Uploaded image for project: 'RHEL Documentation'
  1. RHEL Documentation
  2. RHELDOCS-20894

Missing documentation on using VEX files with OpenSCAP in RHEL 10 after OVAL v2 deprecation

XMLWordPrintable

    • None
    • rhel-sst-ccs
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • CCS 2025-17, CCS 2025-18, CCS 2025-19
    • None
    • Unspecified
    • Unspecified
    • Unspecified

      Document link: No official document available

      Section number and name: NA

      Describe the issue:

      A customer is looking for guidance on how to use VEX files with OpenSCAP in RHEL 10. Specifically, they want to know what command or workflow should replace

      /usr/bin/oscap oval eval --report ...

       given the deprecation of OVAL v2.

      References:

      Blog: https://www.redhat.com/en/blog/red-hat-vex-files-cves-are-now-generally-available 
      Announcement: https://access.redhat.com/security/oval-v2-deprecation-announcement 

      Impact of this issue:

      Customers do not have documented steps to follow, which causes confusion when transitioning from OVAL to VEX in RHEL 10.

      Suggestions for improvement:

      I did not find any mention in the RHEL 10 product documentation about OVAL v2 deprecation, nor are there steps explaining how to consume or use VEX files with OpenSCAP.

       

       

              jafiala@redhat.com Jan Fiala
              rhn-support-prjagtap Pradeep Jagtap
              RHEL Docs RHEL Docs
              Votes:
              2 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: