Skip to content

Disabled Weak SSL and Add Tar download for First Sync

Compare
Choose a tag to compare
@austinsonger austinsonger released this 21 May 16:09
· 162 commits to master since this release
fd8a011
  • Disable weak SSL ciphers and TLS protocols for gvmd API #174

su -c "gvmd --listen=0.0.0.0 --port=9390 --gnutls-priorities=SECURE128:-AES-128-CBC:-CAMELLIA-128-CBC:-VERS-SSL3.0:-VERS-TLS1.0:-VERS-TLS1.1" gvm

  • Add tar download for first sync #177
if [ ! -f "/firstsync" ]; then
	echo "Downloading data TAR to speed up first sync..."
	curl -o /tmp/data.tar.xz https://vulndata.securecompliance.solutions/file/VulnData/data.tar.xz # This file is updated at 0:00 UTC every day
	mkdir /tmp/data

	echo "Extracting data TAR..."
	tar --extract --file=/tmp/data.tar.xz --directory=/tmp/data

	mv /tmp/data/nvt-feed/* /usr/local/var/lib/openvas/plugins
	mv /tmp/data/gvmd-data/* /usr/local/var/lib/gvm/data-objects
	mv /tmp/data/scap-data/* /usr/local/var/lib/gvm/scap-data
	mv /tmp/data/cert-data/* /usr/local/var/lib/gvm/cert-data

	chown gvm:gvm -R /usr/local/var/lib/openvas/plugins
	chown gvm:gvm -R /usr/local/var/lib/gvm/data-objects
	chown gvm:gvm -R /usr/local/var/lib/gvm/scap-data
	chown gvm:gvm -R /usr/local/var/lib/gvm/cert-data

	rm /tmp/data.tar.xz
	rm -r /tmp/data
fi

If you test this new release and run into any issues please add your comments to this release discussion and please make sure to include the following information

Host Device:

  • OS:
  • Version: