Bookmark this page

Guided Exercise: Running OpenSCAP Reports from Red Hat Insights

Use the compliance service in Red Hat Insights to configure OpenSCAP policies and review the resulting reports.

Back to video
Running OpenSCAP Reports from Red Hat Insights

Outcomes

  • Configure OpenSCAP policies in Red Hat Insights.

  • Review RHEL systems compliance by using Red Insights.

As the student user on the workstation machine, use the lab command to prepare your environment for this exercise, and to ensure that all required resources are available.

[student@workstation ~]$ lab start insights-running

Instructions

  1. On the workstation machine, open a web browser and navigate to the Hybrid Cloud Console at https://console.redhat.com/insights/. Log in with your Red Hat account. Navigate to SecurityComplianceSCAP Policies.

  2. Click Create new policy.

  3. Select RHEL 9 as the operating system, and filter the policy types by using the server keyword in the Policy type search field.

  4. Select the CIS Red Hat Enterprise Linux 9 Benchmark for Level 1 - Server policy and click Next.

  5. Review the policy details and click Next.

  6. Select the serverd.lab.example.com system to be added to this policy, and click Next.

  7. Customize the policy for the environment's needs. Select the Sudo and Updating Software rules, and click Next.

  8. Review your custom policy, and click Finish

  9. On the serverd machine, install the SCAP Security Guide.

    1. Log in to the serverd machine as the student user. No password is required.

      [student@workstation ~]$ ssh student@serverd
      [student@serverd ~]$
    2. Use the sudo -i command to switch identity to the root user. Use student as the password.

      [student@serverd ~]$ sudo -i
      [sudo] password for student: student
      [root@serverd ~]#
    3. Install the scap-security-guide package, which provides the SCAP Security Guide.

      [root@serverd ~]# dnf install scap-security-guide
      ...output omitted...
      Complete!
  10. Run the insights-client --compliance command.

    [root@serverd ~]# insights-client --compliance
    System uses SSG version 0.1.66
    Saved tailoring file for xccdf_org.ssgproject.content_profile_cis_server_l1 to /var/tmp/oscap_tailoring_file-xccdf_org.ssgproject.content_profile_cis_server_l1.fruiolnu.xml
    Running scan for xccdf_org.ssgproject.content_profile_cis_server_l1... this may take a while
    Uploading Insights data.
    Successfully uploaded report for serverd.lab.example.com.
  11. Navigate to the SecurityComplianceReports page to view the compliance reports.

  12. Click the CIS Red Hat Enterprise Linux 9 Benchmark for Level 1 - Server policy to see the report details:

  13. Click serverd.lab.example.com to see the report details for this server.

Finish

On the workstation machine, use the lab command to complete this exercise. This step is important to ensure that resources from previous exercises do not impact upcoming exercises.

[student@workstation ~]$ lab finish insights-running

Revision: rh415-9.2-a821299