Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-17417

SCAP Tests for dnf settings check that 'yum' rpm is installed

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • rhel-9.4
    • rhel-9.3.0
    • scap-security-guide
    • None
    • None
    • None
    • rhel-sst-security-compliance
    • ssg_security
    • 26
    • None
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Hide

      Manually uninstall `yum` and check that

      $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_clean_components_post_updating /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
      $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
      $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml

      are applicable (either fail or pass result)

      Show
      Manually uninstall `yum` and check that $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_clean_components_post_updating /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml $ oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml are applicable (either fail or pass result)
    • Pass
    • None
    • None

      There are a few SCAP tests that check dnf settings (in /etc/dnf/dnf.conf) but before those checks are run, there is a check to ensure the 'yum' rpm is installed.  When dnf is installed, but yum is NOT installed these tests show the result 'Not Applicable', but they really are applicable as dnf is installed.

      I'm thinking specifically of the following:
      CCE-83463-0

      CCE-83457-2

      CCE-83458-0

      I'm seeing this on RHEL 9.3 

      scap-security-guide-0.1.69-2.el9.noarch.rpm

              jcerny@redhat.com Jan Cerny
              dsugar@tresys.com David Sugar (Inactive)
              Vojtech Polasek Vojtech Polasek
              Milan Lysonek Milan Lysonek
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: