Re: [Open-scap] [EXTERNAL] Open-scap-list Digest, Vol 124, Issue 1

2019-08-08 Thread Greg Silverman
eplying, please edit your Subject line so it is more specific than "Re: Contents of Open-scap-list digest..." Today's Topics: 1. timing rule evaluation times (Greg Silverman) 2. Re: timing rule evaluation times (Shawn Wells) 3. R

[Open-scap] timing rule evaluation times

2019-08-07 Thread Greg Silverman
Is there any way within oscap to record the time taken for each rule's evaluation to complete? We sometimes see it taking over an hour to complete on RHEL7 and want to understand why. Greg Silverman Principal Engineer Veritas Technologies Santa Clar

[Open-scap] Using profiles not distributed in

2019-02-08 Thread Greg Silverman
ndows-1252"; Format="flowed" On 2/6/19 1:11 PM, Greg Silverman wrote: > > We want to use the DISA STIG for RHEL 7 V2R2 profile. The latest > scap-security-guide RPM has V1R4. How is a profile xml file consumed > by oscap? > Most use cases are covered in the RHEL

[Open-scap] Using profiles not distributed in scap-security-guide

2019-02-06 Thread Greg Silverman
We want to use the DISA STIG for RHEL 7 V2R2 profile. The latest scap-security-guide RPM has V1R4. How is a profile xml file consumed by oscap? Greg Silverman ___ Open-scap-list mailing list Open-scap-list@redhat.com https://www.redhat.com/mailman

[Open-scap] profile versions

2019-01-23 Thread Greg Silverman
those available? Greg Silverman ___ Open-scap-list mailing list Open-scap-list@redhat.com https://www.redhat.com/mailman/listinfo/open-scap-list

[Open-scap] CCE-27309-4, xccdf_org.ssgproject.content_rule_bootloader_password for RHEL 7 question

2018-03-05 Thread Greg Silverman
://github.com/OpenSCAP/scap-security-guide/pull/2619/files that there is a change related to checking user.cfg. I cannot quite tell what it is doing. Is it saying that checking the user.cfg file is sufficient? Thanks, Greg Silverman Veritas Technologies Mountain View, CA

[Open-scap] pass/fail/error

2017-07-17 Thread Greg Silverman (CS)
What does "error" mean for a rule result in the scanner? Is it an error in the scanner? Greg Silverman (CS) Veritas Technologies Mountain View, CA ___ Open-scap-list mailing list Open-scap-list@redhat.com https://www.redhat.com/mailman/lis

[Open-scap] OpenSCAP Evaluation Report summary

2017-07-17 Thread Greg Silverman (CS)
= 225 evaluated. But, 112/225 = 50% passed. Why does the scanner give a score of 64.56%? Is it a weighted average? What is the formula? Thanks, Greg Silverman Veritas Technologies Mountain View, CA ___ Open-scap-list mailing list Open-scap-list

[Open-scap] the sed_command idiom

2017-04-19 Thread Greg Silverman (CS)
As an alternative, I change the script to say sed_command_params="sed -I ..." sed ${command_params} This works. It seems more reasonable to me because we do not want a different command, we want different parameters to the sed command. Gr

Re: [Open-scap] please explain this

2017-04-12 Thread Greg Silverman (CS)
x27; to open-scap-list-requ...@redhat.com You can reach the person managing the list at open-scap-list-ow...@redhat.com When replying, please edit your Subject line so it is more specific than "Re: Contents of Open-scap-list digest..." Today's Topics:

Re: [Open-scap] Pleas explain this (Shawn Wells)

2017-04-12 Thread Greg Silverman (CS)
to open-scap-list-requ...@redhat.com You can reach the person managing the list at open-scap-list-ow...@redhat.com When replying, please edit your Subject line so it is more specific than "Re: Contents of Open-scap-list digest..." Today's Topics: 1. Pleas expla

[Open-scap] Pleas explain this

2017-04-12 Thread Greg Silverman (CS)
Many of the generated fixes uses this idiom IFS=$'\n' ... unset $IFS IFS is a variable, but, $IFS is a character string, so, unsetting it does not restore IFS to its default value. What am I missing? Thanks, Greg Silverman Mountain View, Ca __

[Open-scap] customizing generation of mediation scripts

2017-03-21 Thread Greg Silverman (CS)
script. 2. Where can I add bash code to fix items that are not currently fixed? (I realize that some future release may replace changes I make now.) Greg Silverman Veritas Technologies Mountain View, CA ___ Open-scap-list mailing list Open-scap-list@

Re: [Open-scap] Open-scap-list Digest, Vol 96, Issue 11

2017-03-20 Thread Greg Silverman (CS)
AA to fetch that DS file remotely (this might be actually easier option that modifying the %post section). > > ___ > Open-scap-list mailing list > Open-scap-list@redhat.com > https://www.redhat.com/mailman/listinfo/open-scap-list > HTH

Re: [Open-scap] Open-scap-list Digest, Vol 96, Issue 8

2017-03-17 Thread Greg Silverman (CS)
open-scap-list-requ...@redhat.com You can reach the person managing the list at open-scap-list-ow...@redhat.com When replying, please edit your Subject line so it is more specific than "Re: Contents of Open-scap-list digest..." Today's Topics

[Open-scap] customizing remediation

2017-03-16 Thread Greg Silverman (CS)
--output my-remediation-script.sh /usr/share/xml/scap/ssg/content/ssg-rhel7-ds-tailoring.xml i.e., using the tailored xccdf file. What am I missing? Thanks, Greg Silverman Veritas Technologies ___ Open-scap-list mailing list Open-scap-list@redhat.com https