From Openscap
[edit]
Download
[edit]
Current Release: 0.8.0 (Oct 11, 2011)
- added an OVAL Directives schema to allow for a tool to supply a set of directives to more easily specify desired results content.
- enhanced OVAL Results directives to allow for more flexibility in allowed results content
- added new OVAL objects(all OVAL 5.8 objects are covered now)
- updated dpkgprobe
- improved directory traversal algorithm
- all issues reported by coverity are fixed
- added capability to export OVAL Variables from XCCDF
- added cvss score calculator from vector
A tarball is available at http://www.open-scap.org/download/openscap-0.8.0.tar.gz
SHA1 checksum: 826df8826e38e0eb3d5cbed57662577101897061
[edit]
Fedora
OpenSCAP is available on Fedora repositories. To install the library, oscap tool and SCAP content run:
#yum install openscap openscap-utils openscap-content
[edit]
Source Repository
The source repository for OpenSCAP is stored in git. Clone the repository by
$git clone git://git.fedorahosted.org/git/openscap.git
[edit]
SCAP Content
[edit]
Official
- The United States Government Configuration Baseline (USGCB): http://usgcb.nist.gov/usgcb/rhel/download_rhel5.html
- Red Hat patch definitions for security updates: http://www.redhat.com/security/data/oval/
- National Checklist Program Repository: http://web.nvd.nist.gov/view/ncp/repository
- aqueduct: https://fedorahosted.org/aqueduct/
- scap-security-guide: https://fedorahosted.org/scap-security-guide/
[edit]
Testing
- Red Hat Enterprise Linux 6.2 OpenSCAP repository
- Fedora Content OpenSCAP repository
