You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用自定义OpenSCAP配置文件远程评估与修复Ubuntu 22.04的CIS Level 1服务器基准失败

使用自定义OpenSCAP配置文件远程评估与修复Ubuntu 22.04的CIS Level 1服务器基准失败

看起来你遇到的问题是自定义tailoring文件的基准引用路径在远程执行时被错误解析导致的。让我帮你拆解一下原因和解决办法:

问题根源

你用autotailor生成的自定义tailoring文件里,引用基准文件(ssg-ubuntu2204-ds-1.2.xml)的路径可能是带file://前缀的绝对路径,或者是本地RHEL系统上的路径。当oscap-ssh把tailoring文件传到Ubuntu的临时目录后,远程的OpenSCAP进程会尝试在临时目录下拼接这个路径,就出现了/tmp/tmp.8KTqEvg4Pj/file:///usr/share/openscap/ssg-ubuntu2204-ds-1.2.xml这种错误路径——它把临时目录和file://路径硬凑到一起了,自然找不到文件。

解决方案

这里有两种可靠的解决方式,你可以根据情况选择:

方案1:把基准文件和tailoring文件一起传到远程

  1. 先修改你的tailoring文件:打开ssg-ubuntu2204-ds-1.2-tailoring_1.xml,找到<xccdf:Benchmark>标签的href属性,把类似file:///usr/share/openscap/ssg-ubuntu2204-ds-1.2.xml的内容改成ssg-ubuntu2204-ds-1.2.xml(相对路径)。
  2. 然后修改oscap-ssh命令,把基准文件也作为参数传入:
    oscap-ssh root@xx.x.x.xx 22 xccdf eval --remediate --profile xccdf_org.ssgproject.content_profile_ssg-ubuntu2204-ds-1.2-custom --results ssg-ubuntu2204-ds-1.2-remediation-custom-results.xml --results-arf ssg-ubuntu2204-ds-1.2-arf-custom-results.xml ssg-ubuntu2204-ds-1.2.xml ssg-ubuntu2204-ds-1.2-tailoring_1.xml
    
    这样oscap-ssh会把基准文件和tailoring文件都传到远程的临时目录,tailoring文件里的相对路径就能正确找到基准文件了。

方案2:让远程Ubuntu本地拥有基准文件

  1. 先在远程Ubuntu 22.04系统上安装SCAP安全指南包:
    sudo apt update && sudo apt install scap-security-guide
    
    安装完成后,/usr/share/openscap/ssg-ubuntu2204-ds-1.2.xml就会存在于远程系统中。
  2. 修改你的tailoring文件:把<xccdf:Benchmark>标签的href属性改成/usr/share/openscap/ssg-ubuntu2204-ds-1.2.xml(去掉file://前缀,直接用绝对路径)。
  3. 然后执行原来的oscap-ssh命令即可——远程系统会直接访问本地的基准文件,不需要再传过去。

额外验证步骤

在远程执行前,你可以先在本地验证tailoring文件和基准文件的兼容性,避免后续出错:

oscap xccdf validate --profile xccdf_org.ssgproject.content_profile_ssg-ubuntu2204-ds-1.2-custom ssg-ubuntu2204-ds-1.2.xml ssg-ubuntu2204-ds-1.2-tailoring_1.xml

如果命令没有报错,说明文件本身是没问题的,再去远程执行就更稳妥了。

备注:内容来源于stack exchange,提问作者anu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 12:20:29