如何在无头RHEL 8.9 AMI中自动化修复STIG要求并排除指定子集
如何在无头RHEL 8.9 AMI中自动化修复STIG要求并排除指定子集
你完全不用折腾XML修改或者手动编辑生成的脚本——oscap本身就支持直接排除特定STIG规则,这是很多运维人员常用的方案,我来给你两种靠谱的实现方式:
方法一:临时快速排除(适合一次性操作)
oscap的xccdf eval和xccdf generate fix命令都支持--skip-rule参数,你可以直接在生成修复脚本的时候指定要排除的规则ID,多个规则就重复加这个参数就行。
比如假设你要排除的四个规则ID是xccdf_org.ssgproject.content_rule_rule_id_1、xccdf_org.ssgproject.content_rule_rule_id_2、xccdf_org.ssgproject.content_rule_rule_id_3、xccdf_org.ssgproject.content_rule_rule_id_4,执行这条命令就能生成排除了这些规则的修复脚本:
sudo oscap xccdf generate fix \ --template urn:xccdf:fix:script:sh \ --profile xccdf_org.ssgproject.content_profile_stig \ --skip-rule xccdf_org.ssgproject.content_rule_rule_id_1 \ --skip-rule xccdf_org.ssgproject.content_rule_rule_id_2 \ --skip-rule xccdf_org.ssgproject.content_rule_rule_id_3 \ --skip-rule xccdf_org.ssgproject.content_rule_rule_id_4 \ --output custom-remediation-script.sh \ /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
生成的脚本会自动跳过这四个规则的修复步骤,完全不用手动修改。
方法二:自定义STIG Profile(适合长期复用/维护)
如果以后你还需要调整排除的规则,或者要在多个环境复用这个配置,创建自定义Profile是更优雅的选择,步骤也很简单:
- 先导出官方STIG Profile的基础配置:
sudo oscap xccdf export profile xccdf_org.ssgproject.content_profile_stig \ --output stig-custom-profile.xml \ /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
- 修改这个XML,禁用指定规则。因为是无头环境,你可以用
sed自动化完成:
# 在</Profile>标签前插入禁用规则的语句 sed -i '/<\/Profile>/i <select idref="xccdf_org.ssgproject.content_rule_rule_id_1" selected="false"/>\n<select idref="xccdf_org.ssgproject.content_rule_rule_id_2" selected="false"/>\n<select idref="xccdf_org.ssgproject.content_rule_rule_id_3" selected="false"/>\n<select idref="xccdf_org.ssgproject.content_rule_rule_id_4" selected="false"/>' stig-custom-profile.xml # 可选:给自定义Profile改个独特的ID和名称,方便识别 sed -i 's/id="xccdf_org.ssgproject.content_profile_stig"/id="xccdf_custom.profile_stig_excluded_rules"/' stig-custom-profile.xml sed -i 's/<title>STIG for Red Hat Enterprise Linux 8<\/title>/<title>STIG for RHEL 8 (Excluded 4 Rules)<\/title>/' stig-custom-profile.xml
- 用自定义Profile生成修复脚本:
sudo oscap xccdf generate fix \ --template urn:xccdf:fix:script:sh \ --profile xccdf_custom.profile_stig_excluded_rules \ --output custom-remediation-script.sh \ stig-custom-profile.xml /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
小提示:怎么获取规则ID?
你可以先跑一次扫描,在生成的scan-xccdf-results.xml里找到对应规则的ID;或者用这条命令快速查找规则标题对应的ID:
oscap info /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml | grep -A1 -B1 "你要排除的规则标题关键词"
这样操作下来,完全不用手动修改扫描结果或者修复脚本,全程命令行自动化,完美适配无头环境。
备注:内容来源于stack exchange,提问作者Menes Narmer
相关产品推荐
相关产品推荐

