Project

General

Profile

Actions

action #78224

closed

[sle][security][sle15sp3] Integrate the Lynis scanner into OpenQA

Added by llzhao over 3 years ago. Updated over 2 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
New test
Target version:
-
Start date:
2020-11-19
Due date:
% Done:

100%

Estimated time:
(Total: 120.00 h)
Difficulty:
medium

Description

This poo is a parent poo.

Requirements from developer:

One idea would be to include lynis into openQA. This is something we wanted
to do for a long time, but never found the time to do it. So if you have
the time and expertise to include this into openQA this would be great.

We would still use this in our product testing, but having some regular
baseline testing would be interesting. If you're interested have one of the
engineers make themselves familiar with lynis. Lynis offers various output
formats and it probably make sense to check them out and chose one of the
machine readable formats well suited for automation. I think we should
cover these cases:

  • Ensure that tests that we pass don't change into negatives
  • Ensure that newly added test to lynis don't fail

The engineer will need to figure out a good balance between catching issues
and not being to rigid with the test output. It doesn't make sense to match
on an exact lynis output since this will likely change. But we could e.g.
match the high level result returned at the end of an run, that looked
rather stable to me

links:
https://cisofy.com/lynis/


Subtasks 4 (0 open4 closed)

action #78230: [sle][security][sle15sp3] Integrate Lynis into OpenQA - run lynis on Beta1 textmode image, analyse the report , create the Beta1 base lineResolvedllzhao2020-11-19

Actions
action #78330: [sle][security][sle15sp3] Integrate Lynis into OpenQA - find a suitable output format for openQA automation Resolvedllzhao2020-11-20

Actions
action #88155: [sle][security][sle15sp3] Integrate Lynis into OpenQA - setup env Resolvedllzhao2021-01-22

Actions
action #88894: [sle][security][sle15sp3] Integrate the Lynis scanner into OpenQA - phase 2Resolvedllzhao2021-02-22

Actions
Actions

Also available in: Atom PDF