5.3. Managing Compliance Policies
5.3.1. Creating a Policy Copy linkLink copied to clipboard!
Copy linkLink copied to clipboard!
Follow these steps to create a compliance policy, which specifies the SCAP content and profile to be applied to a location and either a host or host group at a specified time.
Prerequisites
Procedure 5.5. To Create a Policy:
- In the Satellite web UI, navigate to
, click and follow the wizard’s steps. - Enter a name for this policy, a description (optional), then click .
- Select the SCAP Content and XCCDF Profile to be applied, then click .
- Specify the scheduled time when the policy is to be applied, then click .Select , , or from the Period drop-down list.
- If you select , also select the desired day of the week from the drop-down list.
- If you select , also specify the desired day of the month in the Day of month field.
- If you select , enter a valid Cron expression in the Cron line field.
The option allows for greater flexibility in the policy's schedule than either the or options. - Select the locations to which the policy is to be applied, then click .
- Select the organizations to which the policy is to be applied, then click .
- Select the host groups to which the policy is to be applied, then click .
- Click .
When the Puppet agent runs on the hosts which belong to the selected host group, or hosts to which the policy has been applied, the OpenSCAP client will be installed and a Cron job added with the policy's specified schedule. The
SCAP Content tab provides the name of the SCAP content file which will be distributed to the directory /var/lib/openscap/content/ on all target hosts.
5.3.2. Viewing a Policy Copy linkLink copied to clipboard!
Copy linkLink copied to clipboard!
Follow these steps to preview the rules which will be applied by specific OpenSCAP content and profile combination. This is useful when planning policies.
Procedure 5.6. To View a Policy:
- In the Satellite web UI, navigate to
. - Click .
5.3.3. Editing a Policy Copy linkLink copied to clipboard!
Copy linkLink copied to clipboard!
Follow these steps to edit a policy. An edited policy is applied to the host when its Puppet agent next checks with the Satellite Server for updates. By default this occurs every 30 minutes.
Procedure 5.7. To Edit a Policy:
- In the Satellite web UI, navigate to
. - From the drop-down list to the right of the policy's name, select .
- Edit the necessary attributes.
- Click .
An edited policy is applied to the host when its Puppet agent next checks with the Satellite Server for updates. By default this occurs every 30 minutes.
5.3.4. Deleting a Policy Copy linkLink copied to clipboard!
Copy linkLink copied to clipboard!
Follow these steps to delete an existing policy.
- In the Satellite web UI, navigate to
. - From the drop-down list to the right of the policy's name, select .
- Click in the confirmation message.
5.3.5. Adding a Policy to a Host Copy linkLink copied to clipboard!
Copy linkLink copied to clipboard!
Follow these steps to add a policy to one or more hosts.
- In the Satellite web UI, navigate to
. - Select the host or hosts to which you want to add the policy.
- Click .
- In the new panel that opens, select the appropriate policy from the list of available policies and click .