Questions tagged [openscap]

Open source suite of SCAP tools

http://www.open-scap.org/page/Main_Page

SCAP is a line of standards managed by NIST. It was created to provide a standardized approach to maintaining the security of enterprise systems, such as automatically verifying the presence of patches, checking system security configuration settings, and examining systems for signs of compromise.

The SCAP suite contains multiple complex data exchange formats that are to be used to transmit important vulnerability, configuration, and other security data. Historically, there have been few tools that provide a way to query this data in the needed format. This lack of tools makes the barrier to entry very high and discourages adoption of these protocols by the community. It's our goal to create a framework of libraries and tools to improve the accessibility of SCAP and enhance the usability of the information it represents.

49 questions
0
votes
1 answer

remediation script for centos 7 throws syntax errors

thanks in advance. i am running a fresh download of openscap on centos7 (patched). it produces a remediation script, but the script throws an error repeatedly. its the same syntax issue many times in the script ./x.sh: line 107: syntax error near…
Tony
  • 3
  • 1
0
votes
1 answer

SCAP - Workbench on MAC (with Remote Machine option) - Failed to create SSH master socket

I'm running latest workbench: SCAP Workbench 1.2.1, compiled with Qt 5.13.2, using OpenSCAP 1.4.0 I can't run a scan on remote server using RHEL7 (DISA STIG profile - or any profile) because of a socket error ... anyone else have this issue? Can't…
-1
votes
1 answer

False positives when scanning CentOS7 with OpenSCAP

I just installed OpenSCAP Benchmark scanner on a CentOS7 box I had stigged by hand. There are a huge number of false positives showing up and I'm not sure if it's a bug or somehow it's not remediated when it should be. I followed the STIGs from…
Jean
  • 1
-1
votes
1 answer

Why Openshift 3 is missing from openscap static page?

I am trying to access https://static.open-scap.org/ssg-guides/ssg-ocp3-guide-index.html to understand some of the issues found in a scan but seems that this webpage is now missing. Anybody does know why? Is there any archive?
Tito
  • 101
  • 2
1 2 3
4