From 2a2b17dfb901bd395aa9b1d3eb16f9ceb2d58852 Mon Sep 17 00:00:00 2001 From: James Berendzen Date: Tue, 4 Aug 2026 16:41:20 -0400 Subject: [PATCH] Uploading cleanup from 4214 before breaking it apart in sections per endeavor guidelines --- .../modules/con_compliance-email-notifications.adoc | 2 +- ..._configuring-compliance-policy-deployment-methods.adoc | 2 +- .../common/modules/con_managing-compliance-policies.adoc | 2 +- guides/common/modules/con_monitoring-compliance.adoc | 2 +- ...mote-scap-resources-in-a-disconnected-environment.adoc | 2 +- ...g-project-for-puppet-compliance-policy-deployment.adoc | 3 +++ .../common/modules/proc_creating-a-compliance-policy.adoc | 2 +- .../common/modules/proc_deleting-a-compliance-report.adoc | 2 +- ..._deploying-a-policy-in-a-host-group-using-ansible.adoc | 6 +++--- ...c_deploying-a-policy-in-a-host-group-using-puppet.adoc | 4 ++-- .../proc_deploying-a-policy-on-a-host-using-ansible.adoc | 4 ++-- .../proc_deploying-a-policy-on-a-host-using-puppet.adoc | 4 ++-- .../common/modules/proc_editing-a-compliance-policy.adoc | 2 +- .../proc_getting-supported-scap-contents-for-rhel.adoc | 2 +- .../proc_listing-available-scap-contents-using-cli.adoc | 2 +- .../modules/proc_loading-the-default-scap-contents.adoc | 2 +- .../modules/proc_remediating-compliance-failures.adoc | 2 +- ...proc_running-a-security-compliance-scan-on-demand.adoc | 4 ++-- .../common/modules/proc_searching-compliance-reports.adoc | 8 +++++++- .../proc_uploading-additional-scap-content-using-cli.adoc | 5 +++-- ...oc_uploading-additional-scap-content-using-web-ui.adoc | 6 +++--- .../common/modules/proc_viewing-a-compliance-policy.adoc | 2 +- .../proc_viewing-compliance-policy-statistics.adoc | 2 +- .../modules/ref_inclusion-of-remote-scap-resources.adoc | 2 +- 24 files changed, 42 insertions(+), 32 deletions(-) diff --git a/guides/common/modules/con_compliance-email-notifications.adoc b/guides/common/modules/con_compliance-email-notifications.adoc index 770a69ead4f..cef2df2d3ad 100644 --- a/guides/common/modules/con_compliance-email-notifications.adoc +++ b/guides/common/modules/con_compliance-email-notifications.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: CONCEPT -[id="Compliance_Email_Notifications_{context}"] +[id="Compliance_Email_Notifications"] = Compliance email notifications [role="_abstract"] diff --git a/guides/common/modules/con_configuring-compliance-policy-deployment-methods.adoc b/guides/common/modules/con_configuring-compliance-policy-deployment-methods.adoc index 754fa202269..d93d3e7fadd 100644 --- a/guides/common/modules/con_configuring-compliance-policy-deployment-methods.adoc +++ b/guides/common/modules/con_configuring-compliance-policy-deployment-methods.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: CONCEPT -[id="configuring-compliance-policy-deployment-methods_{context}"] +[id="configuring-compliance-policy-deployment-methods"] = Configuring compliance policy deployment methods [role="_abstract"] diff --git a/guides/common/modules/con_managing-compliance-policies.adoc b/guides/common/modules/con_managing-compliance-policies.adoc index 7f506062a32..70345f341d0 100644 --- a/guides/common/modules/con_managing-compliance-policies.adoc +++ b/guides/common/modules/con_managing-compliance-policies.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: CONCEPT -[id="Managing_Compliance_Policies_{context}"] +[id="Managing_Compliance_Policies"] = Managing compliance policies [role="_abstract"] diff --git a/guides/common/modules/con_monitoring-compliance.adoc b/guides/common/modules/con_monitoring-compliance.adoc index e3fb6bf808f..98c556de176 100644 --- a/guides/common/modules/con_monitoring-compliance.adoc +++ b/guides/common/modules/con_monitoring-compliance.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: CONCEPT -[id="Monitoring_Compliance_{context}"] +[id="Monitoring_Compliance"] = Monitoring compliance [role="_abstract"] diff --git a/guides/common/modules/proc_applying-remote-scap-resources-in-a-disconnected-environment.adoc b/guides/common/modules/proc_applying-remote-scap-resources-in-a-disconnected-environment.adoc index 865eb9f111b..e83e796400f 100644 --- a/guides/common/modules/proc_applying-remote-scap-resources-in-a-disconnected-environment.adoc +++ b/guides/common/modules/proc_applying-remote-scap-resources-in-a-disconnected-environment.adoc @@ -10,7 +10,7 @@ If your hosts do not have internet access, you must download remote SCAP resourc .Prerequisites * You have registered your host to {Project} with remote execution enabled. * Fetching remote resources must be disabled, which is the default. -For more information, see xref:inclusion-of-remote-scap-resources_{context}[]. +For more information, see xref:inclusion-of-remote-scap-resources[]. .Procedure . On your {ProjectServer}, examine the data stream you use in your compliance policy to find out which missing resource you must download: diff --git a/guides/common/modules/proc_configuring-project-for-puppet-compliance-policy-deployment.adoc b/guides/common/modules/proc_configuring-project-for-puppet-compliance-policy-deployment.adoc index c2a737f5797..112ed4090d7 100644 --- a/guides/common/modules/proc_configuring-project-for-puppet-compliance-policy-deployment.adoc +++ b/guides/common/modules/proc_configuring-project-for-puppet-compliance-policy-deployment.adoc @@ -6,6 +6,9 @@ [role="_abstract"] If you want to use Puppet to deploy compliance policies, configure {Project} for Puppet compliance policy deployment. +.Prerequisites +. Ensure Puppet is enabled. + .Procedure . Ensure Puppet is enabled. . Ensure the OpenVox agent is installed on hosts. diff --git a/guides/common/modules/proc_creating-a-compliance-policy.adoc b/guides/common/modules/proc_creating-a-compliance-policy.adoc index 76f6a87eafd..9b2f243eb17 100644 --- a/guides/common/modules/proc_creating-a-compliance-policy.adoc +++ b/guides/common/modules/proc_creating-a-compliance-policy.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: PROCEDURE -[id="Creating_a_Compliance_Policy_{context}"] +[id="Creating_a_Compliance_Policy"] = Creating a compliance policy [role="_abstract"] diff --git a/guides/common/modules/proc_deleting-a-compliance-report.adoc b/guides/common/modules/proc_deleting-a-compliance-report.adoc index 760efa5dbf5..c0de403d539 100644 --- a/guides/common/modules/proc_deleting-a-compliance-report.adoc +++ b/guides/common/modules/proc_deleting-a-compliance-report.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: PROCEDURE -[id="Deleting_a_Compliance_Report_{context}"] +[id="Deleting_a_Compliance_Report"] = Deleting a compliance report [role="_abstract"] diff --git a/guides/common/modules/proc_deploying-a-policy-in-a-host-group-using-ansible.adoc b/guides/common/modules/proc_deploying-a-policy-in-a-host-group-using-ansible.adoc index 915b0e77f8c..f24a9614000 100644 --- a/guides/common/modules/proc_deploying-a-policy-in-a-host-group-using-ansible.adoc +++ b/guides/common/modules/proc_deploying-a-policy-in-a-host-group-using-ansible.adoc @@ -1,13 +1,13 @@ :_mod-docs-content-type: PROCEDURE -[id="Deploying_a_Policy_in_a_Host_Group_Using_Ansible_{context}"] +[id="Deploying_a_Policy_in_a_Host_Group_Using_Ansible"] = Deploying a policy in a host group using Ansible [role="_abstract"] After you deploy a compliance policy in a host group using Ansible, the Ansible role installs the SCAP client and configures OpenSCAP scans on the hosts according to the selected compliance policy. The SCAP content in the compliance policy might require remote resources. -For more information, see xref:inclusion-of-remote-scap-resources_{context}[]. +For more information, see xref:inclusion-of-remote-scap-resources[]. .Prerequisites * You have enabled OpenSCAP on your {SmartProxy}. @@ -17,7 +17,7 @@ include::snip_prerequisite-repositories-with-oscap.adoc[] + include::snip_prerequisite-project-client-repository-enabled.adoc[] This repository is required for installing the SCAP client. -* You have xref:Creating_a_Compliance_Policy_{context}[created a compliance policy] with the Ansible deployment option and assigned the host group. +* You have xref:Creating_a_Compliance_Policy[created a compliance policy] with the Ansible deployment option and assigned the host group. .Procedure . In the {ProjectWebUI}, navigate to *Configure* > *Host Groups*. diff --git a/guides/common/modules/proc_deploying-a-policy-in-a-host-group-using-puppet.adoc b/guides/common/modules/proc_deploying-a-policy-in-a-host-group-using-puppet.adoc index 10297b49d89..366f20177ca 100644 --- a/guides/common/modules/proc_deploying-a-policy-in-a-host-group-using-puppet.adoc +++ b/guides/common/modules/proc_deploying-a-policy-in-a-host-group-using-puppet.adoc @@ -1,13 +1,13 @@ :_mod-docs-content-type: PROCEDURE -[id="Deploying_a_Policy_in_a_Host_Group_Using_Puppet_{context}"] +[id="Deploying_a_Policy_in_a_Host_Group_Using_Puppet"] = Deploying a policy in a host group using Puppet [role="_abstract"] After you deploy a compliance policy in a host group using Puppet, the OpenVox agent installs the SCAP client and configures OpenSCAP scans on the hosts on the next Puppet run according to the selected compliance policy. The SCAP content in your compliance policy might require remote resources. -For more information, see xref:inclusion-of-remote-scap-resources_{context}[]. +For more information, see xref:inclusion-of-remote-scap-resources[]. .Prerequisites * You have enabled OpenSCAP on your {SmartProxy}. diff --git a/guides/common/modules/proc_deploying-a-policy-on-a-host-using-ansible.adoc b/guides/common/modules/proc_deploying-a-policy-on-a-host-using-ansible.adoc index 49a214795b9..19b0c5b144d 100644 --- a/guides/common/modules/proc_deploying-a-policy-on-a-host-using-ansible.adoc +++ b/guides/common/modules/proc_deploying-a-policy-on-a-host-using-ansible.adoc @@ -1,13 +1,13 @@ :_mod-docs-content-type: PROCEDURE -[id="Deploying_a_Policy_on_a_Host_Using_Ansible_{context}"] +[id="Deploying_a_Policy_on_a_Host_Using_Ansible"] = Deploying a policy on a host using Ansible [role="_abstract"] After you deploy a compliance policy on a host using Ansible, the Ansible role installs the SCAP client and configures OpenSCAP scans on the host according to the selected compliance policy. The SCAP content in the compliance policy might require remote resources. -For more information, see xref:inclusion-of-remote-scap-resources_{context}[]. +For more information, see xref:inclusion-of-remote-scap-resources[]. .Prerequisites * You have enabled OpenSCAP on your {SmartProxy}. diff --git a/guides/common/modules/proc_deploying-a-policy-on-a-host-using-puppet.adoc b/guides/common/modules/proc_deploying-a-policy-on-a-host-using-puppet.adoc index 4696ebbaa38..5b05f4762a0 100644 --- a/guides/common/modules/proc_deploying-a-policy-on-a-host-using-puppet.adoc +++ b/guides/common/modules/proc_deploying-a-policy-on-a-host-using-puppet.adoc @@ -1,13 +1,13 @@ :_mod-docs-content-type: PROCEDURE -[id="Deploying_a_Policy_on_a_Host_Using_Puppet_{context}"] +[id="Deploying_a_Policy_on_a_Host_Using_Puppet"] = Deploying a policy on a host using Puppet [role="_abstract"] After you deploy a compliance policy on a host using Puppet, the OpenVox agent installs the SCAP client and configures OpenSCAP scans on the host on the next Puppet run according to the selected compliance policy. The SCAP content in your compliance policy might require remote resources. -For more information, see xref:inclusion-of-remote-scap-resources_{context}[]. +For more information, see xref:inclusion-of-remote-scap-resources[]. .Prerequisites * You have enabled OpenSCAP on your {SmartProxy}. diff --git a/guides/common/modules/proc_editing-a-compliance-policy.adoc b/guides/common/modules/proc_editing-a-compliance-policy.adoc index b966971bb3f..a53bbc683e5 100644 --- a/guides/common/modules/proc_editing-a-compliance-policy.adoc +++ b/guides/common/modules/proc_editing-a-compliance-policy.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: PROCEDURE -[id="Editing_a_Compliance_Policy_{context}"] +[id="Editing_a_Compliance_Policy"] = Editing a compliance policy [role="_abstract"] diff --git a/guides/common/modules/proc_getting-supported-scap-contents-for-rhel.adoc b/guides/common/modules/proc_getting-supported-scap-contents-for-rhel.adoc index 0afbdc75ed9..2eb7f8291e7 100644 --- a/guides/common/modules/proc_getting-supported-scap-contents-for-rhel.adoc +++ b/guides/common/modules/proc_getting-supported-scap-contents-for-rhel.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: PROCEDURE -[id="getting-supported-scap-contents-for-rhel_{context}"] +[id="getting-supported-scap-contents-for-rhel"] = Getting supported SCAP contents for RHEL [role="_abstract"] diff --git a/guides/common/modules/proc_listing-available-scap-contents-using-cli.adoc b/guides/common/modules/proc_listing-available-scap-contents-using-cli.adoc index 45b282436f8..92a7ea31d1a 100644 --- a/guides/common/modules/proc_listing-available-scap-contents-using-cli.adoc +++ b/guides/common/modules/proc_listing-available-scap-contents-using-cli.adoc @@ -11,7 +11,7 @@ You can use Hammer CLI to view available SCAP contents. * Your user account has a role assigned that has the `view_scap_contents` permission. .Procedure -* Run the following Hammer command on {ProjectServer}: +* List SCAP contents on {ProjectServer}: + [options="nowrap", subs="+quotes,attributes,verbatim"] ---- diff --git a/guides/common/modules/proc_loading-the-default-scap-contents.adoc b/guides/common/modules/proc_loading-the-default-scap-contents.adoc index 8a397364269..4ba24523e8d 100644 --- a/guides/common/modules/proc_loading-the-default-scap-contents.adoc +++ b/guides/common/modules/proc_loading-the-default-scap-contents.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: PROCEDURE -[id="Loading_the_Default_SCAP_Contents_{context}"] +[id="Loading_the_Default_SCAP_Contents"] = Loading the default SCAP contents [role="_abstract"] diff --git a/guides/common/modules/proc_remediating-compliance-failures.adoc b/guides/common/modules/proc_remediating-compliance-failures.adoc index 5f8bd8df832..e3e27b3b24f 100644 --- a/guides/common/modules/proc_remediating-compliance-failures.adoc +++ b/guides/common/modules/proc_remediating-compliance-failures.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: PROCEDURE -[id="remediating-compliance-failures_{context}"] +[id="remediating-compliance-failures"] = Remediating compliance failures [role="_abstract"] diff --git a/guides/common/modules/proc_running-a-security-compliance-scan-on-demand.adoc b/guides/common/modules/proc_running-a-security-compliance-scan-on-demand.adoc index 2bed87e0688..a169ff9fed1 100644 --- a/guides/common/modules/proc_running-a-security-compliance-scan-on-demand.adoc +++ b/guides/common/modules/proc_running-a-security-compliance-scan-on-demand.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: PROCEDURE -[id="running-a-security-compliance-scan-on-demand_{context}"] +[id="running-a-security-compliance-scan-on-demand"] = Running a security compliance scan on demand [role="_abstract"] @@ -10,7 +10,7 @@ However, you can also run a scan on a host for all configured compliance policie .Prerequisites * Your user account has a role assigned that has the `view_hosts`, `create_job_invocations`, and `view_job_invocations` permissions. * You have created a compliance policy and deployed it on the host. -** For more information about managing policies, see xref:Managing_Compliance_Policies_{context}[]. +** For more information about managing policies, see xref:Managing_Compliance_Policies[]. ** For more information about deploying policies, see xref:deploying-compliance-policies_{context}[]. .Procedure diff --git a/guides/common/modules/proc_searching-compliance-reports.adoc b/guides/common/modules/proc_searching-compliance-reports.adoc index 492bebb14de..5c03b7965d9 100644 --- a/guides/common/modules/proc_searching-compliance-reports.adoc +++ b/guides/common/modules/proc_searching-compliance-reports.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: PROCEDURE -[id="Searching_Compliance_Reports_{context}"] +[id="Searching_Compliance_Reports"] = Searching compliance reports [role="_abstract"] @@ -20,36 +20,42 @@ However, you can use multiple fields in a single search expression. .Search query examples ==== Find all compliance reports for which more than five rules failed: + [options="nowrap", subs="+quotes,verbatim,attributes"] ---- failed > 5 ---- Find all compliance reports created after January 1, 2023, for hosts with hostnames that contain `prod-`: + [options="nowrap", subs="+quotes,verbatim,attributes"] ---- host ~ prod- AND date > "Jan 1, 2023" ---- Find all reports generated by the `rhel7_audit` compliance policy from an hour ago: + [options="nowrap", subs="+quotes,verbatim,attributes"] ---- "1 hour ago" AND compliance_policy = date = "1 hour ago" AND compliance_policy = rhel7_audit ---- Find reports that pass an XCCDF rule: + [options="nowrap", subs="+quotes,verbatim,attributes"] ---- xccdf_rule_passed = xccdf_org.ssgproject.content_rule_firefox_preferences-auto-download_actions ---- Find reports that fail an XCCDF rule: + [options="nowrap", subs="+quotes,verbatim,attributes"] ---- xccdf_rule_failed = xccdf_org.ssgproject.content_rule_firefox_preferences-auto-download_actions ---- Find reports that have a result different than fail or pass for an XCCDF rule: + [options="nowrap", subs="+quotes,verbatim,attributes"] ---- xccdf_rule_othered = xccdf_org.ssgproject.content_rule_firefox_preferences-auto-download_actions diff --git a/guides/common/modules/proc_uploading-additional-scap-content-using-cli.adoc b/guides/common/modules/proc_uploading-additional-scap-content-using-cli.adoc index 714641cf0e9..5af3496fbf0 100644 --- a/guides/common/modules/proc_uploading-additional-scap-content-using-cli.adoc +++ b/guides/common/modules/proc_uploading-additional-scap-content-using-cli.adoc @@ -23,11 +23,12 @@ endif::[] .Procedure . Place the SCAP data-stream file to a directory on your {ProjectServer}, such as `_/usr/share/xml/scap/my_content/_`. -. Run the following Hammer command on {ProjectServer}: +. On {ProjectServer}, upload the additional SCAP contents: + [options="nowrap", subs="+quotes,attributes,verbatim"] ---- -$ hammer scap-content bulk-upload --type directory \ +$ hammer scap-content bulk-upload +--type directory \ --directory _/usr/share/xml/scap/my_content/_ \ --location "_My_Location_" \ --organization "_My_Organization_" diff --git a/guides/common/modules/proc_uploading-additional-scap-content-using-web-ui.adoc b/guides/common/modules/proc_uploading-additional-scap-content-using-web-ui.adoc index 0940e981b1c..7d36928dbd4 100644 --- a/guides/common/modules/proc_uploading-additional-scap-content-using-web-ui.adoc +++ b/guides/common/modules/proc_uploading-additional-scap-content-using-web-ui.adoc @@ -4,7 +4,7 @@ = Uploading additional SCAP content using {ProjectWebUI} [role="_abstract"] -You can upload additional SCAP content into {ProjectServer}, either content created by yourself or obtained elsewhere. +You can upload additional SCAP contents into {ProjectServer}, either content created by yourself or obtained elsewhere. ifndef::satellite[] For example, you can get the latest OpenSCAP contents for additional systems from the https://github.com/ComplianceAsCode/content/releases[SSG GitHub repository]. endif::[] @@ -12,7 +12,7 @@ endif::[] ifdef::satellite[] [NOTE] ==== -{Team} only provides support for SCAP content obtained from {Team}. +{Team} only provides support for SCAP contents obtained from {Team}. ==== endif::[] @@ -30,4 +30,4 @@ endif::[] . Click *Submit*. .Verification -* If the SCAP content file is loaded successfully, a message similar to `Successfully created _My SCAP Content_` is displayed. +* If the SCAP contents file is loaded successfully, a message similar to `Successfully created _My SCAP Content_` is displayed. diff --git a/guides/common/modules/proc_viewing-a-compliance-policy.adoc b/guides/common/modules/proc_viewing-a-compliance-policy.adoc index f6f2ac6809b..8672d220472 100644 --- a/guides/common/modules/proc_viewing-a-compliance-policy.adoc +++ b/guides/common/modules/proc_viewing-a-compliance-policy.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: PROCEDURE -[id="Viewing_a_Compliance_Policy_{context}"] +[id="Viewing_a_Compliance_Policy"] = Viewing a compliance policy [role="_abstract"] diff --git a/guides/common/modules/proc_viewing-compliance-policy-statistics.adoc b/guides/common/modules/proc_viewing-compliance-policy-statistics.adoc index 0906f56aa5e..a22546e2d9c 100644 --- a/guides/common/modules/proc_viewing-compliance-policy-statistics.adoc +++ b/guides/common/modules/proc_viewing-compliance-policy-statistics.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: PROCEDURE -[id="Viewing_Compliance_Policy_Statistics_{context}"] +[id="Viewing_Compliance_Policy_Statistics"] = Viewing compliance policy statistics [role="_abstract"] diff --git a/guides/common/modules/ref_inclusion-of-remote-scap-resources.adoc b/guides/common/modules/ref_inclusion-of-remote-scap-resources.adoc index 3c4d06a83b4..6aed8f6dbe3 100644 --- a/guides/common/modules/ref_inclusion-of-remote-scap-resources.adoc +++ b/guides/common/modules/ref_inclusion-of-remote-scap-resources.adoc @@ -1,6 +1,6 @@ :_mod-docs-content-type: REFERENCE -[id="inclusion-of-remote-scap-resources_{context}"] +[id="inclusion-of-remote-scap-resources"] = Inclusion of remote SCAP resources [role="_abstract"]