<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Šimon Lukašík</title>
    <link>/</link>
    <description>Recent content on Šimon Lukašík</description>
    <generator>Hugo</generator>
    <language>en</language>
    <copyright>&lt;a href=&#34;https://creativecommons.org/licenses/by-nc/4.0/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CC BY-NC 4.0&lt;/a&gt;</copyright>
    <lastBuildDate>Mon, 13 Dec 2021 00:00:00 +0000</lastBuildDate>
    <atom:link href="/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>GoComply with OSCAL &amp; FedRAMP :: Introduction to fedramp</title>
      <link>/posts/2021/12/gocomply-with-oscal-fedramp-introduction-to-fedramp/</link>
      <pubDate>Mon, 13 Dec 2021 00:00:00 +0000</pubDate>
      <guid>/posts/2021/12/gocomply-with-oscal-fedramp-introduction-to-fedramp/</guid>
      <description>&lt;p&gt;This is the fifth and final post of the &lt;a href=&#34;/tags/gocomply/&#34;&gt;GoComply series&lt;/a&gt; that introduces open source pipeline to produce and process OSCAL and FedRAMP documents. If You want to achieve continuous compliance at the lowest possible cost, &lt;a href=&#34;https://github.com/gocomply&#34;&gt;GoComply project&lt;/a&gt; is here to help. With GoComply, You will rely on open source tooling and your data will be stored in standardized formats and thus you will have a enough head room and knee room to achieve your organizational goals.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GoComply with OSCAL &amp; FedRAMP :: Introduction to metaschema</title>
      <link>/posts/2020/12/gocomply-with-oscal-fedramp-introduction-to-metaschema/</link>
      <pubDate>Sat, 12 Dec 2020 00:00:00 +0000</pubDate>
      <guid>/posts/2020/12/gocomply-with-oscal-fedramp-introduction-to-metaschema/</guid>
      <description>&lt;p&gt;This is the fourth post of the &lt;a href=&#34;/tags/gocomply/&#34;&gt;GoComply series&lt;/a&gt; that introduces open source pipeline to produce and process OSCAL and FedRAMP documents. If You want to achieve continuous compliance at the lowest possible cost, &lt;a href=&#34;https://github.com/gocomply&#34;&gt;GoComply project&lt;/a&gt; is here to help. With GoComply, You will rely on open source tooling and your data will be stored in standardized formats and thus you will have a enough head room and knee room to achieve your organizational goals.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GoComply with OSCAL &amp; FedRAMP :: Introduction to oscalkit</title>
      <link>/posts/2020/12/gocomply-with-oscal-fedramp-introduction-to-oscalkit/</link>
      <pubDate>Fri, 11 Dec 2020 00:00:00 +0000</pubDate>
      <guid>/posts/2020/12/gocomply-with-oscal-fedramp-introduction-to-oscalkit/</guid>
      <description>&lt;p&gt;This is the third post of the &lt;a href=&#34;/tags/gocomply/&#34;&gt;GoComply series&lt;/a&gt; that introduces open source pipeline to produce and process OSCAL and FedRAMP documents. If You want to achieve continuous compliance at the lowest possible cost, &lt;a href=&#34;https://github.com/gocomply&#34;&gt;GoComply project&lt;/a&gt; is here to help. With GoComply, You will rely on open source tooling and your data will be stored in standardized formats and thus you will have a enough head room and knee room to achieve your organizational goals.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GoComply with OSCAL &amp; FedRAMP :: Introduction to OSCAL</title>
      <link>/posts/2020/12/gocomply-with-oscal-fedramp-introduction-to-oscal/</link>
      <pubDate>Thu, 10 Dec 2020 00:00:00 +0000</pubDate>
      <guid>/posts/2020/12/gocomply-with-oscal-fedramp-introduction-to-oscal/</guid>
      <description>&lt;p&gt;This is the second post of the &lt;a href=&#34;/tags/gocomply/&#34;&gt;GoComply series&lt;/a&gt; that introduces open source pipeline to produce and process OSCAL and FedRAMP documents. If You want to achieve continuous compliance at the lowest possible cost, &lt;a href=&#34;https://github.com/gocomply&#34;&gt;GoComply project&lt;/a&gt; is here to help. With GoComply, You will rely on open source tooling and your data will be stored in standardized formats and thus you will have a enough head room and knee room to achieve your organizational goals.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GoComply with OSCAL &amp; FedRAMP :: Introduction to OpenControl</title>
      <link>/posts/2020/12/gocomply-with-oscal-fedramp-introduction-to-opencontrol/</link>
      <pubDate>Tue, 08 Dec 2020 00:00:00 +0000</pubDate>
      <guid>/posts/2020/12/gocomply-with-oscal-fedramp-introduction-to-opencontrol/</guid>
      <description>&lt;p&gt;This is the first post of the &lt;a href=&#34;/tags/gocomply/&#34;&gt;GoComply series&lt;/a&gt; that introduces open source pipeline to produce and process OSCAL and FedRAMP documents. If You want to achieve continuous compliance at the lowest possible cost, &lt;a href=&#34;https://github.com/gocomply&#34;&gt;GoComply project&lt;/a&gt; is here to help. With GoComply, You will rely on open source tooling and your data will be stored in standardized formats and thus you will have a enough head room and knee room to achieve your organizational goals.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Red Hat adopts ROLIE protocol for automated exchange of security compliance assets</title>
      <link>/posts/2020/09/red-hat-adopts-rolie-protocol-for-automated-exchange-of-security-compliance-assets/</link>
      <pubDate>Wed, 30 Sep 2020 00:00:00 +0000</pubDate>
      <guid>/posts/2020/09/red-hat-adopts-rolie-protocol-for-automated-exchange-of-security-compliance-assets/</guid>
      <description>&lt;p&gt;Red Hat Blog has today published my post about Rolie protocol and its open source implementation Golie.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.redhat.com/en/blog/red-hat-adopts-rolie-protocol-automated-exchange-security-compliance-assets&#34;&gt;https://www.redhat.com/en/blog/red-hat-adopts-rolie-protocol-automated-exchange-security-compliance-assets&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;I hope you enjoy the reading. Feel free to follow up on &lt;a href=&#34;https://gitter.im/GoComply/community&#34;&gt;https://gitter.im/GoComply/community&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability scanning in disconnected environments</title>
      <link>/posts/2020/06/vulnerability-scanning-in-disconnected-environments/</link>
      <pubDate>Mon, 29 Jun 2020 00:00:00 +0000</pubDate>
      <guid>/posts/2020/06/vulnerability-scanning-in-disconnected-environments/</guid>
      <description>&lt;p&gt;In this post we will learn how to instruct OpenSCAP to build us a DataStream that does vulnerability scanning and yet it does not require internet connection to fetch the latest vulnerability feed.&lt;/p&gt;&#xA;&lt;h2 id=&#34;introduction-to-remote-references-in-scap&#34;&gt;Introduction to remote references in SCAP&lt;/h2&gt;&#xA;&lt;p&gt;An XCCDF file may contain references to remote content. That is useful in cases when we want scanners to fetch content from the remote location every time the scan is run. This may be beneficial in cases when the referenced context changes often and we always want to use the latest greatest version for scanning. Widely used example is vulnerability scanning. Consider the following snippet (or similar) that is part of any Red Hat Enterprise Linux guidance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSD2Go - Automatically generate golang xml parsers</title>
      <link>/posts/2020/05/xsd2go-automatically-generate-golang-xml-parsers/</link>
      <pubDate>Sat, 30 May 2020 00:00:00 +0000</pubDate>
      <guid>/posts/2020/05/xsd2go-automatically-generate-golang-xml-parsers/</guid>
      <description>&lt;p&gt;Did you ever need to write XML parser from scratch? You can have a parser ready in few minutes! Let me introduce you to &lt;a href=&#34;https://github.com/GoComply/xsd2go&#34;&gt;xsd2go&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-bother&#34;&gt;Why bother?&lt;/h2&gt;&#xA;&lt;p&gt;Most of my readers will probably have an experience with the wide spread XML applications like RSS or Atom feeds, SVG, XHTML. For those well known XML applications you will find good library encapsulating the parsing for you. You just include existing parser in your project and you are done with it. However, what would you do if you cannot use it (think of license mismatch), or what would you do if there was no parsing library at all?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Steps to set-up Yubikey authentication to FreeIPA</title>
      <link>/posts/2019/11/steps-to-set-up-yubikey-authentication-to-freeipa/</link>
      <pubDate>Mon, 25 Nov 2019 00:00:00 +0000</pubDate>
      <guid>/posts/2019/11/steps-to-set-up-yubikey-authentication-to-freeipa/</guid>
      <description>&lt;p&gt;This post presents happy path (or reference architecture). The aim is to provide&#xA;reproducible steps to configure functioning smart card environment.&lt;/p&gt;&#xA;&lt;p&gt;There are multiple ways to set-up smart card authentication. Configuration varies based on factors like&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;the CA that signs keys on smart cards&lt;/li&gt;&#xA;&lt;li&gt;properties of CN (Common Name) that are required&lt;/li&gt;&#xA;&lt;li&gt;identity mapping rules (how to translate CN from smart card to identity)&lt;/li&gt;&#xA;&lt;li&gt;versions of client &amp;amp; server stack&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;This blog post gives concrete steps on how to set-up FreeIPA 4.6.6 (Red Hat Identity Management) server for authentication with yubikey smart card.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to debug Smart Card authentication client</title>
      <link>/posts/2019/11/how-to-debug-smart-card-authentication-client/</link>
      <pubDate>Mon, 18 Nov 2019 00:00:00 +0000</pubDate>
      <guid>/posts/2019/11/how-to-debug-smart-card-authentication-client/</guid>
      <description>&lt;h2 id=&#34;dummy-intro-to-smart-card-authentication&#34;&gt;Dummy intro to smart card authentication&lt;/h2&gt;&#xA;&lt;p&gt;Smart card authentication is just like authentication with certificates and private keys (X509, PKI).&#xA;The difference is that instead of fetching your private key and certificate from the disk, you let&#xA;smart card do the cryptographic operations for you and private key never leaves the card. Special&#xA;protocols are used on the client to allow communication between browser and the smart card.&lt;/p&gt;&#xA;&lt;h2 id=&#34;setting-things-can-be-difficult&#34;&gt;Setting things can be difficult&lt;/h2&gt;&#xA;&lt;p&gt;Smart card authentication over HTTPS may be challenging thing to deploy. Especially, for&#xA;newcomers. At one step You have to set-up all the components properly.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
