When a colleague says they run OpenVAS, what might they mean, and how do OpenVAS, GVM and Greenbone Community Edition relate?
answer
- scanner versus whole framework
- rename after OpenVAS 9
- Greenbone Vulnerability Management
- 2022 umbrella name
basics
~20 sOpenVAS can mean just the scan engine or the whole framework. The framework was renamed GVM after OpenVAS 9, and since 2022 Greenbone calls its open-source releases Greenbone Community Edition, with the OpenVAS Scanner as one component.
solid answer
~40 sOpenVAS began in 2006 as a fork of Nessus after Nessus left open source, and Greenbone AG has led it since 2008. The word is ambiguous: it can mean the scan engine (the OpenVAS Scanner, today `ospd-openvas` plus `openvas-scanner`), the whole framework, the project or a release. After OpenVAS 9 in 2017 the framework releases were named **GVM** (Greenbone Vulnerability Management), starting with GVM-10, because the scanner had become one module beside `gvmd` and the web interface. In 2022 Greenbone adopted **Greenbone Community Edition** as the umbrella name for its open-source releases; the commercial line is Greenbone Enterprise, formerly GSM. So I would ask whether they mean the engine or the full stack.
go deeper
Recall that OpenVAS can mean the scanner or the whole framework, that the framework became GVM after OpenVAS 9, and that Greenbone Community Edition is today's open-source umbrella name.
Place the components under the names: the OpenVAS Scanner is ospd-openvas plus openvas-scanner, while gvmd, the web interface and the feed complete the framework.
Show the operational consequence: who supports a distribution package, why releases must never be mixed, and which component's log you read for which fault.
Frame the open-source versus enterprise line honestly: what the Community Edition gives for free, and what support, appliances and the Enterprise Feed add for a team that cannot self-support.
## Why one name means several things **OpenVAS** started life as the name of a single vulnerability scanner and grew into the name of a whole framework, a release line and a community. The Greenbone documentation itself lists five things the word can mean depending on context: - a **vulnerability scanner** (the OpenVAS Scanner), - a **software framework** of several components (what was later called GVM), - a **software project** led by the company Greenbone, - a **source code release** of the vulnerability management solution (OpenVAS 9, GVM 20.08 and so on), - a **community** of users and developers. So when a colleague says "we run OpenVAS", the first useful question is whether they mean the scan engine alone or the full stack with its manager, database, web interface and feed. ## A short history that explains the names The names make sense once you know the order in which they appeared: 1. In **2005** the developers of Nessus stopped publishing it under open-source licences and moved to a proprietary model. 2. In **2006** several forks of Nessus appeared; only one kept going: **OpenVAS**, the Open Vulnerability Assessment System. 3. In **2008** **Greenbone AG** was founded to drive OpenVAS forward; from **2009** it added a central management service and a web interface around the scanner. 4. In **March 2017** the framework reached **OpenVAS 9**. The next release was named **GVM-10** (Greenbone Vulnerability Management): from then on, the OpenVAS Scanner was only one module of many. The licences did not change. 5. **GVM 11** (2019) turned the old `openvassd` daemon into the `openvas` command-line scanner, controlled by `ospd-openvas` over the XML-based **Open Scanner Protocol (OSP)**, replacing the old OTP protocol. 6. From **GVM 20.08** releases used calendar versioning; in **2022** Greenbone adopted **Greenbone Community Edition** as the umbrella name for all its open-source work, and Community Edition **22.4** is the current documented release line. 7. Since **2023** the components are released independently, most of them with semantic versioning. ## What each name refers to today | Name | What it refers to today | |---|---| | **OpenVAS Scanner** | The scan engine: `ospd-openvas` plus `openvas-scanner`, which executes the Vulnerability Tests (VTs) | | **GVM** | The framework's former name, Greenbone Vulnerability Management; it survives in component names such as `gvmd` and `gvm-tools` | | **Greenbone Community Edition** | The open-source releases of the whole framework, which distributions repackage | | **Greenbone Community Feed** | The freely available feed of VTs, SCAP and CERT data, scan configs and port lists | | **Greenbone Enterprise** | The commercial on-premises line: appliances running the Greenbone OS (GOS) with the GVM framework and the Greenbone Enterprise Feed; **Greenbone Security Manager (GSM)** is its former name | The Community Edition is developed as part of the commercial Greenbone Enterprise product line, which is why the open-source docs keep pointing at the enterprise manuals for scanning concepts. ## Why the distinction matters when you operate it - **Who supports your install.** Greenbone provides no packages for any Linux distribution apart from its own GOS. A Kali package, a third-party repository or a random container image was built by someone else, may be adjusted or outdated, and the first contact for a fault is that packager. Greenbone's own support covers only the Enterprise line; the community forum is volunteer help. - **Never mix releases.** `gvmd`, `ospd-openvas` and `openvas-scanner` rely on public and private interfaces that can change with every release, even a bugfix release, so running a scanner from the main branch beside a released `gvmd` is very likely to break. - **Reading the right documentation.** Error messages name components (`gvmd`, `ospd-openvas`, `gsad`), not "OpenVAS". Knowing which component a log line belongs to is the first step in any diagnosis. - **Licence and cost conversations.** "OpenVAS is free" is true of the Community Edition and the Community Feed; the appliances and the Enterprise Feed are commercial products. ## How to answer in an interview A strong answer does three things in a few sentences: 1. **Separates the scanner from the framework**: the OpenVAS Scanner is the engine; the framework around it adds `gvmd`, the web interface and the feed. 2. **Places the rename**: OpenVAS 9 in 2017 was the last framework release under that name, followed by GVM-10. 3. **Names today's umbrella**: Greenbone Community Edition for the open-source releases, Greenbone Enterprise for the commercial appliances and feed. Adding the Nessus origin, a fork after Nessus left open source, shows you know why the two products look alike, without claiming anything about how either one works today.
- Your team installed OpenVAS from a Linux distribution's packages and gvmd fails after an upgrade. Who do you contact first?The packager. Greenbone builds no packages for any distribution except its own GOS, and its FAQ says distribution builds may be adjusted, outdated or broken. Raise it on that distribution's tracker first; Greenbone's community forum is volunteer help, and its paid support covers the Enterprise line only.
- Can you upgrade only the scanner to a newer release and keep the older gvmd?No. The Greenbone FAQ says never to mix components from different releases: `gvmd`, `ospd`, `ospd-openvas` and `openvas-scanner` depend on interfaces that can change in every release, even bugfix ones. Update the whole set to matching releases and run `gvmd --migrate` when the database schema changes.
saying these in an interview costs you the question
- GVM is just the newer name of the scanner process itself.
- Greenbone Community Edition is a time-limited trial that needs a licence key.
- Greenbone builds and supports the OpenVAS packages shipped by Kali and other distributions.
- You can run a newer openvas-scanner beside an older gvmd without trouble.
- OpenVAS is unrelated to Nessus and was written from scratch by Greenbone.