-
Notifications
You must be signed in to change notification settings - Fork 750
Build reference tables in RHEL9 and RHEL10 and include CCE #13890
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7,6 +7,8 @@ set(PRODUCT "rhel10") | |
|
|
||
| ssg_build_product(${PRODUCT}) | ||
|
|
||
| ssg_build_html_ref_tables("${PRODUCT}" "table-${PRODUCT}-{ref_id}refs" "anssi;cis;cui;nist;pcidss") | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Why this selection of profiles? What about E8, STIG, and other profiles? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. It's the same we had in RHEL8 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I think that if we do it we should do it for all profiles existing. |
||
|
|
||
| ssg_build_html_cce_table(${PRODUCT}) | ||
|
|
||
| ssg_build_html_srgmap_tables(${PRODUCT}) | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm not happy about reactivating the legacy tables in new products. Our goal is to get rid of them instead. We replaced them by control files, and also by rendering the control files as HTML online.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yeah, I understand that. The thing is that we don't have an easy way to map CCEs into references, and some customers find it useful.
Would be another way to creating these mappings?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good point, I have missed that CCEs can be useful to some people. But I still think we should evaluate whether a separate table is what you want. People also can see the CCEs in HTML guides and HTML reports.
You should be able to add CCE number to rendered control files (eg. https://complianceascode.github.io/content-pages/rendered-policies/rhel9/cis_rhel9.html ) this way:
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This sounds like a good idea.