Use the compliance service in Red Hat Insights to configure OpenSCAP policies and review the resulting reports.
Outcomes
Configure OpenSCAP policies in Red Hat Insights.
Review RHEL systems compliance by using Red Insights.
As the student user on the workstation machine, use the lab command to prepare your environment for this exercise, and to ensure that all required resources are available.
[student@workstation ~]$ lab start insights-running
Instructions
On the workstation machine, open a web browser and navigate to the Hybrid Cloud Console at https://console.redhat.com/insights/.
Log in with your Red Hat account.
Navigate to → → .
![]() |
Click .
![]() |
Select as the operating system, and filter the policy types by using the server keyword in the search field.
![]() |
Select the CIS Red Hat Enterprise Linux 9 Benchmark for Level 1 - Server policy and click .
![]() |
Review the policy details and click .
![]() |
Select the serverd.lab.example.com system to be added to this policy, and click .
![]() |
Customize the policy for the environment's needs.
Select the Sudo and Updating Software rules, and click .
![]() |
Review your custom policy, and click
![]() |
On the serverd machine, install the SCAP Security Guide.
Log in to the serverd machine as the student user.
No password is required.
[student@workstation ~]$ ssh student@serverd
[student@serverd ~]$Use the sudo -i command to switch identity to the root user.
Use student as the password.
[student@serverd ~]$sudo -i[sudo] password for student:student[root@serverd ~]#
Install the scap-security-guide package, which provides the SCAP Security Guide.
[root@serverd ~]# dnf install scap-security-guide
...output omitted...
Complete!Run the insights-client --compliance command.
[root@serverd ~]# insights-client --compliance
System uses SSG version 0.1.66
Saved tailoring file for xccdf_org.ssgproject.content_profile_cis_server_l1 to /var/tmp/oscap_tailoring_file-xccdf_org.ssgproject.content_profile_cis_server_l1.fruiolnu.xml
Running scan for xccdf_org.ssgproject.content_profile_cis_server_l1... this may take a while
Uploading Insights data.
Successfully uploaded report for serverd.lab.example.com.Navigate to the → → page to view the compliance reports.
![]() |
Click the policy to see the report details:
![]() |
Click to see the report details for this server.
![]() |