Mailing List Archive

Re: [ext] ClamAV and Cohesity
> We use Cohesity a lot here in Belgium and inform our customers about the
> app usage of ClamAV.
> This has worked fine in the past but recently we experience at multiple
> customers that the app does no longer renew the signature database.

Which version of clamav is being used? And: How are the updates done?

--
Ralf Hildebrandt
Charité - Universitätsmedizin Berlin
Geschäftsbereich IT | Abteilung Netzwerk

Campus Benjamin Franklin (CBF)
Haus I | 1. OG | Raum 105
Hindenburgdamm 30 | D-12203 Berlin

Tel. +49 30 450 570 155
ralf.hildebrandt@charite.de
https://www.charite.de
_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat
Re: [ext] ClamAV and Cohesity [ In reply to ]
In Cohesity I see:

Version
ClamAV 0.102.2
Antivirus Signature Database Bytecode: 333, Daily: 26439, Main: 62
Last updated: 2/1/22, 12:30 PM

That last update is strange because the system and ClamAV have only been
installed in December 2022.
So is this a default date or not, I don't know.

The Cohesity app is configured to use database servers 'database.clamav.net'
and 'db.us.clamav.net' which seem to be existing and correct.



regards

Steven


On Mon, May 22, 2023 at 11:19?AM Ralf Hildebrandt via clamav-users <
clamav-users@lists.clamav.net> wrote:

> > We use Cohesity a lot here in Belgium and inform our customers about the
> > app usage of ClamAV.
> > This has worked fine in the past but recently we experience at multiple
> > customers that the app does no longer renew the signature database.
>
> Which version of clamav is being used? And: How are the updates done?
>
> --
> Ralf Hildebrandt
> Charité - Universitätsmedizin Berlin
> Geschäftsbereich IT | Abteilung Netzwerk
>
> Campus Benjamin Franklin (CBF)
> Haus I | 1. OG | Raum 105
> Hindenburgdamm 30 | D-12203 Berlin
>
> Tel. +49 30 450 570 155
> ralf.hildebrandt@charite.de
> https://www.charite.de
> _______________________________________________
>
> Manage your clamav-users mailing list subscription / unsubscribe:
> https://lists.clamav.net/mailman/listinfo/clamav-users
>
>
> Help us build a comprehensive ClamAV guide:
> https://github.com/Cisco-Talos/clamav-documentation
>
> https://docs.clamav.net/#mailing-lists-and-chat
>
Re: [ext] ClamAV and Cohesity [ In reply to ]
* steven aldenkamp <steven.aldenkamp@gmail.com>:
> In Cohesity I see:
>
> Version
> ClamAV 0.102.2
> Antivirus Signature Database Bytecode: 333, Daily: 26439, Main: 62
> Last updated: 2/1/22, 12:30 PM

https://endoflife.date/clamav

I guess 0.102.x is EOLsince Jan 2022 (thus the "Last updated")

https://docs.clamav.net/faq/faq-eol.html

So best would be if there was an update to ClamAV 0.103 or better
still 1.0

"Each LTS feature release will be supported with access to download
signatures for the duration of the three year support period plus one
additional year."

and

"Non-LTS feature releases will be allowed access to download
signatures until at least four (4) months after the next-next feature
release is published."

--
Ralf Hildebrandt
Charité - Universitätsmedizin Berlin
Geschäftsbereich IT | Abteilung Netzwerk

Campus Benjamin Franklin (CBF)
Haus I | 1. OG | Raum 105
Hindenburgdamm 30 | D-12203 Berlin

Tel. +49 30 450 570 155
ralf.hildebrandt@charite.de
https://www.charite.de
_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat
Re: [ext] ClamAV and Cohesity [ In reply to ]
Thanks.

Apparently the info I gave earlier was older.

We noticed also
ClamAV 0.103.5
Antivirus Signature Database Bytecode: 333, Daily: 26659, Main: 62
Last updated: 5/11/23, 9:33 AM

So a much more recent update.

But that daily number 26659 seems to stay unchanged but I don't know
exactly what that is.

And we haven't received much info yet from Cohesity either who are the
primary contact for this app although it is ClamAV which runs in the
background.


Steven


On Mon, May 22, 2023 at 2:00?PM Ralf Hildebrandt via clamav-users <
clamav-users@lists.clamav.net> wrote:

> * steven aldenkamp <steven.aldenkamp@gmail.com>:
> > In Cohesity I see:
> >
> > Version
> > ClamAV 0.102.2
> > Antivirus Signature Database Bytecode: 333, Daily: 26439, Main: 62
> > Last updated: 2/1/22, 12:30 PM
>
> https://endoflife.date/clamav
>
> I guess 0.102.x is EOLsince Jan 2022 (thus the "Last updated")
>
> https://docs.clamav.net/faq/faq-eol.html
>
> So best would be if there was an update to ClamAV 0.103 or better
> still 1.0
>
> "Each LTS feature release will be supported with access to download
> signatures for the duration of the three year support period plus one
> additional year."
>
> and
>
> "Non-LTS feature releases will be allowed access to download
> signatures until at least four (4) months after the next-next feature
> release is published."
>
> --
> Ralf Hildebrandt
> Charité - Universitätsmedizin Berlin
> Geschäftsbereich IT | Abteilung Netzwerk
>
> Campus Benjamin Franklin (CBF)
> Haus I | 1. OG | Raum 105
> Hindenburgdamm 30 | D-12203 Berlin
>
> Tel. +49 30 450 570 155
> ralf.hildebrandt@charite.de
> https://www.charite.de
> _______________________________________________
>
> Manage your clamav-users mailing list subscription / unsubscribe:
> https://lists.clamav.net/mailman/listinfo/clamav-users
>
>
> Help us build a comprehensive ClamAV guide:
> https://github.com/Cisco-Talos/clamav-documentation
>
> https://docs.clamav.net/#mailing-lists-and-chat
>
Re: [ext] ClamAV and Cohesity [ In reply to ]
steven aldenkamp via clamav-users wrote:
> Thanks.
>
> Apparently the info I gave earlier was older.
>
> We noticed also
> ClamAV 0.103.5

This is still three minor patch releases behind the current one in the
0.103 series, and IIRC there were some low-grade security fixes in that
span.

It should still be receiving signature updates though.

> And we haven't received much info yet from Cohesity either who are the
> primary contact for this app although it is ClamAV which runs in the
> background.

If some third party is bundling ClamAV, it's up to them to keep it
properly up to date.

-kgd
_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat