Hi All, As promised, here is the OVAL content editor.
https://blogs.vmware.com/security/2016/07/vmware-releases-oval-content-editor-open-source-project.html Hope you find this useful. Thanks and regards, Pravin Goyal ________________________________ From: Pravin Goyal <[email protected]> Sent: Tuesday, May 24, 2016 4:24:52 AM To: [email protected] Subject: Re: SCAP editor Thanks everyone for the comments. You should see something soon. Expect: 1. Support for OVAL 5.11.1 - for Windows, Linux, Unix and Independent schema only 2. Create XCCDF 1.2 from OVAL 5.11.1 content 3. Sleek version - just OVAL creation, nothing more Timeframe: Approx 8-12 weeks from now, depending upon legal clearance etc. Source: Source files will be released License: GPL v3 Stay tuned! Thanks and regards, Pravin Goyal ________________________________________ From: [email protected] <[email protected]> on behalf of [email protected] <[email protected]> Sent: Monday, May 23, 2016 9:30 PM To: [email protected] Subject: Open-scap-list Digest, Vol 86, Issue 17 Send Open-scap-list mailing list submissions to [email protected] To subscribe or unsubscribe via the World Wide Web, visit https://www.redhat.com/mailman/listinfo/open-scap-list or, via email, send a message with subject or body 'help' to [email protected] You can reach the person managing the list at [email protected] When replying, please edit your Subject line so it is more specific than "Re: Contents of Open-scap-list digest..." Today's Topics: 1. OpenSCAP Error: Invalid type, value or format (Dragos Prisaca) 2. Re: SCAP editor (Shawn Wells) ---------------------------------------------------------------------- Message: 1 Date: Mon, 23 May 2016 10:59:46 -0400 From: Dragos Prisaca <[email protected]> To: [email protected] Subject: [Open-scap] OpenSCAP Error: Invalid type, value or format Message-ID: <[email protected]> Content-Type: text/plain; charset="utf-8" Hello, OpenSCAP 1.2.10 does not process correctly the following OVAL object: <rpminfo_object xmlns=" http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:nist.validation.linuxRpmInfo:obj:67" version="1"> <name datatype="string" operation="pattern match">^.+$</name> <filter xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" action="include">oval:nist.validation.linuxRpmInfo:ste:67</filter> </rpminfo_object> where the ste:67 is defined as: <rpminfo_state xmlns=" http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:nist.validation.linuxRpmInfo:ste:67" version="1"> <signature_keyid datatype="string" operation="pattern match">^[15].+$</signature_keyid> </rpminfo_state> OpenSCAP output: ?OpenSCAP Error: Probe at sd=1 (rpminfo) reported an error: Invalid type, value or format [oval_probe_ext.c:393] Unable to receive a message from probe [oval_probe_ext.c:579] Invalid oval result type: -1. [oval_resultTest.c:179]?? Please let me know if you need a copy of the content and I?ll send it directly to you. Respectfully, _Dragos. -------------- next part -------------- An HTML attachment was scrubbed... URL: <https://www.redhat.com/archives/open-scap-list/attachments/20160523/80ada0c0/attachment.html> ------------------------------ Message: 2 Date: Mon, 23 May 2016 11:15:59 -0400 From: Shawn Wells <[email protected]> To: [email protected] Subject: Re: [Open-scap] SCAP editor Message-ID: <[email protected]> Content-Type: text/plain; charset="windows-1252"; Format="flowed" On 5/23/16 1:05 AM, Pravin Goyal wrote: > > Hi All, > > Drawing your attention towards http://www.g2-inc.com/escape. > > > Do we have a fair number of people who are using this (or wanted to > use this but put it down since it is not kept up to date)? > > > I am trying to refresh the tool: > > 1. Add support for OVAL 5.11.1 - for Windows, Linux, Unix and > Independent schemas only > 2. Add support for creating XCCDF 1.2 from OVAL 5.11.1 content (No > XCCDF development support as such. Just take OVAL as input and xsl > transform it into XCCDF 1.2) > 3. Strip down all other broken capabilities and schema versions (such > as OVAL 5.3 etc.) > > To me, #1 is the most important thing and is most widely used. Is > there anything else that I should look at? > > Please let me know your comments. - Adding a feature akin to the SSG testcheck.py scripts. If writing a singular OVAL check, it'd be great to compile that into proper SCAP 1.2 compliant file and run it. - Auto completion of OVAL definitions (ind:filepath, testcheck...) -- Shawn Wells Chief Security Strategist U.S. Public Sector [email protected] | 443.534.0130 -------------- next part -------------- An HTML attachment was scrubbed... URL: <https://www.redhat.com/archives/open-scap-list/attachments/20160523/5536fc02/attachment.html> ------------------------------ _______________________________________________ Open-scap-list mailing list [email protected] https://www.redhat.com/mailman/listinfo/open-scap-list End of Open-scap-list Digest, Vol 86, Issue 17 **********************************************
_______________________________________________ Open-scap-list mailing list [email protected] https://www.redhat.com/mailman/listinfo/open-scap-list
