsoNormal"><span style="color:black"><img style="width: 1.0416in; height: 0.625in;" id="m_-5756817362790773891Picture_x0020_1" alt="signature_391156818" width="100" height="60" border="0"><img style="width: 0.677in; height: 0.677in;" id="m_-5756817362790773891Picture_x0020_2" alt="signature_1649351063" width="65" height="65" border="0"><u></u><u></u></span></p><p class="MsoNormal"><span style="color:black"><u></u> <u></u></span></p><p class="MsoNormal"><u></u> <u></u></p></div></div>_______________________________________________<br>
Open-scap-list mailing list<br>
<a>Open-scap-list@redhat.com</a><br>
<a rel="noreferrer">https://listman.redhat.com/mailman/listinfo/open-scap-list</a><br>
</div></blockquote></div></div>