[Satellite 6] How to SCAP scan the Satellite server?
Issue
- How to SCAP scan the Satellite server?
The Satellite server was previously registered to itself to be able to scan openscap.
But since self-registered Satellite is not supported, it is registered back to the Customer Portal.
The SCAP Scan failed with:
fatal: [SAT6_FQDN]: FAILED! => {"changed": true, "cmd": "/usr/bin/foreman_scap_client 6", "delta": "0:01:15.886305", "end": "2025-06-25 12:53:20.168637", "msg": "non-zero return code", "rc": 4, "start": "2025-06-25 12:52:04.282332", "stderr": "", "stderr_lines": [], "stdout": "DEBUG: running: oscap xccdf eval
:
:
"Uploading results to https://SAT6_FQDN:9090/compliance/arf/6", "Upload failed: curl: (60) SSL certificate problem: unable to get local issuer certificate", "More details here: https://curl.haxx.se/docs/sslcerts.html", "", "curl failed to verify the legitimacy of the server and therefore could not", "establish a secure connection to it. To learn more about this situation and", "how to fix it, please visit the web page mentioned above."]}
- How to configure foreman_scap_client on Satellite server?
Environment
- Red Hat Satellite Server 6.16 and above
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.