16:00:04 #startmeeting Ansible Lockdown WG 16:00:04 Meeting started Thu Apr 4 16:00:04 2019 UTC. 16:00:04 This meeting is logged and archived in a public location. 16:00:04 The chair is shepdelacreme. Information about MeetBot at http://wiki.debian.org/MeetBot. 16:00:04 Useful Commands: #action #agreed #halp #info #idea #link #topic. 16:00:04 The meeting name has been set to 'ansible_lockdown_wg' 16:00:11 #chair cyberpear 16:00:11 Current chairs: cyberpear shepdelacreme 16:01:16 for once, no open PRs 16:01:30 I don't think there is much to discuss today. No open PRs on the RHEL7-STIG repo 16:01:32 haha 16:01:50 RHEL7-CIS has some open but they are awaiting some updates 16:01:51 but only because I didn't take a minute to implement #233 16:03:05 I'm still struggling with how to get the CIS benchmarks up to par with the STIG one 16:03:28 what do you mean by that? 16:03:43 docs, tests, etc 16:03:58 I like the idea behind what SSG is doing to auto-generate ansible roles from a common set of knowledge 16:04:04 I think functionally it is pretty good...needs some updates but it generally works 16:04:05 but they are not ansible experts 16:04:39 yeah the SSG roles are ok...they aren't great as far as being configurable though 16:05:26 I haven't been brave enough to actually run them, based on bad experiences w/ their bash remediations 16:05:40 In order to get the CIS benchmark docs built like the STIG role docs I would either need to parse PDFs of the CIS benchmarks or figure out a way to pull the CIS xccdfs 16:06:17 I think you were saying those are also not freely available? 16:06:20 also testing/verification is difficult because we don't have access to the xccdf stuff 16:07:02 yeah you have to pay for all the xccdf content and then you still don't have a license to redistribute them so putting them in a public repo is a non-starter 16:07:32 I'm sure as heck not interested in figuring out how to parse PDFs for that content though lol 16:08:24 oh and the base license cost for the CIS stuff would be $10k 16:10:28 would be nice if they had something free or reduced for OSS projects 16:12:37 yeah 16:13:50 alright well if no one has anything else this week we can end early? 16:14:22 that's all I've got for now. I'll send a PR later today. 16:14:27 thanks for your time! 16:14:37 thanks! 16:14:41 #endmeeting