Yes, I enabled Debian testing on Jessie to install 
libopenscap8 release 1.2.9-1.

I have not tried other scans. Which would you recommend? Thanks


--Luther

On Thursday, April 27, 2017 6:50 PM, Philippe Thierry <p...@reseau-libre.net> 
wrote:



Hi,

I've seen a same type of error with SSG 0.1.32 when using OpenSCAP 
release 1.0.9 (Debian Jessie release). That's why by now the ssg package 
for Debian is still using 0.1.31 - same message but whithout the 
SIGSEGV). I've never seen this bug with 1.2.x version of OpenSCAP.

What is strange is the fact that the second scan just works fine. The 
two executions are normally independantly executed, without any 
interactions.

You precised that the target uses libopenscap8 release 1.2.9-1, which 
means that you backported the Stretch release on Jessie ?

Have you tried other scans to check if there is no more bug or if it 
happends heratically ?



Le 27/04/2017 à 12:23, Luther Goh Lu Feng a écrit :
> Running a from a debian scanner, to scan a debian target using openscap-ssh, 
> first time scan results in the error below.
>
> Command is:
> ssh -t debian@192.168.0.1 "~/oscap-ssh/oscap-ssh root@192.168.0.2 22  xccdf 
> eval --fetch-remote-resources --results ~/scan/debian-xccdf-results.xml 
> --report ~/scan/debian-xccdf-results.html --profile 
> xccdf_org.ssgproject.content_profile_common 
> /usr/share/ssg/ssg-debian8-ds.xml";
>
> Scanner libaries:
> libopenscap8                         1.2.9-1+b2
> ssg-debian                           0.1.31-3
>
>
> Target libraries:
> libopenscap8                         1.2.9-1+b2
>
> Second scan results in no error. Is this a known bug or is there a 
> misconfiguration somewhere?
>
>
> ===============
> OpenSCAP Error: Probe with PID=6497 has been killed with signal 11 
> [../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
> Item corresponding to object 'oval:ssg-obj_package_rsyslog_installed:obj:1' 
> from test 'oval:ssg-test_package_rsyslog_installed:tst:1' has an unknown 
> flag. This may indicate a bug in OpenSCAP. 
> [../../../../src/OVAL/results/oval_resultTest.c:908]
> Probe with PID=6509 has been killed with signal 11 
> [../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
> Item corresponding to object 'oval:ssg-obj_package_telnetd_removed:obj:1' 
> from test 'oval:ssg-test_package_telnetd_removed:tst:1' has an unknown flag. 
> This may indicate a bug in OpenSCAP. 
> [../../../../src/OVAL/results/oval_resultTest.c:908]
> Probe with PID=6515 has been killed with signal 11 
> [../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
> Item corresponding to object 
> 'oval:ssg-obj_package_inetutils-telnetd_removed:obj:1' from test 
> 'oval:ssg-test_package_inetutils-telnetd_removed:tst:1' has an unknown flag. 
> This may indicate a bug in OpenSCAP. 
> [../../../../src/OVAL/results/oval_resultTest.c:908]
> Probe with PID=6523 has been killed with signal 11 
> [../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
> Item corresponding to object 'oval:ssg-obj_package_telnetd-ssl_removed:obj:1' 
> from test 'oval:ssg-test_package_telnetd-ssl_removed:tst:1' has an unknown 
> flag. This may indicate a bug in OpenSCAP. 
> [../../../../src/OVAL/results/oval_resultTest.c:908]
> Probe with PID=6529 has been killed with signal 11 
> [../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
> Item corresponding to object 'oval:ssg-obj_package_nis_removed:obj:1' from 
> test 'oval:ssg-test_package_nis_removed:tst:1' has an unknown flag. This may 
> indicate a bug in OpenSCAP. 
> [../../../../src/OVAL/results/oval_resultTest.c:908]
> Probe with PID=6535 has been killed with signal 11 
> [../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
> Item corresponding to object 'oval:ssg-obj_package_ntpdate_removed:obj:1' 
> from test 'oval:ssg-test_package_ntpdate_removed:tst:1' has an unknown flag. 
> This may indicate a bug in OpenSCAP. 
> [../../../../src/OVAL/results/oval_resultTest.c:908]
> Probe with PID=6541 has been killed with signal 11 
> [../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
> Item corresponding to object 'oval:ssg-obj_package_auditd_installed:obj:1' 
> from test 'oval:ssg-test_package_auditd_installed:tst:1' has an unknown flag. 
> This may indicate a bug in OpenSCAP. 
> [../../../../src/OVAL/results/oval_resultTest.c:908]
> Probe with PID=6547 has been killed with signal 11 
> [../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
> Item corresponding to object 'oval:ssg-obj_package_cron_installed:obj:1' from 
> test 'oval:ssg-test_package_cron_installed:tst:1' has an unknown flag. This 
> may indicate a bug in OpenSCAP. 
> [../../../../src/OVAL/results/oval_resultTest.c:908]
> Probe with PID=6553 has been killed with signal 11 
> [../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
> Item corresponding to object 'oval:ssg-obj_package_ntp_installed:obj:1' from 
> test 'oval:ssg-test_package_ntp_installed:tst:1' has an unknown flag. This 
> may indicate a bug in OpenSCAP. 
> [../../../../src/OVAL/results/oval_resultTest.c:908]
> Probe with PID=6559 has been killed with signal 11 
> [../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
> Item corresponding to object 
> 'oval:ssg-obj_package_openssh-server_removed:obj:1' from test 
> 'oval:ssg-test_package_openssh-server_removed:tst:1' has an unknown flag. 
> This may indicate a bug in OpenSCAP. 
> [../../../../src/OVAL/results/oval_resultTest.c:908]
> Result  pass
>
> oscap exit code: 2
>
> _______________________________________________
> Open-scap-list mailing list
> Open-scap-list@redhat.com
> https://www.redhat.com/mailman/listinfo/open-scap-list

_______________________________________________
Open-scap-list mailing list
Open-scap-list@redhat.com
https://www.redhat.com/mailman/listinfo/open-scap-list

_______________________________________________
Open-scap-list mailing list
Open-scap-list@redhat.com
https://www.redhat.com/mailman/listinfo/open-scap-list

Reply via email to