Koozali.org: home of the SME Server

SME E-Mail - Either SMTP or ClamAV problem

technostruct

SME E-Mail - Either SMTP or ClamAV problem
« on: August 11, 2004, 01:36:38 PM »
Hello everyone, thanks for taking the time to read, hope I make sense here.

I've setup SME Server 6.0.1, setup e-mail (Primary domain), and setup Webmail (HTTPS-Only).  I setup the Swerts-Knudsen ClamAV-addon, and it seems to be working well ... until I tried to send e-mail via Webmail.  Now this is a clean setup - nobody's been on the server as yet except me.  I've also got the "admin" and "postmaster" accounts forwarding mail to my account.

I sent an e-mail to the people I created an e-mail account for last night, via Webmail interface, in my account, ... and got the following message (personal details replaced by "xxx":
------------------------------------------------------
The message has been quarantined as
4119e59f-3069.msg

The corresponding logfile has been written to
4119e59f-3069.log


Message headers follow:
Received: from localhost (127.0.0.1)
  by xxxxxxxxx (127.0.0.1) with ESMTP; 11 Aug 2004
09:23:41 -0000
Received: from xxxxxx ([xxxxxx2])
by xxxxxxxxxxxxx (IMP) with HTTP
for <xxxxxxx@localhost>; Wed, 11 Aug 2004 02:23:40 -0700
Message-ID: <1092216220.4119e59ce4e36@xxxxxxxxxxxxxx>
Date: Wed, 11 Aug 2004 02:23:40 -0700
From: xxxxx@xxxxxxxxx.net
To: xxxxxxxx, xxxxxxxx, xxxxxxx
Subject: xxxxxxxxxxxxx
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
User-Agent: Internet Messaging Program (IMP) 3.2.1
X-Originating-IP: xxxxxxxxxx
X-Sent-Via: Mitel Networks SME Server
-----------------------------------------------------

Now that looks a whole lot like the ClamAV scanner stopping the e-mail and quarantining it.  That's just strange, too, because I've not sent anything TO the account yet.  How could a virus be propogating ?  I've also got BitDefender scanning all the I-Bays for viruses too ...

Now I'm sure there's details I've left out, ask and ye shall receive them.  I was just so happy to get these items working ... now I'm rather bummed. :-(

technostruct

SME E-Mail - Either SMTP or ClamAV problem
« Reply #1 on: August 11, 2004, 08:16:38 PM »
I did get smart - I got the updated/webGUI interface update of Amavis-ClamAV, and I was able to release all these back into the queue.  I'll have to see if a reboot helped it at all or not, though.  Link to the WebGUI interface (update?) found here: http://www.pagefault.org/howto/amavis_clam.shtml.

And now I am able to read an improved, specific e-mail error message that tells me what the reasoning was:

"Error: Cannot connect to /var/lib/clamav/clamd.sock."

Now, I've gone through all the Forums and Googled and looked around and it appears to be a SpamAssassin issue.  I swear there's got to be SOME fix for it out there, I just haven't found it yet.

I also see where people are poking at the issue being due to "system specs", which I find very, VERY hard to believe - make sure you tell me why I need to look at specs first, this isn't a MicroCrap WinDump system, I have more faith in it than that.

Offline smeghead

  • *
  • 563
  • +0/-0
SME E-Mail - Either SMTP or ClamAV problem
« Reply #2 on: August 11, 2004, 08:31:14 PM »
don't cross post
..................