Re: [exim] Strange error from ClamAV

Top Page
Delete this message
Reply to this message
Author: Odhiambo G. Washington
Date:  
To: exim-users
Subject: Re: [exim] Strange error from ClamAV
* On 04/10/05 13:47 +0100, Ian Eiloart wrote:
>
>
> --On 4 October 2005 11:41:35 +0100 "Stanier, Alan M" <alan@???>
> wrote:
>
> >We run identical installations of exim 4.53 on three SMTP servers.
> >Recently, one has started rejecting all email, with the log showing
> >messages like
> >
> >
> >
> >malware acl condition: clamd: ClamAV returned
> >/var/spool/exim_incoming/scan/1EMk73-0001ij-Ac: Access denied. ERROR
> >
> >
> >
> >This looked like a permissions problem, but the protections on the
> >/var/spool hierarchy are identical on the failing machine and the two
> >working ones. As a test, I chmod'ed 777 all the way up the hierarchy,
> >but the problem persisted.
> >
> >
> >
> >I am baffled ... can anyone suggest what might be wrong?
>
>
> Ooh, I've had this problem too, on an XServe. I don't recall exactly how I
> fixed it, but it may be to do with clamav starting before the user id was
> properly known. If you're getting your user information from a remote (eg,
> ldap) server, then it may be wise to actually define the clamav user
> locally instead.


Isn't it easy to simple run clamd as the exim_user? After all both are
playing with your e-mail files. That's how I do it. In fact, I
statically compile clamav with --with-user=mailnull.
I am yet to hear what disadvantages that has.



        cheers
       - wash 
+----------------------------------+-----------------------------------------+
Odhiambo Washington                    . WANANCHI ONLINE LTD (Nairobi, KE)  |
wash () WANANCHI ! com            . 1ere Etage, Loita Hse, Loita St.,  |
GSM: (+254) 722 743 223            . # 10286, 00100 NAIROBI             |
GSM: (+254) 733 744 121            . (+254) 020 313 985 - 9             |
+---------------------------------+------------------------------------------+
"Oh My God! They killed init! You Bastards!"  
                         --from a /. post