content icon indicating copy to clipboard operation
content copied to clipboard

Security automation content in SCAP, Bash, Ansible, and other formats

Results 630 content issues
Sort by recently updated
recently updated
newest added

During the build of bootable container images we can't use OVAL check in rules from the socket_disabled template because the OVAL tests depend on dbus which isn't available in that...

Image Mode

#### Description: - _Fix inventory_test_kernel_installed for SLE_ #### Rationale: - _The SLE package is kernel-default_

needs-ok-to-test

This PR introduces support for new remediation type "bootc". Remediations of this type will be generated only internally by the future `oscap-bootc` script. They aren't supposed to be generated by...

Infrastructure
Image Mode

#### Description of problem: Automatus tests fail with "Environment failed to prepare" when rules, which are not applicable to containers (e.g. platform is machine,system_with_kernel,systemd,...), are tested in a container environment,...

triaged

#### Description of problem: The regex's for `oval:ssg-apt_sources_list_official:def:1` do not support [DEB822 format](https://manpages.debian.org/bookworm/dpkg-dev/deb822.5.en.html) and therefore return a false positive. ``` ^/etc/apt/sources(.d\/[a-zA-Z0-9]+){0,1}.list$ ^deb[\s]+http://[a-z\.]+\.debian\.org/debian[/]?[\s]+bookworm[\s]+main 1 ^/etc/apt/sources(.d\/[a-zA-Z0-9]+){0,1}.list$ ^deb[\s]+http://security\.debian\.org/debian-security[/]?[\s]+bookworm-security[\s]+main 1 ``` #### SCAP Security...

Debian
Ubuntu

#### Description of problem: Trying to understand why the 'ssg-debderived' package contains configurations up to 22.04, but not for 24.04 (a.k.a. Noble), even though it's been out for six months...

Ubuntu

#### Description: - Add rules to support remote offload of journal logs to Slmicro5 STIG #### Rationale: - Add rules and remediations to configure remote url, tls certificate and key...

Ansible
Bash
SLES
needs-rebase
Update Template

#### Description of problem: Remediating ie. `stig` using OSBuild (Image Builder) via an oscap-generated Blueprint, which contains ``` [customizations.openscap] profile_id = "xccdf_org.ssgproject.content_profile_stig" ... ``` on a Secure Boot (UEFI) virtual...

RHEL
RHEL9
RHEL8
osbuild
RHEL10

#### Description: - Load all the profile if not loaded for Ubuntu without change the mode of loaded profiles #### Rationale: - We change the default mode to enforce for...

Ubuntu
needs-ok-to-test

#### Description: - Check whether all the profiles already parsed and loaded into the kernel #### Rationale: - Make sure the apparmor is aware of all the profiles under /etc/apparmor.d/...

Ubuntu
needs-ok-to-test