Re: [Open-scap] Questions about integration of other Linux distributions analysis

2016-04-15 Thread Philippe Thierry
Hello, There is a begining of a Debian integration in the scap-security-guide, but not yet complete (don't have much time for me these last weeks). Yet you can use it on Debian 8. Nevertheless, if you which to make openscap debian package support services check you need to patch the official De

[Open-scap] Questions about integration of other Linux distributions analysis

2016-04-15 Thread jeremy.rakotoarisoa
Hello, Today, we are working on the integration of a PaaS solution which uses Docker containers in order to deploy application. As a result, we have to ensure that these containers and images they are coming from are not concerned by some vulnerabilities with the packages installed on our conta

Re: [Open-scap] Offline scanning - SCE, probes

2016-04-15 Thread Jan Cerny
Hi Iankko, - Original Message - > From: "Jan Lieskovsky" > To: "Zbynek Moravec" > Cc: open-scap-list@redhat.com > Sent: Friday, April 15, 2016 1:26:09 PM > Subject: Re: [Open-scap] Offline scanning - SCE, probes > > > Hello Zbynek, > > - Original Message - > > From: "Zbynek Mo

Re: [Open-scap] Offline scanning - SCE, probes

2016-04-15 Thread Jan Lieskovsky
Hello Zbynek, - Original Message - > From: "Zbynek Moravec" > To: open-scap-list@redhat.com > Sent: Wednesday, April 13, 2016 11:47:51 PM > Subject: [Open-scap] Offline scanning - SCE, probes > > Hi > > We plan to implement offline scan support for SCE scripts. I would like to > ask >

Re: [Open-scap] Offline scanning - SCE, probes

2016-04-15 Thread Zbynek Moravec
Ok, to perform offline SCE scan we can use these ways: A) add wrapper script script what contains original script but do chroot - maybe easy for bash, python, "impossible" for binaries - but they aren't really used - not universal solution B) fexecve(int fd, char *const argv[], char *const e