Skip to content

crypto_policy_not_overridden is misaligned with DISA #14745

@ggbecker

Description

@ggbecker

The testing environment does not contain the openscap-engine-sce package therefore it doesn't check the rule that only contains SCE content.

If we install the package, the check would pass and would still be misaligned with DISA results because DISA's content checks for the symlinks which for the FIPS:STIG crypto policy does not work since subpolicy always copy the files to the config locations instead of symlinks.

9.8	fail	/scanning/disa-alignment/oscap	crypto_policy_not_overridden		SSG result: notchecked, DISA result(s): SV-258236r1101920_rule:fail
9.8	fail	/scanning/disa-alignment/anaconda	crypto_policy_not_overridden		SSG result: notchecked, DISA result(s): SV-258236r1101920_rule:fail
9.8	fail	/scanning/disa-alignment/ansible	crypto_policy_not_overridden		SSG result: notchecked, DISA result(s): SV-258236r1101920_rule:fail

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions