You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在无头RHEL 8.9 AMI中自动化修复STIG要求并排除指定子集

如何在无头RHEL 8.9 AMI中自动化修复STIG要求并排除指定子集

你完全不用折腾XML修改或者手动编辑生成的脚本——oscap本身就支持直接排除特定STIG规则,这是很多运维人员常用的方案,我来给你两种靠谱的实现方式:

方法一:临时快速排除(适合一次性操作)

oscap的xccdf eval和xccdf generate fix命令都支持--skip-rule参数,你可以直接在生成修复脚本的时候指定要排除的规则ID,多个规则就重复加这个参数就行。

比如假设你要排除的四个规则ID是xccdf_org.ssgproject.content_rule_rule_id_1、xccdf_org.ssgproject.content_rule_rule_id_2、xccdf_org.ssgproject.content_rule_rule_id_3、xccdf_org.ssgproject.content_rule_rule_id_4,执行这条命令就能生成排除了这些规则的修复脚本:

sudo oscap xccdf generate fix \
  --template urn:xccdf:fix:script:sh \
  --profile xccdf_org.ssgproject.content_profile_stig \
  --skip-rule xccdf_org.ssgproject.content_rule_rule_id_1 \
  --skip-rule xccdf_org.ssgproject.content_rule_rule_id_2 \
  --skip-rule xccdf_org.ssgproject.content_rule_rule_id_3 \
  --skip-rule xccdf_org.ssgproject.content_rule_rule_id_4 \
  --output custom-remediation-script.sh \
  /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml

生成的脚本会自动跳过这四个规则的修复步骤,完全不用手动修改。

方法二:自定义STIG Profile(适合长期复用/维护)

如果以后你还需要调整排除的规则,或者要在多个环境复用这个配置,创建自定义Profile是更优雅的选择,步骤也很简单:

  1. 先导出官方STIG Profile的基础配置:
sudo oscap xccdf export profile xccdf_org.ssgproject.content_profile_stig \
  --output stig-custom-profile.xml \
  /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
  1. 修改这个XML,禁用指定规则。因为是无头环境,你可以用sed自动化完成:
# 在</Profile>标签前插入禁用规则的语句
sed -i '/<\/Profile>/i <select idref="xccdf_org.ssgproject.content_rule_rule_id_1" selected="false"/>\n<select idref="xccdf_org.ssgproject.content_rule_rule_id_2" selected="false"/>\n<select idref="xccdf_org.ssgproject.content_rule_rule_id_3" selected="false"/>\n<select idref="xccdf_org.ssgproject.content_rule_rule_id_4" selected="false"/>' stig-custom-profile.xml

# 可选:给自定义Profile改个独特的ID和名称,方便识别
sed -i 's/id="xccdf_org.ssgproject.content_profile_stig"/id="xccdf_custom.profile_stig_excluded_rules"/' stig-custom-profile.xml
sed -i 's/<title>STIG for Red Hat Enterprise Linux 8<\/title>/<title>STIG for RHEL 8 (Excluded 4 Rules)<\/title>/' stig-custom-profile.xml
  1. 用自定义Profile生成修复脚本:
sudo oscap xccdf generate fix \
  --template urn:xccdf:fix:script:sh \
  --profile xccdf_custom.profile_stig_excluded_rules \
  --output custom-remediation-script.sh \
  stig-custom-profile.xml /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml

小提示:怎么获取规则ID?

你可以先跑一次扫描,在生成的scan-xccdf-results.xml里找到对应规则的ID;或者用这条命令快速查找规则标题对应的ID:

oscap info /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml | grep -A1 -B1 "你要排除的规则标题关键词"

这样操作下来,完全不用手动修改扫描结果或者修复脚本,全程命令行自动化,完美适配无头环境。

备注:内容来源于stack exchange,提问作者Menes Narmer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 10:19:41