plus3it / plus3it/ash-linux-formula

[Feature Request] Update `oscap` logic to allow use of a tailoring XML in concert with standard remediation

Open
#446 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
SaltStack
Stars
19
Forks
17
PR merge metrics
No merged PRs in 30d

Description

Is your feature request related to a problem? Please describe.

The oscap content shipped as part to the overall watchmaker content contains more content than is executed in the default profile(s). It would improve hardening-flexibility to ensure that the oscap-invocations were written to be able to pass a site-specific tailoring file.

Describe the solution you'd like

Change oscap methods so that, instead of using just the relevant profile's default content, they include reference to tailoring-content …then make that tailoring-content null.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the oscap methods and their current profile-only invocations in this Salt formula, then review the linked tailoring-file guidance. Define how a site-specific tailoring XML is passed alongside standard remediation and how a null tailoring value behaves; done means the oscap invocations support both cases.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
operating-systems, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.