[Avcheck] Antivirus with Postfix and DrWeb

Sergey Akhapkin Sergey Akhapkin <asv@drweb.ru>
Mon, 21 Jan 2002 20:43:31 +0300


Hello Nicolai,

Monday, January 21, 2002, 7:17:38 PM, you wrote:

NSG> I'm trying to configure Postfix with the DrWeb antivirus scanner, using AVCheck to pipe the mails to the scanner.
NSG> My current setup doesn't complain in any way(it delivers mail and everything *seems* to work, Avcheck adds a X-AV header), but I can't get it to detect the Eicar testmail(gzipped or not). I'm
NSG> running both in chrooted enviroment, as suggested in the docs.

NSG> When running the test supplied with AVCheck, injecting the eicar.msg, I don't get any response, with no log-entries anywhere. I've set DrWeb to log as much as I can, but nothing shows up there.

NSG> My postfix master.cf:

NSG> localhost:1025  inet n       -      n      -       - smtpd -o content_filter=
NSG> smtp      inet  n       -       n       -       -       smtpd -o content_filter=avcheck
NSG> avcheck    unix -       n      n      -       5      pipe
NSG>         flags=q user=avclient argv=/usr/local/avcheck/avcheck
NSG>         -d /var/spool/drwebtest -h Webpartner -s DrWeb:/usr/local/drweb/run/sock
NSG>         -f ${sender} -S :1025 -- ${recipient}

NSG> Could anyone guide me to where the problem might be, or how I could enable more logging, since I find it pretty hard to get any further, when I get no errors or the likes in return to my
NSG> attempts.

Sorry, excuse me for a stupid questions:
Are you see running drwebd ?
What you see in daemon log after it start ? (Could be key file not loaded)

-- 
Best regards,
 Sergey                            mailto:asv@drweb.ru