I am testing openscap profiles for almalinux and I found that if you directly remediate with anssi bp28 high profile, system does not boot. That happens both if you install with that profile selected or if you manually apply profile latter wish oscap xccdf eval --remediate
After reboot emergency console shows and there you can find that the problem is that /boot/efi could not be mounted.
#journalctl -xb systemd: Failed to mount /boot/efi.
I do not have found were in the profile remediation vfat filesystem is forbbiden.
# modprobe -v vfat insmod /lib/modules/4.18.0-372.19.1.el8_6.x86_64/kernel/fs/fat/fat.ko.xz modprobe: ERROR: could not insert 'vfat': Operation not permitted
It is not blacklisted on modprobe.d files, checked /etc/modprobe.d [/usr]/lib/modprobe.d/
Secure boot is enabled. But I saw no difference disabling it.
Workarround could be to comment /boot/efi entry in /etc/fstab, but that only allows you to start, if grub/kernel packages needed to be upgraded there will not upgrade content of real /boot/efi (you could manually select new kernel on boot menu to start), so no long term solution.
Any thought will be welcomed.