|
From: Kari M. <ka...@tr...> - 2005-04-17 23:13:57
|
This is for mail gateway implementations of Devil-Linux. Sagator is a nice integrator between Postfix, SpamAssassin and ClamAV. The default settings with DL are not working properly. Previously I=20 sent a minor fix for SpamAssassin+Sagator. This posting is for=20 ClamAV+Sagator. You can do this in many different ways. This way changes as little as=20 possible the default configuration. I suggest you add to file /etc/sysconfig/jail/SAGATOR the following 3=20 lines to add the directory (with proper user rights) for virus definition= s: MKDIR /var/lib/clamav CHMOD 750 /var/lib/clamav CHOWN clamav:vscan /var/lib/clamav A quick explanation: /var/lib/clamav is the default directory for virus definitions. As=20 Sagator is executed jailrooted, this directory (actually=20 /var/spool/vscan/var/lib/clamav) does not exist. This is also the=20 directory where Sagator excepts the virus defs to be. ClamAV requires write access to this directory, but Sagator (user/group=20 vscan) only requires read+chdir access. This change, however is not sufficient. ClamAV is not executed=20 jailrooted. That means the ClamAV default directory /var/lib/clamav=20 does not match with Sagator's /var/spool/vscan/var/lib/clamav. Sagator's readme file recommends changing the following two files /etc/freshclam.conf /etc/clamd.conf ...and the change is simple: DatabaseDirectory /var/spool/vscan/var/lib/clamav You could leave the default line there as a commented one. There is a minor drawback here: You have to remember to do this change=20 every time you upgrade ClamAV, and that is (fortunately) quite often. *** As there is very little use on DL for ClamAV alone -- it is almost=20 always used with Sagator, I think the above DatabaseDirectory change=20 propably should make it to the default etc.tar.bz2. Comments? Terveisin/With kind regards/Med h=E4lsningar/Lugupidamisega, Kari Mattsson Trivore Corp. |
|
From: Heiko Z. <he...@zu...> - 2005-04-19 15:55:45
|
> > This is for mail gateway implementations of Devil-Linux. > > > Sagator is a nice integrator between Postfix, SpamAssassin and ClamAV. > > > The default settings with DL are not working properly. Previously I > sent a minor fix for SpamAssassin+Sagator. This posting is for > ClamAV+Sagator. > > > You can do this in many different ways. This way changes as little as > possible the default configuration. > > I suggest you add to file /etc/sysconfig/jail/SAGATOR the following 3 > lines to add the directory (with proper user rights) for virus > definitions: > > > MKDIR /var/lib/clamav > CHMOD 750 /var/lib/clamav > CHOWN clamav:vscan /var/lib/clamav > > > A quick explanation: > /var/lib/clamav is the default directory for virus definitions. As > Sagator is executed jailrooted, this directory (actually > /var/spool/vscan/var/lib/clamav) does not exist. This is also the > directory where Sagator excepts the virus defs to be. ClamAV requires write > access to this directory, but Sagator (user/group vscan) only requires > read+chdir access. > > This change, however is not sufficient. ClamAV is not executed > jailrooted. That means the ClamAV default directory /var/lib/clamav does > not match with Sagator's /var/spool/vscan/var/lib/clamav. > > Sagator's readme file recommends changing the following two files > /etc/freshclam.conf > /etc/clamd.conf > > > ...and the change is simple: > > > DatabaseDirectory /var/spool/vscan/var/lib/clamav > > > > You could leave the default line there as a commented one. > > > There is a minor drawback here: You have to remember to do this change > every time you upgrade ClamAV, and that is (fortunately) quite often. > > *** > > > As there is very little use on DL for ClamAV alone -- it is almost > always used with Sagator, I think the above DatabaseDirectory change > propably should make it to the default etc.tar.bz2. > > Comments? I have my sagator configured to connect to clamd, which currently is not chrooted. Your suggestion would actually improve security, so if nobody complains we could do the change. -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Heiko Z. <he...@zu...> - 2005-04-23 13:54:08
|
Kari Mattsson wrote: > > This is for mail gateway implementations of Devil-Linux. > > Sagator is a nice integrator between Postfix, SpamAssassin and ClamAV. > > The default settings with DL are not working properly. Previously I > sent a minor fix for SpamAssassin+Sagator. This posting is for > ClamAV+Sagator. > > You can do this in many different ways. This way changes as little as > possible the default configuration. > > I suggest you add to file /etc/sysconfig/jail/SAGATOR the following 3 > lines to add the directory (with proper user rights) for virus > definitions: > > MKDIR /var/lib/clamav > CHMOD 750 /var/lib/clamav > CHOWN clamav:vscan /var/lib/clamav OK I added this. > > A quick explanation: > /var/lib/clamav is the default directory for virus definitions. As > Sagator is executed jailrooted, this directory (actually > /var/spool/vscan/var/lib/clamav) does not exist. This is also the > directory where Sagator excepts the virus defs to be. > ClamAV requires write access to this directory, but Sagator > (user/group vscan) only requires read+chdir access. > > This change, however is not sufficient. ClamAV is not executed > jailrooted. That means the ClamAV default directory /var/lib/clamav > does not match with Sagator's /var/spool/vscan/var/lib/clamav. > > Sagator's readme file recommends changing the following two files > /etc/freshclam.conf > /etc/clamd.conf > > ...and the change is simple: > > DatabaseDirectory /var/spool/vscan/var/lib/clamav Hmmmm...... Anybody else has an oppinion about this? > > You could leave the default line there as a commented one. > > There is a minor drawback here: You have to remember to do this change > every time you upgrade ClamAV, and that is (fortunately) quite often. > > *** > > As there is very little use on DL for ClamAV alone -- it is almost > always used with Sagator, I think the above DatabaseDirectory change > propably should make it to the default etc.tar.bz2. > > Comments? > -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Kari M. <ka...@tr...> - 2005-04-23 17:04:59
|
Heiko Zuerker wrote: > Kari Mattsson wrote: > >> Sagator's readme file recommends changing the following two files >> /etc/freshclam.conf >> /etc/clamd.conf >> >> ...and the change is simple: >> >> DatabaseDirectory /var/spool/vscan/var/lib/clamav > > > Hmmmm...... > Anybody else has an oppinion about this? I do :-) Don't do the change. Yesterday I re-created the email filter from scratch (=default etc.tar.bz2), and it actually doesn't work with the above DatabaseDirectory /var/spool/vscan... setting. Sagator complains about not being able to find signatures. The default in /etc/freshclam.conf works ok. :-) ...and I don't the clamd any more. I just commented out 2 lines starting clamd in file /etc/init.d/clamd in the start section. It was easier than splitting the init.d script and then playing with the startup dependencies. /Kari |
|
From: Kari M. <kar...@tr...> - 2005-04-23 16:56:05
|
Heiko Zuerker wrote: > Kari Mattsson wrote: > >> Sagator's readme file recommends changing the following two files >> /etc/freshclam.conf >> /etc/clamd.conf >> >> ...and the change is simple: >> >> DatabaseDirectory /var/spool/vscan/var/lib/clamav > > > Hmmmm...... > Anybody else has an oppinion about this? I do :-) Don't do the change. Yesterday I re-created the email filter from scratch (=default etc.tar.bz2), and it actually doesn't work with the above DatabaseDirectory /var/spool/vscan... setting. Sagator complains about not being able to find signatures. The default in /etc/freshclam.conf works ok. :-) ...and I don't the clamd any more. I just commented out 2 lines starting clamd in file /etc/init.d/clamd in the start section. It was easier than splitting the init.d script and then playing with the startup dependencies. /Kari |