Hi,

Is there any reason why SSG doesn't use the profile values on the description, 
eg:

(...)
<description>The SELinux state should be set to <tt><sub 
idref="var_selinux_state_name"/></tt> at
(...)

Instead of the current:
(...)
<description>The SELinux state should be set to <tt>enforcing</tt> at
(...)

With the current approach, the rule description (possibly) won't match the 
profile and will mention misleading remediations.


Regards

--
Rui Pedro Bernardino
CTE2/Tecnologias e Desenvolvimento
PT Inovação


_______________________________________________
scap-security-guide mailing list
[email protected]
https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide

Reply via email to