From 9c8ae7fd395c31796278b6f271fe51de6c32b7e1 Mon Sep 17 00:00:00 2001 From: devGregA Date: Thu, 20 Aug 2026 02:30:41 -0600 Subject: [PATCH] docs(connectors): document GMP over SSH for OpenVAS / Greenbone Greenbone deprecated TLS/GMP - it was the default only through GOS 3.1 - in favour of GMP over SSH from GOS 4 on, and a current Greenbone commonly exposes no TLS listener at all. The section described only the TLS transport, which left the reader with no way to connect a modern instance. Splits the transport choice out, says which version needs which, and documents the SSH setup: either arrangement found in the field (an appliance-style forced-command account, or an ordinary account permitted to forward to gvmd's unix socket) works and is detected automatically. Calls out that the GMP user is still required on SSH - SSH only carries the connection, GMP authenticates over it - and that the host key fingerprint field takes all of a server's fingerprints, since there is no telling which key type gets negotiated. The TLS instructions stay, with the caveat that the Community Edition compose stack has no TLS listener and needs something in front of the socket. Co-Authored-By: Claude Opus 5 --- .../connectors/upstream/toolreference.md | 38 ++++++++++++++++--- 1 file changed, 32 insertions(+), 6 deletions(-) diff --git a/docs/content/connectors/upstream/toolreference.md b/docs/content/connectors/upstream/toolreference.md index 364b0406b9..080423dbf1 100644 --- a/docs/content/connectors/upstream/toolreference.md +++ b/docs/content/connectors/upstream/toolreference.md @@ -1726,19 +1726,45 @@ DefectDojo maps each PDCP **scan** as a separate Record and imports that scan's ## **OpenVAS / Greenbone** -The OpenVAS / Greenbone connector imports **network vulnerability findings** from a Greenbone (Greenbone Community Edition or Greenbone Enterprise) instance. It talks to `gvmd` over **GMP (Greenbone Management Protocol)** — an XML protocol over a TLS socket, not HTTP — and syncs the whole instance: it enumerates scan **tasks** and creates a DefectDojo product for each, importing the results of each task's latest report. +The OpenVAS / Greenbone connector imports **network vulnerability findings** from a Greenbone (Greenbone Community Edition or Greenbone Enterprise) instance. It talks to `gvmd` over **GMP (Greenbone Management Protocol)** — an XML protocol, not HTTP — and syncs the whole instance: it enumerates scan **tasks** and creates a DefectDojo product for each, importing the results of each task's latest report. + +GMP can be carried two ways, and which one you need depends on your Greenbone version: + +* **SSH** — what Greenbone documents from **GOS 4** onwards, and the right choice for a current instance. +* **TLS** — gvmd's older transport on port **9390**. It was the default only through GOS 3.1, and a current Greenbone commonly exposes no TLS listener at all. #### Prerequisites -A Greenbone **GMP user** (username + password) and network access to gvmd's GMP TLS port (default **9390**). The Greenbone Community Edition compose stack fronts gvmd via a unix socket, so to reach it from a networked connector you either run the connector where it can reach the socket or expose the GMP TLS port (for example a `socat` TLS bridge to `gvmd.sock`). +A Greenbone **GMP user** (username + password) in all cases. The GMP user is always required: SSH only carries the connection to `gvmd`, and GMP still authenticates over it. + +For the **SSH** transport, an SSH account on the Greenbone host that reaches `gvmd`, plus its host key fingerprint. Either arrangement works and the connector detects which one your host uses: + +* An account whose forced command connects the session to `gvmd` — the arrangement Greenbone appliances ship, and the one `gvm-tools` uses. The default account name is `gmp`. +* An ordinary account permitted to forward to gvmd's unix socket (`AllowStreamLocalForwarding`), which suits self\-managed and containerised installs. + +For the **TLS** transport, network access to gvmd's GMP TLS port (default **9390**). Note that the Greenbone Community Edition compose stack fronts `gvmd` with a unix socket and no TLS listener, so this transport needs something in front of the socket — for example a `socat` TLS bridge to `gvmd.sock`. #### Connector Mappings -1. Enter the gvmd host in the **Location** field (host or `host:port`). +1. Enter the Greenbone host in the **Location** field. 2. Enter the GMP **Username** and **Password**. -3. Optionally set the **GMP Port** (defaults to 9390). -4. For gvmd's default self\-signed certificate, either provide a **CA Certificate (PEM)** to verify against, or set **Skip TLS Verification** to `true`. -5. Optionally, set a **Minimum Severity** to limit which findings are imported. +3. Optionally, set a **Minimum Severity** to limit which findings are imported. + +Then configure one transport. + +**For SSH:** + +1. Set **Transport** to `ssh`. +2. Enter the **SSH Username** (defaults to `gmp`) and, if it is not 22, the **SSH Port**. +3. Provide either an **SSH Private Key** — with its **SSH Key Passphrase** if the key is encrypted — or an **SSH Password**. A key is preferred. +4. Enter the **SSH Host Key Fingerprint**. A server usually offers host keys of several types and there is no telling in advance which one gets negotiated, so paste **all** of them, separated by commas or spaces. `ssh-keyscan | ssh-keygen -lf -` prints them for every key the host offers, and its output can be pasted as\-is. Setting **Skip SSH Host Key Check** to `true` accepts any host key instead, which is not recommended. Note that **Skip TLS Verification** does *not* do this \- it covers the TLS certificate only, so that routinely skipping the check on gvmd's self\-signed certificate cannot quietly un\-pin your host keys. +5. Optionally set the **gvmd Socket Path** if your host permits socket forwarding but keeps the socket somewhere non\-standard. Left blank, the connector probes the usual locations. + +**For TLS:** + +1. Leave **Transport** blank. +2. Optionally set the **GMP Port** (defaults to 9390). +3. For gvmd's default self\-signed certificate, either provide a **CA Certificate (PEM)** to verify against, or set **Skip TLS Verification** to `true`. Each Greenbone task becomes a Record. Findings come from the task's latest finished report — one per ``. Severity is taken from the result's threat level (Greenbone's `Log`/`Debug` informational levels map to Info), with the numeric CVSS score recorded; CVE references become vulnerability ids, the NVT solution becomes the mitigation, and each result's host/port becomes an endpoint.