Referencing the following document:
When the scan is generated using the following command, how did you determine to select “stig” as the --profile option? When I run the “info” command on the ssg-rl8-ds.xml file, “stig” is not listed under profiles.
“sudo oscap xccdf eval --report unit-test-disa-scan.html --profile stig /usr/share/xml/scap/ssg/content/ssg-rl8-ds.xml”
I tried the same command using a benchmark file from cyber.mil, and it failed unless I selected an actual profile listed within the xml file.
Youd look at the value after the profile section, so if you look at these
oscap info /usr/share/xml/scap/ssg/content/ssg-rl8-ds.xml
(trimmed for viewability)
Title: DISA STIG for Red Hat Enterprise Linux 8
Title: DISA STIG with GUI for Red Hat Enterprise Linux 8
the part you cut off from that is following the profile_ in the Id: section, so the values are “stig” and “stig_gui” respectively. You should see a pretty big list of from info, if you arent you may have a bad /usr/share/xml/scap/ssg/content/ssg-rl8-ds.xml