Skip to main content

Greenbone Logo

ospd-openvas

GitHub releases PyPI Build and test

ospd-openvas is an OSP server implementation to remotely control OpenVAS Scanner and Notus Scanner.

Once running, you need to configure OpenVAS Scanner and Notus Scanner for the Greenbone Vulnerability Manager, for example via the web interface Greenbone Security Assistant. Then you can create scan tasks to use both scanners.

Installation

Requirements

Python 3.9 and later is supported.

ospd-openvas has dependencies on the following Python packages:

  • defusedxml
  • deprecated
  • lxml
  • packaging
  • paho-mqtt
  • psutil
  • python-gnupg
  • redis

Mandatory configuration

The ospd-openvas startup parameter --lock-file-dir or the lock_file_dir config parameter of the ospd.conf config file needs to point to the same location / path of the gvmd daemon and the openvas command line tool (Default: <install-prefix>/var/run). Examples for both are shipped within the config sub-folder of this project.

Also in order to be able to use Notus ospd-openvas must connect to a MQTT broker, such as Mosquitto in order to communicate. With the parameter --mqtt-broker-address (Default: localhost) the correct address must be given as well as the corresponding port with --mqtt-broker-port (Default: 1883).

Please see the Details section of the GVM release notes for more details.

Optional configuration

Please note that although you can run openvas (launched from an ospd-openvas process) as a user without elevated privileges, it is recommended that you start openvas as root since a number of Network Vulnerability Tests (NVTs) require root privileges to perform certain operations like packet forgery. If you run openvas as a user without permission to perform these operations, your scan results are likely to be incomplete.

As openvas will be launched from an ospd-openvas process with sudo, the next configuration is required in the sudoers file:

sudo visudo

add this line to allow the user running ospd-openvas, to launch openvas with root permissions

<user> ALL = NOPASSWD: <install prefix>/sbin/openvas

If you set an install prefix, you have to update the path in the sudoers file too:

Defaults        secure_path=<existing paths...>:<install prefix>/sbin

Usage

There are no special usage aspects for this module beyond the generic usage guide.

Please follow the general usage guide for ospd-based scanners:

https://github.com/greenbone/ospd-openvas/blob/main/docs/USAGE-ospd-scanner.md

Support

For any question on the usage of ospd-openvas please use the Greenbone Community Portal. If you found a problem with the software, please create an issue on GitHub. If you are a Greenbone customer you may alternatively or additionally forward your issue to the Greenbone Support Portal.

Maintainer

This project is maintained by Greenbone AG.

Contributing

Your contributions are highly appreciated. Please create a pull request on GitHub. Bigger changes need to be discussed with the development team via the issues section at GitHub first.

For development you should use poetry to keep your python packages separated in different environments. First install poetry via pip

python3 -m pip install --user poetry

Afterwards run

poetry install

in the checkout directory of ospd-openvas (the directory containing the pyproject.toml file) to install all dependencies including the packages only required for development.

The ospd-openvas repository uses autohooks to apply linting and auto formatting via git hooks. Please ensure the git hooks are active.

poetry install
poetry run autohooks activate --force

License

Copyright (C) 2018-2022 Greenbone AG

Licensed under the GNU Affero General Public License v3.0 or later.

Release files for ospd-openvas 22.10.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ospd-openvas 22.10.5
File Size Uploaded
ospd_openvas-22.10.5.tar.gz 183.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ospd-openvas 22.10.5
File Interpreter ABI Platform
ospd_openvas-22.10.5-py3-none-any.whl Python 3 none any Details

Total release size: 296.5 kB

Release files / ospd_openvas-22.10.5.tar.gz

Download URL ospd_openvas-22.10.5.tar.gz
Size 183.2 kB
Tags Source
SHA-256 checksum
How to use checksums
0cdf98f541f50d15c71d640cf44e5508b3ff6a18c8f6fae817bc97fe797bd7af
BLAKE2b-256 checksum
How to use checksums
5fc08f2c5e55a9f16a40b924c23bcec2f330aa0b757fdcaddecf841ac0cf0959
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / ospd_openvas-22.10.5-py3-none-any.whl

Download URL ospd_openvas-22.10.5-py3-none-any.whl
Size 113.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
49b8e0e9c5b757a2bc0b3a778cdfe36e7130e248e4e618bc076598ff52f20aa4
BLAKE2b-256 checksum
How to use checksums
6e04d5b284f358e3757133d6dab2e7e4c950fb8065184d94bcdd773e083871b6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page