This lab article closes a practical gap in the SUSE series: it does not stop at installing SLES 16, but shows how a managed SLES 16 system behaves when OpenSCAP content, hardening profiles, remediation and SUSE Multi-Linux Manager lifecycle channels meet in practice.
The important finding is deliberately precise: CIS publishes a benchmark for SUSE Linux Enterprise 16, but the SUSE-provided scap-security-guide package in this lab exposes ANSSI, HIPAA, PCI-DSS and base profiles for SLE 16, not a ready-made CIS Level 2 profile. Therefore this article documents an ANSSI-BP-028 high run and explains how CIS Level 2 must be handled separately and honestly.
Why CIS, OpenSCAP and Hardening Matter
CIS Benchmarks are vendor- and community-maintained security baselines. They translate common operating-system hardening questions into concrete checks: password policy, SSH behavior, sudo restrictions, file permissions, audit rules, kernel parameters and logging. In practice they are useful because security teams, auditors and operations teams can discuss the same baseline instead of comparing vague hardening opinions.
OpenSCAP is tooling for evaluating machine-readable SCAP content. The oscap command can scan a system, generate an HTML report and, depending on the profile, create remediation in Bash or Ansible form. That makes hardening repeatable: first measure, then change deliberately, then scan again and document exceptions.
SUSE Multi-Linux Manager adds the operational layer around that workflow. Packages, profiles, remediation runs and evidence do not live on an isolated test machine, but inside the same lifecycle, proxy and channel model that also supplies updates to production servers. That is why this article checks the manager and channel path before looking at the score.
Concepts at a glance
| Term | Meaning | Why it matters |
|---|---|---|
| CIS Benchmark | A published hardening baseline for a product or platform | Creates a shared technical and audit reference |
| CIS Level 1 | Usually a practical baseline with lower operational impact | Good starting point for broadly used systems |
| CIS Level 2 | Stricter baseline with more potential operational impact | Needs workload testing and documented exceptions |
| SCAP | Machine-readable security content and result format | Allows automated scans and comparable evidence |
| OpenSCAP / oscap | Scanner and reporting tooling for SCAP content | Turns profiles into repeatable checks and reports |
| Remediation | Generated or manual changes to satisfy failed rules | Must be reviewed before production rollout |
CIS Benchmark
- Meaning
- A published hardening baseline for a product or platform
- Why it matters
- Creates a shared technical and audit reference
CIS Level 1
- Meaning
- Usually a practical baseline with lower operational impact
- Why it matters
- Good starting point for broadly used systems
CIS Level 2
- Meaning
- Stricter baseline with more potential operational impact
- Why it matters
- Needs workload testing and documented exceptions
SCAP
- Meaning
- Machine-readable security content and result format
- Why it matters
- Allows automated scans and comparable evidence
OpenSCAP / oscap
- Meaning
- Scanner and reporting tooling for SCAP content
- Why it matters
- Turns profiles into repeatable checks and reports
Remediation
- Meaning
- Generated or manual changes to satisfy failed rules
- Why it matters
- Must be reviewed before production rollout
Lab Setup
Systems used
| Component | Role | Evidence |
|---|---|---|
| mlm01.example.test | SUSE Multi-Linux Manager 5.2 | Manager UI, channel assignment and registered system view |
| mgrproxy01.example.test | MLM proxy between manager and client | Client repositories were served through the proxy URL |
| sles16-client01.example.test | SLES 16 managed client | OpenSCAP scan target and remediation target |
mlm01.example.test
- Role
- SUSE Multi-Linux Manager 5.2
- Evidence
- Manager UI, channel assignment and registered system view
mgrproxy01.example.test
- Role
- MLM proxy between manager and client
- Evidence
- Client repositories were served through the proxy URL
sles16-client01.example.test
- Role
- SLES 16 managed client
- Evidence
- OpenSCAP scan target and remediation target
The SLES 16 client was reachable through the proxy, registered in SUSE Multi-Linux Manager and assigned to a production lifecycle channel. That is intentionally close to a customer rollout: the compliance workflow must work through the same package and proxy path that normal operations use.
Channel Readiness Before Hardening
The first check was not an OpenSCAP scan. It was package availability on the managed client. A hardening guide is not useful if the client cannot install the scanner and the security guide from its assigned lifecycle channel.
zypper refreshzypper se -s openscap scap-security-guiderpm -q openscap openscap-utils libopenscap33 scap-security-guide
In the lab, the production channel assigned to the client did not expose all OpenSCAP packages even though the manager already had them in other synchronized SLES 16 channels. This is a realistic lifecycle-management issue: cloned channels can be too narrow or stale. Fix the channel content before scheduling scans at scale.
Package readiness
| Package | Purpose | Finding |
|---|---|---|
| openscap-utils | Provides oscap CLI tooling | Required for local scan and report generation |
| scap-security-guide | Provides SLE 16 datastream content | Required for supported profiles |
| libopenscap33 | Runtime library | Dependency of OpenSCAP tools |
| libexslt0 / libxmlsec1-openssl1 | XML and signature support | Dependency gap surfaced during package installation |
openscap-utils
- Purpose
- Provides oscap CLI tooling
- Finding
- Required for local scan and report generation
scap-security-guide
- Purpose
- Provides SLE 16 datastream content
- Finding
- Required for supported profiles
libopenscap33
- Purpose
- Runtime library
- Finding
- Dependency of OpenSCAP tools
libexslt0 / libxmlsec1-openssl1
- Purpose
- XML and signature support
- Finding
- Dependency gap surfaced during package installation
Available SLES 16 Profiles
oscap info /usr/share/xml/scap/ssg/content/ssg-sle16-ds.xml
Profile result
| Profile | Status in this lab | Operational interpretation |
|---|---|---|
| ANSSI-BP-028 minimal/intermediary/enhanced/high | Available | Usable for automated SLE 16 OpenSCAP evidence |
| HIPAA | Available | Useful for healthcare-aligned baseline checks |
| PCI-DSS 4.0.1 | Available | Useful where cardholder-data environments are relevant |
| CIS Level 1 / Level 2 | Not exposed by the installed SSG datastream | Use CIS benchmark/CIS-CAT/Build Kit or a validated tailored profile instead |
ANSSI-BP-028 minimal/intermediary/enhanced/high
- Status in this lab
- Available
- Operational interpretation
- Usable for automated SLE 16 OpenSCAP evidence
HIPAA
- Status in this lab
- Available
- Operational interpretation
- Useful for healthcare-aligned baseline checks
PCI-DSS 4.0.1
- Status in this lab
- Available
- Operational interpretation
- Useful where cardholder-data environments are relevant
CIS Level 1 / Level 2
- Status in this lab
- Not exposed by the installed SSG datastream
- Operational interpretation
- Use CIS benchmark/CIS-CAT/Build Kit or a validated tailored profile instead
Baseline Scan
mkdir -p /root/openscap-evidence/sles16-hardening-20261006oscap xccdf eval \--profile xccdf_org.ssgproject.content_profile_anssi_bp28_high \--results /root/openscap-evidence/sles16-hardening-20261006/anssi-high-results.xml \--report /root/openscap-evidence/sles16-hardening-20261006/anssi-high-report.html \/usr/share/xml/scap/ssg/content/ssg-sle16-ds.xml
Baseline result
| Result | Count | Meaning |
|---|---|---|
| PASS | 156 | Controls already fulfilled by the installed system |
| FAIL | 216 | Rules requiring remediation or design decisions |
| NOT APPLICABLE | 24 | Rules not applicable to this target |
| NOT CHECKED | 1 | Rule not evaluated automatically |
PASS
- Count
- 156
- Meaning
- Controls already fulfilled by the installed system
FAIL
- Count
- 216
- Meaning
- Rules requiring remediation or design decisions
NOT APPLICABLE
- Count
- 24
- Meaning
- Rules not applicable to this target
NOT CHECKED
- Count
- 1
- Meaning
- Rule not evaluated automatically
Controlled Remediation
Before applying remediation, the VM was snapshotted. This is not optional for high-hardening profiles. Partitioning, sudo, audit, PAM, SSH and kernel settings can affect access and operations immediately.
virsh snapshot-create-as \--domain sles16-client01 \--name before-openscap-anssi-high-20261006 \--description "Before SLES16 OpenSCAP ANSSI high remediation evidence run" \--disk-only --atomic --no-metadataoscap xccdf generate fix --fix-type bash \--profile xccdf_org.ssgproject.content_profile_anssi_bp28_high \--output anssi-high-remediation.sh \anssi-high-results.xmloscap xccdf generate fix --fix-type ansible \--profile xccdf_org.ssgproject.content_profile_anssi_bp28_high \--output anssi-high-remediation.yml \anssi-high-results.xml
The remediation script completed, but the log also showed realistic limits: some packages could not be reinstalled from the assigned repositories, one SSSD PAM remediation was missing, and sudo was hardened with requiretty, noexec, use_pty and umask. That is exactly why remediation belongs into a tested maintenance workflow instead of a blind one-liner.
Before and after
| Metric | Before remediation | After remediation |
|---|---|---|
| PASS | 156 | 261 |
| FAIL | 216 | 101 |
| ERROR | 0 | 10 |
| Score | not used as release gate | 79.57 percent in the generated report |
PASS
- Before remediation
- 156
- After remediation
- 261
FAIL
- Before remediation
- 216
- After remediation
- 101
ERROR
- Before remediation
- 0
- After remediation
- 10
Score
- Before remediation
- not used as release gate
- After remediation
- 79.57 percent in the generated report
What This Means for CIS Level 2
Do not rename an ANSSI high scan to CIS Level 2. If a customer requires CIS Level 2 for SLES 16, the correct path is to obtain the CIS SLE 16 benchmark content, run it with CIS-CAT Pro or a validated tailored SCAP workflow, document local exceptions and keep the evidence tied to the actual benchmark version.
Technical acceptance
| Check | Result | Comment |
|---|---|---|
| Client managed by MLM | PASS | sles16-client01.example.test visible and current in MLM |
| Proxy path used | PASS | Client repositories were served through mgrproxy01.example.test |
| OpenSCAP package readiness | PASS WITH FINDING | Packages existed on the manager, but lifecycle channel content needed attention |
| SLE 16 SSG profile discovery | PASS | ANSSI, HIPAA, PCI-DSS and base profiles listed |
| CIS Level 2 automation | NOT CLAIMED | CIS benchmark exists, but no CIS profile was present in the installed SUSE SSG datastream |
| Remediation | PASS WITH CONDITIONS | Improved results, but repository and sudo/noexec effects require operational review |
Client managed by MLM
- Result
- PASS
- Comment
- sles16-client01.example.test visible and current in MLM
Proxy path used
- Result
- PASS
- Comment
- Client repositories were served through mgrproxy01.example.test
OpenSCAP package readiness
- Result
- PASS WITH FINDING
- Comment
- Packages existed on the manager, but lifecycle channel content needed attention
SLE 16 SSG profile discovery
- Result
- PASS
- Comment
- ANSSI, HIPAA, PCI-DSS and base profiles listed
CIS Level 2 automation
- Result
- NOT CLAIMED
- Comment
- CIS benchmark exists, but no CIS profile was present in the installed SUSE SSG datastream
Remediation
- Result
- PASS WITH CONDITIONS
- Comment
- Improved results, but repository and sudo/noexec effects require operational review
Operational Checklist
For production, treat this as a controlled change: verify channel contents, snapshot or backup first, run a baseline scan, review the generated remediation, apply in a maintenance window, re-scan, document exceptions and only then define whether the system is compliant enough for the intended workload.



