You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

适配Pop!_OS 22.04 LTS:修改Ubuntu SCAP以执行扫描

问题:Pop!_OS 22.04 LTS 使用Ubuntu 20.04 SCAP扫描时所有检测项被标记为不适用

我使用基于Ubuntu的Pop!_OS 22.04 LTS系统,已安装openScap工具,采用cyber.mil提供的SCC 5.8 Ubuntu 22 AMD64 SCAP进行扫描。但由于该SCAP默认适配Ubuntu 20.04 LTS,所有检测项均被标记为不适用而跳过。

使用的终端命令:

sudo oscap xccdf eval --fetch-remote-resources --oval-results --profile xccdf_mil.disa.stig_profile_MAC-2_Sensitive --report scan.html --results scan_results /home/komodo2013/Downloads/updated_scap.xml

修改尝试:
我曾编写Python脚本将所有<platform>Ubuntu 20.04 LTS</platform>标签替换为<platform>Pop!_OS 22.04 LTS</platform>,且文件中存在<xccdf:platform idref="cpe:/o:pop_os:pop_os:22.04"/>,但问题仍未解决。

推测问题出在以下XML片段:

<definitions>
    <definition class="inventory" id="oval:mil.disa.stig.ubuntu2004:def:1" version="1">
        <metadata>
            <title>Ubuntu 20.04 LTS is installed</title>
            <affected family="unix">
                <platform>Ubuntu 20.04 LTS</platform>
            </affected>
            <reference ref_id="cpe:/o:canonical:ubuntu_linux:20.04" source="CPE" />
            <description>Ubuntu 20.04 LTS is installed</description>
        </metadata>
        <criteria>
            <criterion comment="Ubuntu 20.04 is installed" test_ref="oval:mil.disa.stig.ubuntu2004:tst:100" />
            </criteria>
    </definition>
</definitions>
<tests>
    <textfilecontent54_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" check="all" check_existence="at_least_one_exists" comment="Ubuntu 20.04 is installed" id="oval:mil.disa.stig.ubuntu2004:tst:100" version="1">
    <object object_ref="oval:mil.disa.stig.ubuntu2004:obj:100" />
    <state state_ref="oval:mil.disa.stig.ubuntu2004:ste:100" />
    </textfilecontent54_test>
</tests>

扫描可完成并生成HTML报告,但所有检测项仍被跳过。请问如何让扫描正常执行,或修改SCAP以适配Pop!_OS?


解决方案
  • 修改OVAL inventory定义的平台匹配逻辑
    你看到的XML片段是OVAL的inventory检测项,用来验证系统版本。要适配Pop!_OS 22.04,需修改:

    1. 将<affected>下的<platform>值改为Pop!_OS 22.04 LTS
    2. 替换<reference>中的CPE引用为cpe:/o:pop_os:pop_os:22.04
    3. 更新标题和描述里的系统版本信息,方便后续识别
  • 调整OVAL测试的对象与状态规则
    这个inventory测试对应的对象和状态需要匹配Pop!_OS的系统标识:

    • 找到对应<object>(oval:mil.disa.stig.ubuntu2004:obj:100),它通常读取/etc/os-release或/etc/lsb-release,需修改匹配内容为Pop!_OS的标识,比如把VERSION_ID="20.04"改为VERSION_ID="22.04",NAME="Ubuntu"改为NAME="Pop!_OS"
    • 同步修改对应的<state>(oval:mil.disa.stig.ubuntu2004:ste:100)的预期值,确保能匹配Pop!_OS系统信息
  • 批量替换全文件CPE引用
    除inventory定义外,整个SCAP文件中所有指向Ubuntu 20.04的CPE(cpe:/o:canonical:ubuntu_linux:20.04)都要替换为Pop!_OS 22.04的CPE(cpe:/o:pop_os:pop_os:22.04),包括XCCDF规则中的平台引用。

  • 验证修改后的SCAP文件
    修改完成后,先验证文件语法正确性:

    oscap xccdf validate /home/komodo2013/Downloads/updated_scap.xml
    oscap oval validate /home/komodo2013/Downloads/updated_scap.xml
    

    确认无语法错误后,再重新执行扫描命令。

  • 备选:强制跳过平台检测
    若不想修改大量OVAL内容,可在扫描命令中添加--skip-platform-check参数,强制跳过平台兼容性检测:

    sudo oscap xccdf eval --skip-platform-check --fetch-remote-resources --oval-results --profile xccdf_mil.disa.stig_profile_MAC-2_Sensitive --report scan.html --results scan_results /home/komodo2013/Downloads/updated_scap.xml
    

    注意:此方法可能导致部分Ubuntu 20.04规则在Pop!_OS上执行出错,需手动排查无效规则。

内容的提问来源于stack exchange,提问作者Jacob Larsen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 06:13:15