[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Update openscap-daemon



Hello Raphaël,

I took a look on the bug. The problem is that there is no more cpe-oval.xml file in libopenscap8. The /usr/share/openscap/cpe/ dir is empty, only keeping a README explaining the following:

--------------[snip]------------------
This folder contains the default CPE dictionary and its associated OVAL file.

The CPE names inside are taken from official CPE dictionary found at
https://nvd.nist.gov/cpe.cfm with the following exceptions:

1) cpe:/o:redhat:enterprise_linux:6 (adapted from RHEL5 CPE name)
2) cpe:/o:fedoraproject:fedora:16 (taken from CPE_NAME in /etc/os-release on F16) 3) cpe:/o:fedoraproject:fedora:17 (taken from CPE_NAME in /etc/os-release on F17)
--------------[snip]------------------

I dunno what is the best way to correct this, as openscap-daemon does not host a default CPE file in its sources. I'll discuss a little with Pierre if there is a way to get back a CPE file from libopenscap8 or not. The other way is to update the README.Debian in order to get back an official CPE XML file from the NIST website. The last way would be to require scap-security-guide (at least ssg-core and one of others binary packages) to get back cpe files, but I'm not fan of that last possibility as there is not always a real reason to deploy this package on the computer/VM/container hosting oscapd.

Pierre : Can you confirm that there is no more CPE oval file distributed with libopenscap in any way ?

Cheers,

On 2018-04-26 23:13, Raphael Hertzog wrote:
Hello Philippe,

I have prepared an update of the package in the git repository to fix the RC bug and to switch to a new upstream release. But I noticed at the same time
that the autopkgtests are not working currently.

I think the problem boils down to a bad default configuration:
Apr 26 20:57:57 debian oscapd[2615]: RuntimeError: Path
'/usr/share/openscap/cpe/openscap-cpe-oval.xml' given for the cpe-oval
file (config file entry: CPE OVAL) doesn't exist.

Can you look into fixing this so that we can release the updated package?

Are you getting the bug reports on the package ? If not, please subscribe to
it on https://tracker.debian.org/pkg/openscap-daemon

Thank you.

--
Philippe.



Reply to: