20장. Security


The following chapters contain the most notable changes to security between RHEL 9 and RHEL 10.

20.1. Security compliance changes

Installation hardening with OSCAP Anaconda Addon removed

The oscap-anaconda-addon package has been removed. As a consequence, the RHEL 10 installer no longer provides the Security Policy spoke and installation hardening. RHEL 10 introduces a more flexible and customizable approach to hardening systems by using Anaconda and Kickstart in addition to the already existing Image Builder option. For more information, see Creating pre-hardened images with RHEL image builder OpenSCAP integration.

OpenSCAP

The new version 1.4.x of the OpenSCAP scanner is provided in RHEL 10. The most important changes are the following:

  • The openscap package no longer provides the openscap-devel subpackage for the libopenscap library, which is now an internal library without public API and any guarantee for backward compatibility. The openscap package is provided with no guarantee of ABI and API compatibility.
  • The following ds submodules that provide data stream composing functions have been removed from the oscap tool:

    • sds-compose
    • sds-add
    • sds-split
    • rds-create
    • rds-split
  • The following incomplete modules have been removed:

    • cve
    • cvss
    • cvrf
  • The following deprecated command-line options have been removed:

    • --template
    • --oval-template
    • --sce-template
    • --skip-valid is removed and is replaced by --skip-validation
  • New Kickstart remediation type was added.
  • The autotailor tool now can produce XCCDF tailoring files based on JSON Tailoring.

SCAP Workbench

The scap-workbench package with the SCAP Workbench GUI utility has been removed. As alternatives, you can use the oscap and autotailor command-line tools or Red Hat Lightspeed for both tailoring and scanning. For more information, see Managing SCAP security policies in the Red Hat Lightspeed compliance service.

SCAP Security Guide

The scap-security-guide package does not contain the following profiles:

  • Protection Profile for General Purpose Operating Systems (OSPP)
  • Centro Criptológico Nacional (CCN) - Basic
  • Centro Criptológico Nacional (CCN) - Intermediate

For the complete list of profiles supported in RHEL 10, see SCAP security profiles supported in RHEL 10.

Red Hat logoGithubredditYoutubeTwitter

자세한 정보

평가판, 구매 및 판매

커뮤니티

Red Hat 소개

Red Hat은 기업이 핵심 데이터 센터에서 네트워크 에지에 이르기까지 플랫폼과 환경 전반에서 더 쉽게 작업할 수 있도록 강화된 솔루션을 제공합니다.

보다 포괄적 수용을 위한 오픈 소스 용어 교체

Red Hat은 코드, 문서, 웹 속성에서 문제가 있는 언어를 교체하기 위해 최선을 다하고 있습니다. 자세한 내용은 다음을 참조하세요.Red Hat 블로그.

Red Hat 문서 정보

Legal Notice

Theme

© 2026 Red Hat
맨 위로 이동