OpenScap and RH Satellite questions
Hi we are just getting our feet wet with oscap. Our server estate consists of all RHEL server 6.7 systems and we need a way to automate the oscap scans using a central mgmt. server. Upon reading it seems like we are going to need RH Satellite in order to do this. If this is true then I have a few high level questions.
1) If we stand up Satellite server would the remote systems need to run some sort of Satellite agent (capsule server?) or would we just need to install spacewalk-oscap on the systems? I ask because this documentation below in section 8.4 talks about spacewalk-oscap.
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html-single/Security_Guide/index.html#chap-Compliance_and_Vulnerability_Scanning
However the link below talks about some sort of "satellite capsule server", which, I assume, is something that gets installed on the systems to be managed by Satellite.
https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/6.1/html/Installation_Guide/sect-Red_Hat_Satellite-Installation_Guide-Red_Hat_Satellite_Capsule_Server_Prerequisites.html
2) What do I need to know if we are also using puppet? Are the 2 environments compatible? We are running puppet 3.8.3. The doc above in section 1.4.1 below talks about how the Satellite server must not have any puppet RPMS installed. However there is more documentation down the line on how these 2 co-exist in the same environment. So I am a bit confused.
Any guidance is much appreciated thanks!
Responses