RHEL8 scap content #6888
-
Hi, Forgive me if this belongs elsewhere, I have a question about rhel8 stig playbook that I downloaded from this project. How complete is it? Is it documented somewhere, as far as it's % complete for rhel8 stigs? I ran the playbook on a rhel8 machine, and the results were: 658 passed and 85 failed. Some of the fails were very simple to remediate, such as sshd_idle timeout. Are the failures due to the remediations not being present in the ssg-rhel8-ds.xml file? If this is not the correct place to post, please advise. thanks. |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 3 replies
-
Found my issue. Rookie mistake: The playbook failed on a task and stopped executing tasks. Then I found out why it failed. grub2-editenv -set failed because my grubenv file was not exactly 1024 bytes. You learn something new every day. |
Beta Was this translation helpful? Give feedback.
-
Hey, another rookie here trying to do the same. After running the playbook (I assume you're referring to https://github.com/RedHatOfficial/ansible-role-rhel8-stig, I run a Nesus scan using v1.5 of the DISA STIG and I get over 500 hits still. The playbook runs fine. I see it skipping a few tasks here and there (don't know why yet) but overall it completes just fine. No fails. |
Beta Was this translation helpful? Give feedback.
Found my issue. Rookie mistake: The playbook failed on a task and stopped executing tasks. Then I found out why it failed. grub2-editenv -set failed because my grubenv file was not exactly 1024 bytes. You learn something new every day.