From nobody Sun May 22 05:44:26 2022 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 6E1711B3E2EE; Sun, 22 May 2022 05:44:27 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4L5TtL6rRzz4VBJ; Sun, 22 May 2022 05:44:26 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1653198267; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=kOtpiSoRz6IOYmSwLhQBh36vZxGejFUyzvWPLrVFqSc=; b=b6H54Fgg2aXWzu4Oo6x659k6XHitWKntDUys30EGCa14+OrRsEZbJMqyavWnIzyBPAdx71 0VhZ0V0c5UW919kz7FyasCd7YxmsYA7grAa3rIHbCCq0q48lFdil/vY38Qz0BDDIuFvgkE D8xrrK+gB/3nVPJ0bJAkthdgXpQYXFWFyEkvfZ0LOKABFKukNqrth2oi77RSNSarufACzz U8H+nuW7MvK7QmISInxdT62H0dv1UZTXPsljjTesRfJFvCudybF3n1UJan09+zFRIlJC1u ki6/iFqLlcNvIg04iTCc1/c+u/yh68XqoskioPzZRR6No5SdXqrRcqgirQJcFg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 9DE8C15B34; Sun, 22 May 2022 05:44:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 24M5iQ28005475; Sun, 22 May 2022 05:44:26 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 24M5iQqK005474; Sun, 22 May 2022 05:44:26 GMT (envelope-from git) Date: Sun, 22 May 2022 05:44:26 GMT Message-Id: <202205220544.24M5iQqK005474@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Jose Alonso Cardenas Marquez Subject: git: fc6905611301 - main - security/gvm: update to 21.4.4 List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-main@freebsd.org X-BeenThere: dev-commits-ports-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: acm X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: fc690561130132cfbec20ad3865cf0af7f717ca0 Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1653198267; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=kOtpiSoRz6IOYmSwLhQBh36vZxGejFUyzvWPLrVFqSc=; b=jvNgohoQgxxgjrC+dpnzaUyDSqHlW7eVLFCjx157Bm09/u+z7SmW5vgWDRGUHZjcnw4Jrx 0Y6jqOHtsUnbN/oV6fUUnAmr9ONciTEEMQGTR7y1Zq+2qRjovXOj2OqLZtoiDM0x2744Kd 7VGZ1yBlP1i8ZZ9Y/q0wgxQ/oAvpTaave3v1jEQBIlaKNS4K1KgUHnYyyFVfbVKFXvxQcC RV5zTokNHND8YZR70swnS/K/QBnTM8RWrW+q/yBXN+/9nKRrMtUbXxrViryrrkjug9net4 MjS0pONOTePE/anhAEVwYHgwnSkHSww5yHYaTDBX1rh1KKqevpsfT20kWXzzAA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1653198267; a=rsa-sha256; cv=none; b=eRnHNy96vaEUIp9dRmn8Yc84TF0wnbkXoVcD26Ipp5ESs7JOtIntY616kDNN8DQ8rAtJeM ugItP5EpEK7zZ/OjQoSFAGkSgMW+QIxURx18DgDa8WhAxM0m+rOEHg4eMHfR17e1PU5oHi xAMY85Zg6Wxre6jyCOrXgY0PLh72pYClN00ygPFSoBAdL81OnGxb7hR9mcYwRb1UIFy4JB otftTnCqpu8dQ9Vp4/x7Cm+S8EzyS9ht9j4lBlGf9JpfM3d8tbUHxASW9+CIxrrKlkZ4wX zlVtV2RWWdwzwehfjmCEyVdNud8wRGdvUmrvuxMUQn8o8DLOUZum1QV3fS/zdA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by acm: URL: https://cgit.FreeBSD.org/ports/commit/?id=fc690561130132cfbec20ad3865cf0af7f717ca0 commit fc690561130132cfbec20ad3865cf0af7f717ca0 Author: Jose Alonso Cardenas Marquez AuthorDate: 2022-05-22 05:25:38 +0000 Commit: Jose Alonso Cardenas Marquez CommitDate: 2022-05-22 05:42:11 +0000 security/gvm: update to 21.4.4 - security/openvas update to 21.4.4 - security/gvmd update to 21.4.5 - security/gvm-libs update to 21.4.4 - security/py-ospd-openvas update to 21.4.4 - security/py-python-gvm update to 21.11.0 - security/gsad was added - security/gsa was added - security/py-ospd was removed. Now it is part of security/py-osdp-openvas port - security/greenbone-security-assistant was removed. gsad and gsa ports was added instead of it --- security/gvm/Makefile | 5 +++-- security/gvm/files/pkg-message.in | 28 ++++++++++++++++++---------- 2 files changed, 21 insertions(+), 12 deletions(-) diff --git a/security/gvm/Makefile b/security/gvm/Makefile index 1eee1478469f..3a78a7032912 100644 --- a/security/gvm/Makefile +++ b/security/gvm/Makefile @@ -1,5 +1,5 @@ PORTNAME= gvm -PORTVERSION= 21.4.3 +PORTVERSION= 21.4.4 CATEGORIES= security MAINTAINER= acm@FreeBSD.org @@ -20,7 +20,8 @@ RUN_DEPENDS+= ${LOCALBASE}/bin/ospd-openvas:security/py-ospd-openvas@${PY_FLAVOR RUN_DEPENDS+= ${LOCALBASE}/sbin/openvas:security/openvas # Install GVM Web Interface -RUN_DEPENDS+= ${LOCALBASE}/sbin/gsad:security/greenbone-security-assistant +RUN_DEPENDS+= ${LOCALBASE}/sbin/gsad:security/gsad +RUN_DEPENDS+= ${LOCALBASE}/share/gvm/gsad/web/index.html:security/gsa SUB_FILES= pkg-message diff --git a/security/gvm/files/pkg-message.in b/security/gvm/files/pkg-message.in index e01bd8dfdaf6..fb6fed9cc012 100644 --- a/security/gvm/files/pkg-message.in +++ b/security/gvm/files/pkg-message.in @@ -38,7 +38,11 @@ Basic instructions for configure your gvm infraestruture are following: # sysrc ospd_openvas_enable="YES" # sysrc gsad_enable="YES" -5) Currently, ospd_openvas should run as a user without elevated privileges +5) Start redis service + + # service redis start + +6) Currently, ospd_openvas should run as a user without elevated privileges (gvm) and use sudo for run openvas scanner but it does not work properly. Like a workaround you must run redis as root and the same with ospd_openvas. @@ -48,9 +52,13 @@ Basic instructions for configure your gvm infraestruture are following: ospd_openvas_user="root" Take in mind it is not the best configuration for run ospd_openvas and - openvas. + openvas. + + The following could avoid some scan issues with openvas + + # echo "test_alive_hosts_only = no" >> /usr/local/etc/openvas/openvas.conf -6) The following steps are neccessary before of you can access to GVM web +7) The following steps are neccessary before of you can access to GVM web interface (gsad): Start gvmd service. It will listen on /var/run/gvmd/gvmd.sock by default @@ -80,7 +88,7 @@ Basic instructions for configure your gvm infraestruture are following: # su -m gvm -c "gvmd --modify-setting 78eceaec-3385-11ea-b237-28d24461215b --value -7) Start OSPD-OpenVAS Wrapper service. It will listen on /var/run/ospd/ospd.sock by default +8) Start OSPD-OpenVAS Wrapper service. It will listen on /var/run/ospd/ospd.sock by default # service ospd_openvas start @@ -93,11 +101,11 @@ Basic instructions for configure your gvm infraestruture are following: # su -m gvm -c "gvmd --verify-scanner=08b69003-5fc2-4037-a479-93b440211c73" Scanner version: OpenVAS x.x.x -8) Start GVM web interface. It will listen on http://127.0.0.1 by default +9) Start GVM web interface. It will listen on http://127.0.0.1 by default # service gsad start -9) Some openvas scanner tasks need access to /dev/bpf device. Add the +10) Some openvas scanner tasks need access to /dev/bpf device. Add the following lines to /etc/devfs.conf own bpf root:gvm @@ -107,15 +115,15 @@ Basic instructions for configure your gvm infraestruture are following: # service devfs restart -10) gvm log files are stores to /var/log/gvm directory +11) gvm log files are stores to /var/log/gvm directory -11) gsad can export results to PDF. It needs print/texlive-texmf port +12) gsad can export results to PDF. It needs print/texlive-texmf port # pkg install texlive-texmf It will install 1G of data -12) If you need more configure information you can look at the following links: +13) If you need more configure information you can look at the following links: https://github.com/greenbone/gvmd/blob/master/INSTALL.md https://github.com/greenbone/openvas/blob/master/INSTALL.md @@ -129,7 +137,7 @@ Basic instructions for configure your gvm infraestruture are following: # ospd-openvas -h # gsad -h -13) Enjoy it +14) Enjoy it EOM } ]