From owner-freebsd-security@freebsd.org Sat Jul 22 01:49:16 2017 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 2D74BC7A7EC for ; Sat, 22 Jul 2017 01:49:16 +0000 (UTC) (envelope-from yonas@fizk.net) Received: from mail-io0-x244.google.com (mail-io0-x244.google.com [IPv6:2607:f8b0:4001:c06::244]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id F040D65D03 for ; Sat, 22 Jul 2017 01:49:15 +0000 (UTC) (envelope-from yonas@fizk.net) Received: by mail-io0-x244.google.com with SMTP id f1so4464672ioj.2 for ; Fri, 21 Jul 2017 18:49:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fizk.net; s=google; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-language; bh=8TqvzxWj7MRAegGrdPIeO8pdV7Bi3DcuMqQKP8zQGfI=; b=cOZBkbRd4T5zUmE/KXLM4q5zffRNjM+VZVOvvNlgQEIakVb2uRncSwCKnfoCWkzwPk a2kuX1XF2pXJzMeJx7Xy0mpF8dSZRdu4nXvMq2MXK5Ha9EdFGaWMNLA1wde75Bg8RkSv LYsC2USQo2PMVZHrNfqLleTvIaw+Hvv/t2cGg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language; bh=8TqvzxWj7MRAegGrdPIeO8pdV7Bi3DcuMqQKP8zQGfI=; b=IoBiTDGXoKXy7TbUWEOQM04u9Y9u44msvB/q4ZfdndnVX3oGgpR1penk2yyJAz7Gx/ 7S65uPCKNu7LOkZA9PiULcn0o+zqY9iHfPuBz1xUUMKIFL2M5vzDcSmAtcOYjS4ORhEZ ELz2an+PXqqgs+aE+m9vLs8VZUwqmgsNHX978Dg3nkBeSY1bBsSqfLxj7RQEJViMaZLV YLDt7AzbsVgHsIj22bWIXPOyLTqshmqShmwcbBYqWDovkSSm+oq9YQtUBugOay5ts7AX nNMCdviCeurKdXJSD84T+gsYAKmT2cnlcraNVDXQMIc4J6HjUPudHzMVg/+lxSIBgseI V5zg== X-Gm-Message-State: AIVw113tR/6v8uZ0lWNTu8Psa6aTPaDj3w4SrC1Jg3nDhlXgMXqa4zlp 0tCxCQhAukwcXhzWOR39hA== X-Received: by 10.107.41.5 with SMTP id p5mr8572030iop.165.1500688154819; Fri, 21 Jul 2017 18:49:14 -0700 (PDT) Received: from [192.168.2.200] (CPEf0f2494a5cf3-CMf0f2494a5cf0.cpe.net.cable.rogers.com. [174.117.121.225]) by smtp.gmail.com with ESMTPSA id 5sm1495708iox.9.2017.07.21.18.49.13 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 21 Jul 2017 18:49:13 -0700 (PDT) Subject: Re: OpenSCAP for FreeBSD To: freebsd-security@freebsd.org References: <3056b3dc-82d6-0634-0f14-2a4308488a95@fizk.net> <2651306.a2lTSCmlO7@freechin.atlnet> From: Yonas Yanfa Message-ID: <72d3444e-5174-776e-049e-8b3099fab779@fizk.net> Date: Fri, 21 Jul 2017 21:49:14 -0400 User-Agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1 MIME-Version: 1.0 In-Reply-To: <2651306.a2lTSCmlO7@freechin.atlnet> Content-Language: en-US Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit X-Content-Filtered-By: Mailman/MimeDel 2.1.23 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 22 Jul 2017 01:49:16 -0000 On 07/21/2017 20:17, Joey Kelly wrote: > On Friday 21 July 2017 19:21:10 Yonas Yanfa wrote: >> Hi, >> >> Is there anything like OpenSCAP for FreeBSD? > If it's a matter of selecting an XML profile, then surely one can be crafted > for any OS you choose. > Yes, and it shouldn't be too hard to port this to FreeBSD, but possibly time consuming. The benefit of porting it is that they already have a lot of security policies written (eg. USGCB, PCI DSS). Scanning and remedying Linux and FreeBSD systems for vulnerabilities could be done using the same XML file. Also, you can use their installer plugin to set security profiles during install. -- Yonas Yanfa In Love With Open Source Drupal :: GitHub :: Mozilla fizk.net | yonas@fizk.net