The Conference was a success
Thanks all participants, it was fun and a success. Read the DevCon2 Minutes.
OpenVAS Developer Conference #2 (July 9-12 2009)
The second OpenVAS developer conference takes again place in Osnabrück, Germany. This page summarizes the current state of planning.


Event organization supported by Intevation GmbH and ffis e.V..
OpenVAS Workshop Agenda - July 8th 2009
Workshop on OpenVAS administration and deployment on the day prior to the
conference: July 8th 2009.
The following topics are covered,
1. OpenVAS architecture 2. Installation of OpenVAS on Linux systems 3. OpenVAS scanning OpenVAS features Creation of policies and running the scan Credentiated and Credential less scanning The OpenVAS knowledge base Logs Scanning different network devices: Windows, Unix Reports 4. OpenVAS Administration 5. Writing NASL plugins 6. OpenVAS integrated tools
Price: EURO 300
The money will be utilized to cover the travel costs for students and other
private OpenVAS developers. Please express your interest by writing to,
openvas-devcon@intevation.de.
To register, fill out the Registration Form.
Conference Agenda - July 9th - 12th 2009
This is a collection of thoughts discussed on the mailing list openvas-discuss. Please involve yourself there to express your ideas or needs.
A major goal is derive a master plan for the next 12-24 month of development.
- review the past 2 years of progress
- discuss core designs (towards OpenVAS 3.0)
- Topic 1.1: tighter nmap integration (service detection, OS detection, network discovery, network scans in contrast to host-based scans and seamless integration of NSE scripts). Also relates to CR#26.
- Topic 1.2: How to establish scan tasks like "all Windows machines in this network".
- Topic 1.3: CR#23 and CR#24 and OIDs: Agree on standard family names and on subdirectory structures. Final layout and assignment procedure
- Topic 1.4: Harmonization/unification strategies for NASL code
- Topic 2.1: New concept of scanner/manager separation (many consequences like retiring OTP for client, having manager mandatory, ...). Big picture(?)
- Topic 2.2: list of internal stuff we want to get rid of (like arglists, hash functions, use ini-file format). E.g. What can be replaced by glib functionality.
- Topic 2.3: New base data structures for cleaner objects, APIs etc. (e.g. "struct NVT {}")
- Topic 2.4: Reorganising openvas-libraries: to have a lightweight core and perhaps other focused libraries to suffice needs of client, manager, etc. Also includes reorganising OpenVAS-Client: Making dependency on openvas-libraries could reduce code base a lot.
- Topic 3.1: Getting rid of NASL-based SSH stuff in favour of openssh(?)
- Topic 3.2: discuss how to extend NVT coverage and how to retire NVTs
- Topic 3.3: Replace the current internationalization concepts in nasl/server with a solution by standard technologies
- Managing OVAL (and other script types) via OpenVAS
- RDBMS data models for results, NVTs etc.
- Walkthrough of all the pending CR's
- Organising OpenVAS project (house keepers for web site, bug tracker, NASL APIs, PR etc.). Possibly assigning people.
- discuss professional services and how they relate to project
- meet the members of the OpenVAS mailing lists in real life and have beers (or other beverages)
Place
Intevation GmbH kindly hosts the developer conference at their offices:
Neuer Graben 1749074 Osnabrück
Germany
Note for attendies of the DevCon1: Intevation moved to new offices in 2008 which are around 5 minutes walking distance from the ones where DevCon1 took place.
Accomodation
Intevation will take care of hotel reservations. Please include your preferences with the expression of interest for attending.
How to attend
Please let us know on the openvas-discuss mailing list or directly to openvas-devcon@intevation.de whether you like to attend.
Preliminary schedule
Time | Thu, July 9th | Fri, July 10th | Sat, July 11th | Sun, July 12th |
---|---|---|---|---|
8-10 | Arrival/Hacking | Hacking | Hacking | Hacking |
10-11 | Arrival | Topic 1.1: Tighter nmap integration TBA |
Topic 2.1: New concept of Scanner/Manager separation TBA |
Topic 3.1: Getting rid of NASL-based SSH stuff TBA |
11-12 | Arrival | Topic 1.2: How to establish scan tasks like "All Windows hosts" TBA |
Topic 2.2: List of internal stuff we want to get rid of TBA |
Topic 3.2: NVT coverage extension and NVT retirement TBA |
12-13 | Arrival | Topic 1.3: Standard family, subdirectory structures, OIDs TBA |
Topic 2.3: New base data structures (objects, APIs etc) TBA |
Topic 3.3: Replacement of current internationalization concepts TBA |
13-14 | Lunch | Lunch | Lunch | Lunch |
14-15 | Welcome Jan-Oliver Wagner, Tim Brown |
Topic 1.4: 'Harmonization' strategies for NASL code TBA |
Topic 2.4: Reorganising openvas-libraries TBA |
Closing Session (next steps)/ Road Map 3.0 |
15-16 | Self-introductions (relation to OpenVAS, focus, interests) All (approx. 5min each) |
In depth discussion of Topic 1.x | In depth discussion of Topic 2.x | Hacking/Departure |
16-17 | Invited Talk: N/A N/A |
In depth discussion of Topic 1.x | In depth discussion of Topic 2.x | Hacking/Departure |
17-18 | Expectations / Adjustments for DevCon2 (also walkthrough pending CRs) All |
In depth discussion of Topic 1.x | In depth discussion of Topic 2.x | Hacking/Departure |
18-19 | OpenVAS community: Structures, Procedures All |
In depth discussion of Topic 1.x | In depth discussion of Topic 2.x | Hacking/Departure |
19-20 | ||||
20- | Dinner, Pub, Hacking (Rampendahl) Afterwards Guided City Tour by night |
Dinner, Pub, Hacking (Lotus Palast) |
Dinner, Pub, Hacking (Arabesque) |
Hacking/Departure |