Re: [Open-scap] Not able to make SCE script working

2018-04-25 Thread Šimon Lukašík
On 04/25/2018 02:10 PM, Raymond Mercier wrote: > Yes, because scap_1402.sh is an external script in the same folder as > ds.xml file. I (badly) supposed that oscap program would directly call > the external file but this is not the case. > I think when you pick the XCCDF file and run oscap d

Re: [Open-scap] Not able to make SCE script working

2018-04-25 Thread Raymond Mercier
Yes, because scap_1402.sh is an external script in the same folder as ds.xml file. I (badly) supposed that oscap program would directly call the external file but this is not the case. How can I pack my script in ds.xml file, is there some resource than can explain ? 2018-04-25 14:05 GMT+02:00 Ši

Re: [Open-scap] Not able to make SCE script working

2018-04-25 Thread Šimon Lukašík
On 04/25/2018 10:24 AM, Raymond Mercier wrote: > Hi Simon > > I updated, the error message is different (but still present) > > xml file: >     severity="medium"> >    selinux >    Checks if you have SELinux > enabled >   http://open-scap.org/page/

Re: [Open-scap] Not able to make SCE script working

2018-04-25 Thread Raymond Mercier
Hi Simon I updated, the error message is different (but still present) xml file: selinux Checks if you have SELinux enabled http://open-scap.org/page/SCE";> ou

Re: [Open-scap] Not able to make SCE script working

2018-04-25 Thread Šimon Lukašík
On 04/25/2018 09:47 AM, Raymond Mercier wrote: > severity="medium"> > selinux > Checks if you have > SELinux enabled > system="http://wordpress-www-open-scap-or

[Open-scap] Not able to make SCE script working

2018-04-25 Thread Raymond Mercier
Hi all, I'm trying to use SCE script in openscap ds file and all I get is "notchecked" status my ds file is attached The command I start is: [root]# oscap xccdf eval --profile xccdf_1_profile_1 rm-ds.xml the result I get is: Title selinux Rulexccdf_1_rule_1402 Result notchecked I think

Re: [Open-scap] [Suspected Spam] Re: OSCAP Scanner Binaries

2018-04-25 Thread Šimon Lukašík
On 04/24/2018 07:12 PM, Mohanraj, Bharath wrote: > Thanks for the info… > >   > > The first thing I want to avoid is my enduser machines hitting the > internet for downloading packages… So, I prefer having them as RPM files > locally and trigger installation of the same… But, in case the RPM > in