mikesplain / openvas-docker

A Docker container for Openvas
MIT License
767 stars 304 forks source link

openvas-scapdata-sync can't seem to finish #37

Closed codering closed 9 years ago

codering commented 9 years ago
docker@boot2docker:~$ docker top 711f459094c3
UID                 PID                 PPID                C                   STIME               TTY                 TIME                CMD
root                9047                773                 0                   01:10               ?                   00:00:00            /usr/bin/python3 -u /sbin/my_init
root                9051                9047                0                   01:10               ?                   00:00:00            /bin/bash /etc/my_init.d/000_setup.sh
root                9082                9047                0                   01:10               ?                   00:00:00            openvassd: Waiting for incoming connections
root                9158                773                 0                   01:12               pts/2               00:00:00            bash
root                9499                9051                0                   01:26               ?                   00:00:00            /bin/sh /usr/local/sbin/openvas-scapdata-sync
root                9506                9499                0                   01:26               ?                   00:00:00            /usr/bin/rsync -ltvrP --delete --exclude /scap.db --exclude private/ rsync://feed.openvas.org:/scap-data /usr/local/var/lib/openvas/scap-data
root                9508                9506                0                   01:26               ?                   00:00:04            /usr/bin/rsync -ltvrP --delete --exclude /scap.db --exclude private/ rsync://feed.openvas.org:/scap-data /usr/local/var/lib/openvas/scap-data

openvas-scapdata-sync can't seem to finish . I wait all day long.

I run "openvas-check-setup --v7" manually,

openvas-check-setup 2.3.0
  Test completeness and readiness of OpenVAS-7

  Please report us any non-detected problems and
  help us to improve this check routine:
  http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss

  Send us the log-file (/tmp/openvas-check-setup.log) to help analyze the problem.

  Use the parameter --server to skip checks for client tools
  like GSD and OpenVAS-CLI.

Step 1: Checking OpenVAS Scanner ... 
        OK: OpenVAS Scanner is present in version 4.0.7.
        OK: OpenVAS Scanner CA Certificate is present as /usr/local/var/lib/openvas/CA/cacert.pem.
        OK: NVT collection in /usr/local/var/lib/openvas/plugins contains 39478 NVTs.
        WARNING: Signature checking of NVTs is not enabled in OpenVAS Scanner.
        SUGGEST: Enable signature checking (see http://www.openvas.org/trusted-nvts.html).
        WARNING: The initial NVT cache has not yet been generated.
        SUGGEST: Start OpenVAS Scanner for the first time to generate the cache.
Step 2: Checking OpenVAS Manager ... 
        OK: OpenVAS Manager is present in version 5.0.11.
        ERROR: No client certificate file of OpenVAS Manager found.
        FIX: Run 'openvas-mkcert-client -n -i'

 ERROR: Your OpenVAS-7 installation is not yet complete!

Please follow the instructions marked with FIX above and run this
script again.

If you think this result is wrong, please report your observation
and help us to improve this check routine:
http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss
Please attach the log-file (/tmp/openvas-check-setup.log) to help us analyze the problem.
mikesplain commented 9 years ago

What's in the tail of your docker log for that container?

There is certainly an issue that I've seen with the new version that may be causing this. I'm hoping to update to v8 shortly and change the way a bit of this runs.

codering commented 9 years ago
....
zone_alarm_local_dos.nasl
zone_alarm_local_dos.nasl.asc
[i] Download complete
[i] Checking dir: ok
[i] Checking MD5 checksum: ok
[i] This script synchronizes a SCAP data directory with the OpenVAS one.
[i] SCAP dir: /usr/local/var/lib/openvas/scap-data
[i] Will use rsync
[i] Using rsync: /usr/bin/rsync
[i] Configured SCAP data rsync feed: rsync://feed.openvas.org:/scap-data
OpenVAS feed server - http://www.openvas.org/
This service is hosted by Intevation GmbH - http://intevation.de/
All transactions are logged.

Please report synchronization problems to openvas-feed@intevation.de.
If you have any other questions, please use the OpenVAS mailing lists
or the OpenVAS IRC chat. See http://www.openvas.org/ for details.

receiving incremental file list
./
COPYING
          1,493 100%    1.42MB/s    0:00:00 (xfr#1, to-chk=63/65)
COPYING.asc
            198 100%   96.68kB/s    0:00:00 (xfr#2, to-chk=62/65)
nvdcve-2.0-2002.xml
     19,454,677 100%    7.24kB/s    0:43:44 (xfr#3, to-chk=61/65)
nvdcve-2.0-2002.xml.asc
            198 100%  193.36kB/s    0:00:00 (xfr#4, to-chk=60/65)
nvdcve-2.0-2003.xml
      5,691,998 100%    7.44kB/s    0:12:27 (xfr#5, to-chk=59/65)
nvdcve-2.0-2003.xml.asc
            198 100%  193.36kB/s    0:00:00 (xfr#6, to-chk=58/65)
nvdcve-2.0-2004.xml
     11,919,460 100%    7.42kB/s    0:26:08 (xfr#7, to-chk=57/65)
nvdcve-2.0-2004.xml.asc
            198 100%   96.68kB/s    0:00:00 (xfr#8, to-chk=56/65)
nvdcve-2.0-2005.xml
     18,410,755 100%   11.88kB/s    0:25:12 (xfr#9, to-chk=55/65)
nvdcve-2.0-2005.xml.asc
            198 100%    0.38kB/s    0:00:00 (xfr#10, to-chk=54/65)
nvdcve-2.0-2006.xml
     28,803,979 100%   22.30kB/s    0:21:01 (xfr#11, to-chk=53/65)
nvdcve-2.0-2006.xml.asc
            198 100%   96.68kB/s    0:00:00 (xfr#12, to-chk=52/65)
nvdcve-2.0-2007.xml
     26,978,204 100%   37.52kB/s    0:11:42 (xfr#13, to-chk=51/65)
nvdcve-2.0-2007.xml.asc
            198 100%    1.93kB/s    0:00:00 (xfr#14, to-chk=50/65)
nvdcve-2.0-2008.xml
     31,788,434 100%   25.30kB/s    0:20:27 (xfr#15, to-chk=49/65)
nvdcve-2.0-2008.xml.asc
            198 100%    0.67kB/s    0:00:00 (xfr#16, to-chk=48/65)
nvdcve-2.0-2009.xml

openvas-scapdata-sync is too slow. Is it my network problem?

mikesplain commented 9 years ago

Yes I would expect that's a network issue. It's halfway through the download process. This can take hours on a slow connection.

mikesplain commented 9 years ago

Once I merge #38 you should also try that.

mikesplain commented 9 years ago

Closing since I haven't heard back from you. Feel free to comment if you have any other issues.