Re: Update openscap-daemon
Hello Raphaël,
I took a look on the bug. The problem is that there is no more
cpe-oval.xml file in libopenscap8.
The /usr/share/openscap/cpe/ dir is empty, only keeping a README
explaining the following:
--------------[snip]------------------
This folder contains the default CPE dictionary and its associated OVAL
file.
The CPE names inside are taken from official CPE dictionary found at
https://nvd.nist.gov/cpe.cfm with the following exceptions:
1) cpe:/o:redhat:enterprise_linux:6 (adapted from RHEL5 CPE name)
2) cpe:/o:fedoraproject:fedora:16 (taken from CPE_NAME in
/etc/os-release on F16)
3) cpe:/o:fedoraproject:fedora:17 (taken from CPE_NAME in
/etc/os-release on F17)
--------------[snip]------------------
I dunno what is the best way to correct this, as openscap-daemon does
not host a default CPE file in its sources. I'll discuss a little with
Pierre if there is a way to get back a CPE file from libopenscap8 or
not.
The other way is to update the README.Debian in order to get back an
official CPE XML file from the NIST website.
The last way would be to require scap-security-guide (at least ssg-core
and one of others binary packages) to get back cpe files, but I'm not
fan of that last possibility as there is not always a real reason to
deploy this package on the computer/VM/container hosting oscapd.
Pierre : Can you confirm that there is no more CPE oval file distributed
with libopenscap in any way ?
Cheers,
On 2018-04-26 23:13, Raphael Hertzog wrote:
Hello Philippe,
I have prepared an update of the package in the git repository to fix
the
RC bug and to switch to a new upstream release. But I noticed at the
same time
that the autopkgtests are not working currently.
I think the problem boils down to a bad default configuration:
Apr 26 20:57:57 debian oscapd[2615]: RuntimeError: Path
'/usr/share/openscap/cpe/openscap-cpe-oval.xml' given for the cpe-oval
file (config file entry: CPE OVAL) doesn't exist.
Can you look into fixing this so that we can release the updated
package?
Are you getting the bug reports on the package ? If not, please
subscribe to
it on https://tracker.debian.org/pkg/openscap-daemon
Thank you.
--
Philippe.
Reply to: