[prev in list] [next in list] [prev in thread] [next in thread] 

List:       scap-security-guide
Subject:    /root/openscap_data
From:       Mike Johnston <mijohnst () gmail ! com>
Date:       2019-03-28 15:49:24
Message-ID: CAAEih=q6WL0+eZ7Lfkd9zaVzN_s4xjbASGKcT5pfTHPFHHLDqQ () mail ! gmail ! com
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


I'm a new to this project and have always done my SCAP lock downs with
kickstart scripts up until now.  This looks to be something I switched to a
long time ago.

In the environment I work in, I need to make custom ISO installation disks
to send out to the field. I've been testing out the 'addon
xccdf_org.ssgproject.content_profile_stig-rhel7-disa' security profile and
then made a custom tailored XML following the guidelines keep a few things
on that were being removed.  My problem is that now that I have my
'ssg-rhel7-ds-tailoring.xml' file, where do I put it in my kickstart
image?  I've tried copying it in the post -nochroot section of my kickstart
to  /tmp/openscap_data and /root/openscap_data and neither of those
worked.

Can someone tell me or show me where in the guide it show where it's
supposed to go?

This is what my kickstart looks like:

-------------------------------------
%post --nochroot
cp /run/install/repo/hardening/ssg-rhel7-ds-tailoring.xml
/root/openscap_data/


%addon org_fedora_oscap
    content-type = scap-security-guide
    profile=xccdf_org.ssgproject.content_profile_stig-rhel7-disa
    tailoring-path=ssg-rhel7-ds-tailoring.xml
%end
-------------------------------------


Thanks for all the work...this is a great project.

[Attachment #5 (text/html)]

<div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div \
dir="ltr"><div dir="ltr"><div dir="ltr">I&#39;m a new to this project and have always \
done my SCAP lock downs with kickstart scripts up until now.   This looks to be \
something I switched to a long time ago.   <br></div><div dir="ltr"><br></div><div \
dir="ltr">In the environment I work in, I need to make custom ISO installation disks \
to send out to the field. I&#39;ve been testing out the &#39;addon \
xccdf_org.ssgproject.content_profile_stig-rhel7-disa&#39; security profile and then \
made a custom tailored XML following the guidelines keep a few things on that were \
being removed.   My problem is that now that I have my \
&#39;ssg-rhel7-ds-tailoring.xml&#39; file, where do I put it in my kickstart image?   \
I&#39;ve tried copying it in the post -nochroot section of my kickstart to   \
/tmp/openscap_data and /root/openscap_data and neither of those worked.   \
<br></div><div dir="ltr"><br></div><div dir="ltr">Can someone tell me or show me \
where in the guide it show where it&#39;s supposed to go?</div><div \
dir="ltr"><br></div><div>This is what my kickstart looks \
like:</div><div><br></div><div>-------------------------------------</div><div>%post \
--nochroot</div><div>cp /run/install/repo/hardening/ssg-rhel7-ds-tailoring.xml \
/root/openscap_data/<br></div><div><br></div><div><br></div><div>%addon \
org_fedora_oscap<br>       content-type = scap-security-guide<br>       \
profile=xccdf_org.ssgproject.content_profile_stig-rhel7-disa <br>       \
                tailoring-path=ssg-rhel7-ds-tailoring.xml <br>%end <br>
-------------------------------------

<br><br></div><div dir="ltr"><br></div><div>Thanks for all the work...this is a great \
project.<br></div></div></div></div></div></div></div></div>


[Attachment #6 (text/plain)]

_______________________________________________
scap-security-guide mailing list -- scap-security-guide@lists.fedorahosted.org
To unsubscribe send an email to scap-security-guide-leave@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedorahosted.org/archives/list/scap-security-guide@lists.fedorahosted.org


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic