Bertilla,

This may be a bit more than you're looking for, but we've started integrating some InSpec work into our workflow and are using the SSG to validate it.

The SSG part of our acceptance test can be found at https://github.com/simp/inspec_profiles/blob/dev/spec/acceptance/suites/default/10_ssg_apply_spec.rb which does a full compile of the SSG at https://github.com/simp/inspec_profiles/blob/dev/spec/acceptance/suites/default/10_ssg_apply_spec.rb#L43-L50.

Trevor

On Tue, Jun 20, 2017 at 5:52 AM, Bertilla Theodore <bertillatheodore1@gmail.com> wrote:
Hi 

I am new to SCAP technology and trying to learn adding new XCCDF and OVAL content to SCAP security guide. I am following the workshop content at http://people.redhat.com/jamisonm/scap/SCAP-Workshop-Coursebook-v2.pdf & https://jlieskov.files.wordpress.com/2013/11/scap_security_guide_questions_answers_contributor_workshop_volume_2_january_2016.pdf 

But they seem to be outdated and I am lost since the directory structure of the latest SSG is different than the one at the time of the workshop. Although I could locate and add a new XCCDF rule, I'm not sure how to compile and validate after that. 'make' returns errors as there is no Makefile. The ssg macros in CMakeLists.txt are missing their definition, so cmake is also not working. I am also not able to locate the HTML guide where I can see the newly added rule (I am guessing that's because I couldn't compile in the first place). I've got the SSG source from https://github.com/OpenSCAP/scap-security-guide.

Please help me on how I should proceed. If there is an updated documentation, please point it out to me.

Your advise would be of great help.
Thanks in advance.

Best regards
Bertilla Theodore

_______________________________________________
scap-security-guide mailing list -- scap-security-guide@lists.fedorahosted.org
To unsubscribe send an email to scap-security-guide-leave@lists.fedorahosted.org




--
Trevor Vaughan
Vice President, Onyx Point, Inc
(410) 541-6699 x788

-- This account not approved for unencrypted proprietary information --