Uploaded image for project: 'RHEL Documentation'
  1. RHEL Documentation
  2. RHELDOCS-20871

[No documentation available]

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • None
    • rhel-10.0
    • Documentation
    • None
    • None
    • None
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified

      Document link: No official document available

      Describe the issue:

      A customer is looking for guidance on how to use VEX files with OpenSCAP in RHEL 10. Specifically, they want to know what command or workflow should replace

      /usr/bin/oscap oval eval --report ...

       given the deprecation of OVAL v2.

      References:

      Blog: https://www.redhat.com/en/blog/red-hat-vex-files-cves-are-now-generally-available 
      Announcement: https://access.redhat.com/security/oval-v2-deprecation-announcement 

      Gap in documentation:
      I did not find any mention in the RHEL 10 product documentation about OVAL v2 deprecation, nor are there steps explaining how to consume or use VEX files with OpenSCAP.

      Impact:
      Customers do not have documented steps to follow, which causes confusion when transitioning from OVAL to VEX in RHEL 10.

       

              rhel-docs RHEL Docs
              rhn-support-prjagtap Pradeep Jagtap
              Archiver:
              tcapek1@redhat.com Tomas Capek

                Created:
                Updated:
                Resolved:
                Archived: