Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 225065 - [ebuild request] app-misc/ovaldi Open Vulnerability and Assessment Language reference interpreter
Summary: [ebuild request] app-misc/ovaldi Open Vulnerability and Assessment Language r...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Default Assignee for New Packages
URL: http://oval.mitre.org/language/downlo...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-06-05 22:59 UTC by Anton Bolshakov
Modified: 2011-06-16 09:27 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
ovaldi with newest release (ovaldi-5.4.2.ebuild,2.12 KB, text/plain)
2008-06-06 18:25 UTC, Mike Weissman
Details
updated ovaldi ebuild (ovaldi-5.4.2-r1.ebuild,2.22 KB, text/plain)
2008-06-12 20:23 UTC, Mike Weissman
Details
ovaldi-5.5.4.ebuild (ovaldi-5.5.4.ebuild,2.22 KB, text/plain)
2008-12-23 03:30 UTC, Anton Bolshakov
Details
ovaldi-5.6.1.ebuild (ovaldi-5.6.1.ebuild,2.22 KB, text/plain)
2009-09-10 21:31 UTC, Anton Bolshakov
Details
ovaldi-5.8.2.ebuild (ovaldi-5.8.2-r1.ebuild,1.55 KB, text/plain)
2010-12-09 16:32 UTC, Anton Bolshakov
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Anton Bolshakov 2008-06-05 22:59:38 UTC
The OVAL Interpreter is a freely available reference implementation created to show how information can be collected from a computer for testing, to evaluate and carry out the OVAL Definitions for that platform, and to report the results of the tests. 

OVAL-interpreter also has been included in Debian’s Ubuntu 8.04 recently:
http://packages.debian.org/source/testing/oval-interpreter
Comment 1 Mike Weissman 2008-06-06 18:25:27 UTC
Attaching an ebuild that uses src download from sourceforge. Build and Functionality working in x86  need testing for amd64.  
Comment 2 Mike Weissman 2008-06-06 18:25:49 UTC
Created attachment 155741 [details]
ovaldi with newest release
Comment 3 Anton Bolshakov 2008-06-07 01:45:50 UTC
Thanks. I've uploaded it to my security tools overlay and also available from the following url directly:
http://gentoo.o0o.nu/portage/app-misc/ovaldi/
Comment 4 Mike Weissman 2008-06-12 19:22:00 UTC
Testing and working on x86_64.
Comment 5 Mike Weissman 2008-06-12 20:22:32 UTC
After testing this a few times, i am going to make some changes to the ebuild, because ovaldi occasionally seems to have problems finding the xsl and xsd files. 
Noticed this was an issue on a clean chroot install doing a QA run.  

Please update with the new ebuild, attached.  Sorry for the over site. 

-Mike
Comment 6 Mike Weissman 2008-06-12 20:23:12 UTC
Created attachment 156543 [details]
updated ovaldi ebuild

fixed some QA issues with xsd and xsl files
Comment 7 Anton Bolshakov 2008-12-23 03:30:09 UTC
Created attachment 176191 [details]
ovaldi-5.5.4.ebuild

openvas 2.0 can optionally use it, so a maintainer of it might be interested to push ovaldi to the portage.
Comment 8 Anton Bolshakov 2009-09-10 21:31:08 UTC
Created attachment 203729 [details]
ovaldi-5.6.1.ebuild
Comment 9 montjoie 2010-12-08 08:19:24 UTC
This is now in the sunrise overlay. You can find it at:
http://overlays.gentoo.org/proj/sunrise/browser/sunrise/app-forensics/ovaldi/ovaldi-5.8.2.ebuild
Comment 10 Anton Bolshakov 2010-12-08 11:02:43 UTC
(In reply to comment #9)
I don't think this is a forensic app.

btw, I've joined pentoo, so the ebuild is also available via pentoo overlay:
http://trac.pentoo.ch/browser/portage/trunk/app-misc/ovaldi

Comment 11 montjoie 2010-12-08 16:42:18 UTC
I think you havent tried to install the ebuild in your overlay because ovaldi 5.8.2 wont compile with xerces3 (the only version available in gentoo) without patching.
And your ebuild have several QA issues (not using mirror, parallel compilation bug, etc))
Try to test it with repoman.

I dont understand why ovaldi is not a forensic tool, it collects and audit informations according to patterns defined in a xml file.
Comment 12 Anton Bolshakov 2010-12-08 17:07:39 UTC
(In reply to comment #11)
> I think you havent tried to install the ebuild in your overlay because ovaldi
> 5.8.2 wont compile with xerces3 (the only version available in gentoo) without
> patching.

Thanks, I haven't. I'll fix that too once I have my test environment back.

> I dont understand why ovaldi is not a forensic tool, it collects and audit
> informations according to patterns defined in a xml file.

yes, but xml files cover "compliance | inventory | patch | vulnerability | miscellaneous" which falls more under host hardening.
Comment 13 Anton Bolshakov 2010-12-09 16:32:45 UTC
Created attachment 256737 [details]
ovaldi-5.8.2.ebuild

montjoie, thanks for the hard work. Here is your ebuild with adjusted dependency list. Apparently, openldap is mandatory.
Comment 14 montjoie 2010-12-13 08:02:24 UTC
I confirm that dev-libs/libgcrypt is mandatory.
For openldap i made it optionnal via an use flag and a patch.
Updated ebuild is in sunrise
Comment 15 Markos Chandras (RETIRED) gentoo-dev 2011-06-16 09:27:40 UTC
On tree. Thanks