适配Pop!_OS 22.04 LTS:修改Ubuntu SCAP以执行扫描
我使用基于Ubuntu的Pop!_OS 22.04 LTS系统,已安装openScap工具,采用cyber.mil提供的SCC 5.8 Ubuntu 22 AMD64 SCAP进行扫描。但由于该SCAP默认适配Ubuntu 20.04 LTS,所有检测项均被标记为不适用而跳过。
使用的终端命令:
sudo oscap xccdf eval --fetch-remote-resources --oval-results --profile xccdf_mil.disa.stig_profile_MAC-2_Sensitive --report scan.html --results scan_results /home/komodo2013/Downloads/updated_scap.xml
修改尝试:
我曾编写Python脚本将所有<platform>Ubuntu 20.04 LTS</platform>标签替换为<platform>Pop!_OS 22.04 LTS</platform>,且文件中存在<xccdf:platform idref="cpe:/o:pop_os:pop_os:22.04"/>,但问题仍未解决。
推测问题出在以下XML片段:
<definitions> <definition class="inventory" id="oval:mil.disa.stig.ubuntu2004:def:1" version="1"> <metadata> <title>Ubuntu 20.04 LTS is installed</title> <affected family="unix"> <platform>Ubuntu 20.04 LTS</platform> </affected> <reference ref_id="cpe:/o:canonical:ubuntu_linux:20.04" source="CPE" /> <description>Ubuntu 20.04 LTS is installed</description> </metadata> <criteria> <criterion comment="Ubuntu 20.04 is installed" test_ref="oval:mil.disa.stig.ubuntu2004:tst:100" /> </criteria> </definition> </definitions> <tests> <textfilecontent54_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" check="all" check_existence="at_least_one_exists" comment="Ubuntu 20.04 is installed" id="oval:mil.disa.stig.ubuntu2004:tst:100" version="1"> <object object_ref="oval:mil.disa.stig.ubuntu2004:obj:100" /> <state state_ref="oval:mil.disa.stig.ubuntu2004:ste:100" /> </textfilecontent54_test> </tests>
扫描可完成并生成HTML报告,但所有检测项仍被跳过。请问如何让扫描正常执行,或修改SCAP以适配Pop!_OS?
修改OVAL inventory定义的平台匹配逻辑
你看到的XML片段是OVAL的inventory检测项,用来验证系统版本。要适配Pop!_OS 22.04,需修改:- 将
<affected>下的<platform>值改为Pop!_OS 22.04 LTS - 替换
<reference>中的CPE引用为cpe:/o:pop_os:pop_os:22.04 - 更新标题和描述里的系统版本信息,方便后续识别
- 将
调整OVAL测试的对象与状态规则
这个inventory测试对应的对象和状态需要匹配Pop!_OS的系统标识:- 找到对应
<object>(oval:mil.disa.stig.ubuntu2004:obj:100),它通常读取/etc/os-release或/etc/lsb-release,需修改匹配内容为Pop!_OS的标识,比如把VERSION_ID="20.04"改为VERSION_ID="22.04",NAME="Ubuntu"改为NAME="Pop!_OS" - 同步修改对应的
<state>(oval:mil.disa.stig.ubuntu2004:ste:100)的预期值,确保能匹配Pop!_OS系统信息
- 找到对应
批量替换全文件CPE引用
除inventory定义外,整个SCAP文件中所有指向Ubuntu 20.04的CPE(cpe:/o:canonical:ubuntu_linux:20.04)都要替换为Pop!_OS 22.04的CPE(cpe:/o:pop_os:pop_os:22.04),包括XCCDF规则中的平台引用。验证修改后的SCAP文件
修改完成后,先验证文件语法正确性:oscap xccdf validate /home/komodo2013/Downloads/updated_scap.xml oscap oval validate /home/komodo2013/Downloads/updated_scap.xml确认无语法错误后,再重新执行扫描命令。
备选:强制跳过平台检测
若不想修改大量OVAL内容,可在扫描命令中添加--skip-platform-check参数,强制跳过平台兼容性检测:sudo oscap xccdf eval --skip-platform-check --fetch-remote-resources --oval-results --profile xccdf_mil.disa.stig_profile_MAC-2_Sensitive --report scan.html --results scan_results /home/komodo2013/Downloads/updated_scap.xml注意:此方法可能导致部分Ubuntu 20.04规则在Pop!_OS上执行出错,需手动排查无效规则。
内容的提问来源于stack exchange,提问作者Jacob Larsen

