Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Convert current "JBossEAP5" benchmark into the form of common SSG product to simplify contributions and enhancements / updates #1046

Closed
iankko opened this issue Feb 19, 2016 · 2 comments
Labels
enhancement General enhancements to the project. Infrastructure Our content build system
Milestone

Comments

@iankko
Copy link

iankko commented Feb 19, 2016

We currently ship security checklist for the JBossEAP5 product in the form of final XCCDF and OVAL files:

The current form of JBossEAP5 benchmark is placing the following barrier WRT to open-source contributions model -- couple of final big (XCCDF, OVAL, OCIL ...) XML files don't allow cooperation on content development (due to many possible conflicts when providing patches). This results into state when SCAP content for JBossEAP5 is:

  • not used as much as it could be,
  • getting more and more outdated due to missing content updates,
  • not suitable for more recent versions of the JBossEAP / WildFly products.

Therefore -- we need:

  • split those standalone XCCDF, OVAL, and OCIL files into the tree structure, as seen by other SSG products.
@iankko iankko added help-wanted This PR/Issue needs help to go forward. BLOCKER Impediments to release, like failure to build content, or content built is out of standard's syntax Infrastructure Our content build system labels Feb 19, 2016
@iankko iankko added this to the 0.1.30 milestone Feb 19, 2016
redhatrises added a commit to redhatrises/scap-security-guide that referenced this issue Mar 4, 2016
redhatrises added a commit to redhatrises/scap-security-guide that referenced this issue Mar 16, 2016
- Add empty JBoss Fuse STIG profile
- Add guide.xml and guide.xslt
- Create new JBoss XCCDF content structure
- Break out groups into new xml files from ssg-fuse6-xccdf.xml

- Part of ComplianceAsCode#1046
redhatrises added a commit to redhatrises/scap-security-guide that referenced this issue Mar 23, 2016
- Add Makefile and build capability
- Add new 'common' and 'stig-amq-upstream' profiles
- Add transforms xslt
- Remove old files
- Add Application Server SRG to shared/references
- Part of ComplianceAsCode#1046
redhatrises added a commit to redhatrises/scap-security-guide that referenced this issue May 12, 2016
- Update Makefile to be able to build with regular OVAL and OVAL5.11
- Fix deprecated OVAL tags
- Fix cpe_generate.py to use
- Part of ComplianceAsCode#1046
@iankko iankko modified the milestones: 0.1.30, 0.1.31 Jun 24, 2016
redhatrises added a commit to redhatrises/scap-security-guide that referenced this issue Jul 14, 2016
- Makefile standardization and cleanup
- Add transforms XSLT
- Remove old files
- Part of ComplianceAsCode#1046
redhatrises added a commit to redhatrises/scap-security-guide that referenced this issue Aug 23, 2016
- Update XCCDF content
- Break out OVAL
- Part of ComplianceAsCode#1046
@mpreisler mpreisler removed the BLOCKER Impediments to release, like failure to build content, or content built is out of standard's syntax label Nov 15, 2016
@mpreisler
Copy link
Member

This is not a blocker, probably marked as blocker by accident.

@yuumasato yuumasato removed this from the 0.1.32 milestone Feb 28, 2017
@yuumasato yuumasato modified the milestones: 0.1.33, 0.1.34 Apr 18, 2017
@yuumasato yuumasato modified the milestones: 0.1.34, 0.1.35 Jun 29, 2017
@yuumasato yuumasato modified the milestones: 0.1.35, 0.1.36 Aug 29, 2017
@redhatrises redhatrises added enhancement General enhancements to the project. and removed help-wanted This PR/Issue needs help to go forward. labels Sep 28, 2017
@redhatrises
Copy link
Contributor

This has been fixed with the lastest JBoss EAP 6 content and the removal of the EAP 5 content.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement General enhancements to the project. Infrastructure Our content build system
Projects
None yet
Development

No branches or pull requests

4 participants