From: "Massimo S." Received: from [192.168.100.201] (HELO mail.2rosenthals.com) by 2rosenthals.com (CommuniGate Pro SMTP 5.4.10) with ESMTP id 11610019 for ecs-isp@2rosenthals.com; Sun, 29 Dec 2024 05:50:19 -0500 Received: from secmgr-va.2rosenthals.com ([50.73.8.217]:50945 helo=mail2.2rosenthals.com) by mail.2rosenthals.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.97.1) (envelope-from ) id 1tRqs6-000000000zX-1MWW for ecs-isp@2rosenthals.com; Sun, 29 Dec 2024 05:50:10 -0500 Received: from mail2.quasarbbs.net ([80.86.52.115]:10044) by mail2.2rosenthals.com with esmtp (Exim 4.97.1) (envelope-from ) id 1tRqs0-000000003BV-01Ap for ecs-isp@2rosenthals.com; Sun, 29 Dec 2024 05:50:04 -0500 X-SASI-Hits: BODY_SIZE_3000_3999 0.000000, BODY_SIZE_5000_LESS 0.000000, BODY_SIZE_7000_LESS 0.000000, CTE_7BIT 0.000000, HTML_00_01 0.050000, HTML_00_10 0.050000, IN_REP_TO 0.000000, LEGITIMATE_SIGNS 0.000000, MSGID_SAMEAS_FROM_HEX_844412 0.100000, MSG_THREAD 0.000000, REFERENCES 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SENDER_NO_AUTH 0.000000, SUSP_DH_NEG 0.000000, TO_IN_SUBJECT 0.500000, USER_AGENT 0.000000, __ANY_URI 0.000000, __BODY_NO_MAILTO 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __CP_URI_IN_BODY 0.000000, __CT 0.000000, __CTE 0.000000, __CT_TEXT_PLAIN 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FORWARDED_MSG 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_ADDR 0.000000, __FROM_NAME_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_REPLYTO 0.000000, __HEADER_ORDER_FROM 0.000000, __HTTPS_URI 0.000000, __INVOICE_MULTILINGUAL 0.000000, __IN_REP_TO 0.000000, __IOC_PHRASE 0.000000, __MAIL_CHAIN 0.000000, __MIME_BOUND_CHARSET 0.000000, __MIME_TEXT_ONLY 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_VERSION 0.000000, __MOZILLA_USER_AGENT 0.000000, __MSGID_HEX_844412 0.000000, __MULTIPLE_URI_TEXT 0.000000, __NO_HTML_TAG_RAW 0.000000, __REFERENCES 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __STOCK_PHRASE_7 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TO_IN_SUBJECT 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __URI_IN_BODY 0.000000, __URI_MAILTO 0.000000, __URI_NOT_IMG 0.000000, __URI_NO_WWW 0.000000, __URI_NS 0.000000, __URI_WITHOUT_PATH 0.000000, __URI_WITH_PATH 0.000000, __USER_AGENT 0.000000 X-SASI-Probability: 10% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2024.12.29.95746 X-SASI-Hits: BODY_SIZE_3000_3999 0.000000, BODY_SIZE_5000_LESS 0.000000, BODY_SIZE_7000_LESS 0.000000, CTE_7BIT 0.000000, HTML_00_01 0.050000, HTML_00_10 0.050000, IN_REP_TO 0.000000, LEGITIMATE_SIGNS 0.000000, MSGID_SAMEAS_FROM_HEX_844412 0.100000, MSG_THREAD 0.000000, REFERENCES 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SUSP_DH_NEG 0.000000, TO_IN_SUBJECT 0.500000, USER_AGENT 0.000000, __ANY_URI 0.000000, __AUTH_RES_PASS 0.000000, __BODY_NO_MAILTO 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __CP_URI_IN_BODY 0.000000, __CT 0.000000, __CTE 0.000000, __CT_TEXT_PLAIN 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FORWARDED_MSG 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_ADDR 0.000000, __FROM_NAME_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_REPLYTO 0.000000, __HEADER_ORDER_FROM 0.000000, __HTTPS_URI 0.000000, __INVOICE_MULTILINGUAL 0.000000, __IN_REP_TO 0.000000, __IOC_PHRASE 0.000000, __MAIL_CHAIN 0.000000, __MIME_BOUND_CHARSET 0.000000, __MIME_TEXT_ONLY 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_VERSION 0.000000, __MOZILLA_USER_AGENT 0.000000, __MSGID_HEX_844412 0.000000, __MULTIPLE_URI_TEXT 0.000000, __NO_HTML_TAG_RAW 0.000000, __REFERENCES 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __STOCK_PHRASE_7 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TO_IN_SUBJECT 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __URI_IN_BODY 0.000000, __URI_MAILTO 0.000000, __URI_NOT_IMG 0.000000, __URI_NO_WWW 0.000000, __URI_NS 0.000000, __URI_WITHOUT_PATH 0.000000, __URI_WITH_PATH 0.000000, __USER_AGENT 0.000000 X-SASI-Probability: 10% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2024.12.29.95746 Received: from [192.168.10.199] (dtp [192.168.10.199]) by srv2 (Weasel v2.9-0001 ) for ; Sun, 29 Dec 2024 11:50:07 -0000 Reply-To: ml@ecomstation.it Subject: Re: [eCS-ISP] (clamav) freshclam and cron/2 To: eCS ISP Mailing List References: Organization: Massimo S. Message-ID: <9e0f28c7-a5db-92bf-5658-d9436d5552e7@ecomstation.it> Date: Sun, 29 Dec 2024 11:49:56 +0100 User-Agent: Mozilla/5.0 (OS/2; U; Warp 4.5; it-IT; rv:1.7.13) Gecko/20060424 Thunderbird/1.0.8 Mnenhy/0.7.4.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=iso-8859-15; format=flowed Content-Language: it-IT Content-Transfer-Encoding: 7bit Il 28/12/2024 03:11, Steven Levine ha scritto: > In , on 12/27/24 > at 11:30 PM, "Massimo S." said: > > Hi Massimo, > >> now it installed also the certificates, but nothing changed, freshclam >> still complain: > >> Fri Dec 27 23:26:25 2024 -> downloadFile: Download source: >> https://database.clamav.net/daily.cvd Fri Dec 27 23:26:25 2024 -> >> downloadFile: Download destination: >> X:/usr/local/clamav/share/clamav/tmp.dfebd40db2/clamav-abaef3085449f10f20ed2baa912a0d29.tmp >> Fri Dec 27 23:26:25 2024 -> ERROR: Download failed (77) Fri Dec 27 >> 23:26:25 2024 -> ERROR: Message: Problem with the SSL CA cert (path? >> access rights?) >> Fri Dec 27 23:26:25 2024 -> ERROR: Can't download daily.cvd from >> https://database.clamav.net/daily.cvd Fri Dec 27 23:26:25 2024 -> Giving >> up on https://database.clamav.net... Fri Dec 27 23:26:25 2024 -> ERROR: >> Update failed for database: daily Fri Dec 27 23:26:25 2024 -> ERROR: >> Database update process failed: Connection failed Fri Dec 27 23:26:25 >> 2024 -> ERROR: Update failed. > > Hmmm. When this failure occurred the first time, did you think to check > if the daily.cvd file was accessible before blaming freshclam. > > Testing here, I get > > [d:\tmp]wgetx https://database.clamav.net/daily.cvd > * wget --no-check-certificate -N ` https://database.clamav.net/daily.cvd` > wget --no-check-certificate -N ` https://database.clamav.net/daily.cvd` > --2024-12-27 18:10:53-- https://database.clamav.net/daily.cvd Resolving > database.clamav.net (database.clamav.net)... 104.16.218.84, 104.16.219.84 > Connecting to database.clamav.net > (database.clamav.net)|104.16.218.84|:443... connected. HTTP request sent, > awaiting response... 403 Forbidden > 2024-12-27 18:10:54 ERROR 403: Forbidden. > > This in and of itself may not be a useful test since freshclam does not > appear to download daily.cvd but rather downloads the files needed to > update your local copy of daily.cvd. I'll do some more testing tomorrow, > if time permits. > > Running freshclam here worked perfectly and I neglected to log the > requested URLs. > > Steven Hi, i believe that freshclam porting has some issue with paths since sometimes it download correctly all the small files that will update daily.cdv in a tmp subdir, but after it fails and i don't understand messages like this one: Sat Dec 28 21:35:23 2024 -> ~[LibClamAV] cli_rmdirs: Can't locate X:/usr/local/clamav/share/clamav/tmp.e77cb458f0: No such file or directory about this one instead: Fri Dec 27 23:26:25 2024 -> WARNING: Download failed (77) Fri Dec 27 23:26:25 2024 -> WARNING: Message: Problem with the SSL CA cert (path? access rights?) i've finally fixed it with: set CURL_CA_BUNDLE=X:\etc\pki\ca-trust\extracted\pem\tls-ca-bundle.pem as from clamav docs: https://docs.clamav.net/faq/faq-freshclam.html#:~:text=First%20you%20may%20try%20installing%20the%20ca-certificates%20package.,path%20of%20the%20CA%20bundle%20on%20your%20system. let's see in the next days what happens with updates massmo