Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-17417

SCAP Tests for dnf settings check that 'yum' rpm is installed

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • rhel-9.4
    • rhel-9.3.0
    • scap-security-guide
    • None
    • sst_security_compliance
    • ssg_security
    • 26
    • None
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Hide

      Manually uninstall `yum` and check that

      $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_clean_components_post_updating /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
      $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
      $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml

      are applicable (either fail or pass result)

      Show
      Manually uninstall `yum` and check that $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_clean_components_post_updating /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml are applicable (either fail or pass result)
    • Pass
    • None
    • None

      There are a few SCAP tests that check dnf settings (in /etc/dnf/dnf.conf) but before those checks are run, there is a check to ensure the 'yum' rpm is installed.  When dnf is installed, but yum is NOT installed these tests show the result 'Not Applicable', but they really are applicable as dnf is installed.

      I'm thinking specifically of the following:
      CCE-83463-0

      CCE-83457-2

      CCE-83458-0

      I'm seeing this on RHEL 9.3 

      scap-security-guide-0.1.69-2.el9.noarch.rpm

            jcerny@redhat.com Jan Cerny
            dsugar@tresys.com David Sugar
            Vojtech Polasek Vojtech Polasek
            Milan Lysonek Milan Lysonek
            Votes:
            0 Vote for this issue
            Watchers:
            9 Start watching this issue

              Created:
              Updated:
              Resolved: