Oracle Linux 8 hardening with CIS security policy

644 Views Asked by At

I am trying to harden an existing Oracle Linux 8 OS with OpenSCAP CISv2 but there is no available bash scripts that can automate this compared to RHEL8.

In Oracle Linux 8 I was told to install OpenSCAP packages. sudo dnf install openscap openscap-utils scap-security-guide Once installed, a list of bash scripts will be available in "/usr/share/scap-security-guide/bash/" where users can run their choice of security policies. Unfortunately for Oracle Linux 8, there isn't any available CIS security policy as compared to RHEL8.

I've also tried to extract the CIS bash script from RHEL 8 and have it executed on Oracle Linux 8 but most portions of it would not work due to missing packages or repo. There might be other errors that I've might missed out but moving forward I am uncertain if remediating this is the way to continue, due to the amount of changes that is required, in order for the bash script to run perfectly.

I've seen OpenSCAP documenting a CIS v2 on Oracle Linux 8 but I've yet to find something that can automate the installation of CIS security policy unlike RHEL 8. Is there anyway to attain a bash script that would allow me to automate the installation of CIS security policy to existing Oracle Linux 8?

Any help will be much appreciated.

Thanks!

0

There are 0 best solutions below