CloudForms and ManageIQ policy, profile and report for DROWN OpenSSH Vulnerability
Switch branches/tags
Nothing to show
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Failed to load latest commit information.
images
scripts
README.md
metadata.yaml

README.md

This is a package containing a policy, profile and report to assist in identifying affected OpenSSL package versions and validate the security of the servers visible in Red Hat CloudForms and ManageIQ.

See this blog post for additional details: Managing Patching Compliance Using DROWN OpenSSL Vulnerability as an Example.

Download the following policy, profile and report yaml definitions and import them in your appliance:

Once the policy and profile imported, the profile can be assigned to VM instances and Compliance can be checked. Screen Shot Compliance Policy

The report provides the results of the compliance checks. Screen Shot Compliance Report