Uploaded image for project: 'RHEL Documentation'
  1. RHEL Documentation
  2. RHELDOCS-20877

Missing documentation on using VEX files with OpenSCAP in RHEL 10 after OVAL v2 deprecation

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • rhel-10.0
    • Documentation
    • None
    • None
    • None
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified

      Document link:No official document available

      Section number and name:NA

      Describe the issue:

      A customer is looking for guidance on how to use VEX files with OpenSCAP in RHEL 10. Specifically, they want to know what command or workflow should replace

      /usr/bin/oscap oval eval --report ...

       given the deprecation of OVAL v2.

      References:

      Blog: https://www.redhat.com/en/blog/red-hat-vex-files-cves-are-now-generally-available 
      Announcement: https://access.redhat.com/security/oval-v2-deprecation-announcement 

       

      Impact of this issue:

      Customers do not have documented steps to follow, which causes confusion when transitioning from OVAL to VEX in RHEL 10.

      Suggestions for improvement:

      I did not find any mention in the RHEL 10 product documentation about OVAL v2 deprecation, nor are there steps explaining how to consume or use VEX files with OpenSCAP.

              rhel-docs RHEL Docs
              rhn-support-prjagtap Pradeep Jagtap
              Archiver:
              tcapek1@redhat.com Tomas Capek

                Created:
                Updated:
                Resolved:
                Archived: