turnersloane
Verified User
- Joined
- Sep 27, 2006
- Messages
- 52
I've been seeing these type of error messages in /var/log/exim/mainlog since about 5am Eastern USA:
2012-01-16 21:53:15 1Rn06l-00084b-Kf malware acl condition: clamd: unable to connect to UNIX socket /usr/local/sbin/clamd (Permission denied)
2012-01-16 21:53:15 1Rn06l-00084b-Kf H=ipxx-xxx-xxx-xxx.mc.at.cox.net ([10.0.0.5]) [xx.xxx.xxx.xxx] F=<[email protected]> temporarily rejected after DATA
No users on this server can send or receive email while this is occuring. I have not performed any updates since Jan 7, 2012 when I updated this particular server to SpamBlocker v4.1. Everything has been working very good.
Troubleshooting shows that if I comment out this section in exim.conf, everything returns to normal.
## deny if email containing virus or other harmful content
#deny message = This message contains a virus or other harmful content (virus_in_message:$malware_name)
#demime = *
#malware = *
But I reinstalled ClamAv via custombuild, just in case....did not have any build errors, ClamAv binds to port 3310, freshclam is running.
More info:
ClamAV 0.97.3/14316/Mon Jan 16 20:23:04 2012
Exim version 4.67 #1 built 22-Apr-2007 19:51:05
SpamBlockerTechnology* powered exim.conf, Version 4.1
As far as I know everything is up to date. The file /usr/local/sbin/clamd exists and is owned by root, should it have a different owner?
Since nothing *appears* to have changed on the server, I'm baffled. I even tried nearly every intelligent solution found here and on other forums, including checking /tmp/clamd.log file size, reinstalling ClamAv, checking file permissions and paths; all seems to be correct - except for the malware acl error.
I'm open for suggestions as I want to update other servers, but obviously am reluctant to do so for now.
Regards,
Sloane
2012-01-16 21:53:15 1Rn06l-00084b-Kf malware acl condition: clamd: unable to connect to UNIX socket /usr/local/sbin/clamd (Permission denied)
2012-01-16 21:53:15 1Rn06l-00084b-Kf H=ipxx-xxx-xxx-xxx.mc.at.cox.net ([10.0.0.5]) [xx.xxx.xxx.xxx] F=<[email protected]> temporarily rejected after DATA
No users on this server can send or receive email while this is occuring. I have not performed any updates since Jan 7, 2012 when I updated this particular server to SpamBlocker v4.1. Everything has been working very good.
Troubleshooting shows that if I comment out this section in exim.conf, everything returns to normal.
## deny if email containing virus or other harmful content
#deny message = This message contains a virus or other harmful content (virus_in_message:$malware_name)
#demime = *
#malware = *
But I reinstalled ClamAv via custombuild, just in case....did not have any build errors, ClamAv binds to port 3310, freshclam is running.
More info:
ClamAV 0.97.3/14316/Mon Jan 16 20:23:04 2012
Exim version 4.67 #1 built 22-Apr-2007 19:51:05
SpamBlockerTechnology* powered exim.conf, Version 4.1
As far as I know everything is up to date. The file /usr/local/sbin/clamd exists and is owned by root, should it have a different owner?
Since nothing *appears* to have changed on the server, I'm baffled. I even tried nearly every intelligent solution found here and on other forums, including checking /tmp/clamd.log file size, reinstalling ClamAv, checking file permissions and paths; all seems to be correct - except for the malware acl error.
I'm open for suggestions as I want to update other servers, but obviously am reluctant to do so for now.
Regards,
Sloane