Scanning the Linux infrastructure with OSCAP

As we discussed earlier in this chapter, the oscap tool is a command-line utility designed for scanning the local machine that it is installed on. The security policies that you wish to audit the host against must also be on the filesystem of the host that it runs on. If you have completed the steps in the section entitled Evaluating and selecting policies, then you should already have everything you need.

With that said, if using the oscap tool to scan your infrastructure is going to be your way forward, you may wish to consider Ansible as a tool to both install it and gather the results when the scan is complete.

Before we come to this, let's look at how we might scan a single host:

  1. Assuming ...

Get Hands-On Enterprise Automation on Linux now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.