You might want to try the FOS? If you are working under classified conditions (which probably shouldn’t' be in such a public setting), there should be a site that is approved to down load authorized sw for use in those types of environments.
Margaret -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Jackson, George C III CTR DISA PEO-MA (US) Sent: Tuesday, May 27, 2014 4:32 PM To: SCAP Security Guide Subject: RE: OpenSCAP Error: Conversion of the string "-" to an integer (64 bits) failed: Invalid argument [oval_cmp.c:113] Hi Shawn, Sure, I used the URL: https://git.fedorahosted.org/git/scap-security-guide.git Unfortunately, I cannot use git directly from the RHEL6 host I need this on to fedorahosted.org as we're a classified site and strict firewall/proxy rules won't allow me to. I can only use a browser on one unclassified Windows workstation (git not allowed) then transfer my downloads over manually :( Any other options for me to get the latest? Thanks, George Jackson Cluster Technical Lead Centaur Operations Northrop Grumman IS -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Shawn Wells Sent: Tuesday, May 27, 2014 4:02 PM To: [email protected] Subject: Re: OpenSCAP Error: Conversion of the string "-" to an integer (64 bits) failed: Invalid argument [oval_cmp.c:113] On 5/27/14, 4:54 PM, Jackson, George C III CTR DISA PEO-MA (US) wrote: > Simon, > > Actually it still doesn't work with the latest > scap-security-guide-0.5.0-InitialDraft.tar.gz I downloaded directly > from the git repo this morning. If I use the oscap from Red Hat's > openscap-1.0.8-1.el6_5.x86_64 with the cmd line of: > > oscap xccdf eval --profile stig-rhel6-server-upstream --results > hera101-results.xml --report hera101-report.html --cpe > /usr/share/xml/scap/ssg/content/ssg-rhel6-cpe-dictionary.xml > /usr/share/xml/scap/ssg/content/ssg-rhel6-xccdf.xml > > I still get: > > Profile "stig-rhel6-server-upstream" was not found. > > If I do the same with --profile stig-server or --profile server I get > output on a few checks but then error out with > > OpenSCAP Error: Selector ID(ensure_logrotate_activated) does not exist > in Benchmark. [xccdf_policy.c:1904] Selector > ID(service_postfix_enabled) does not exist in Benchmark. > [xccdf_policy.c:1904] > > So I went back to the oscap I compiled which didn't give any errors > but every check gave a "Result: notapplicable". I compiled with: > > ./configure --enable-cce --enable-sce > > so I still don't know what I'm doing wrong. Any ideas? The .tar.gz of SSG you mentioned is well over 18 months old. Mind sharing where you nabbed it (the link should probably be taken down)? Are you able to use the latest SSG RPM? Download instructions at: https://fedorahosted.org/scap-security-guide/wiki/downloads _______________________________________________ scap-security-guide mailing list [email protected] https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide _______________________________________________ scap-security-guide mailing list [email protected] https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide
