For anyone wondering how to get around this:
solution was to
- setup one web-admin via the greenbone ~cli interface
- login to web with that web-admin
- setup more users (e.g. user-specific-logins)
- create a group e.g. see-all-objects (note this needs to be a special group
- for each users-specific-login repeat 5.X
5.1. enter details page for the user-specific-login
5.2. copy GUID out of URl https://example.com/user/
5.3. Go to permissions https://example.com/permissions
5.4. add a new permission
Name: Super (has super access)
Subject: Group “see-all-objects”
Resource Type: User
user ID: - Add all users to the group see-all-objects
- Logout of web-admin
- Login to one user-specific-login
- setup & run a scan
- logout & login with different user-specific-login
- see all the created assets/reports/etc.
Background: this works, because the users that are the owners of the tasks/targets/assets/etc. are NOT ~system-admins (as the web-admin) is
And stuff owned by ~system-admins is not visible to ~lower tier admins aka. admins created via the web-interface.
Therefore: modus operandi: use the cli-created accounts only for setup of user-accounts, but not for anything else.
Worked for me with Greenbone OS 22.04.28 - BASIC
Cheers, Markus
P.S. helpful forum posts
https://forum.greenbone.net/t/configuration-of-new-users-in-the-greenbone-security-assistant/14245/4
and some doc