ZhangHuangbin wrote:*) Did you check whether you have duplicate parameters of below two in Amavisd config files?
$virus_quarantine_to =
$virus_quarantine_method =
The error message you posted in first post shows Amavisd trying to release quarantined file from local file system, not from SQL database.
*) When a virus mail was quarantined, any related log in mail log file (/var/log/maillog)? Did you see new SQL record in SQL table "amavisd.quarantine"?
I see that mail in iRedAdmin-Pro .
This is log from /var/log/maillog
Oct 15 16:03:52 poruke postfix/smtpd[17717]: Anonymous TLS connection established from unknown[192.168.1.133]: TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)
Oct 15 16:03:52 poruke postfix/smtpd[17717]: DE9BB1815E1: client=unknown[192.168.1.133], sasl_method=PLAIN, sasl_username=xxxxxxxx
Oct 15 16:03:54 poruke postfix/cleanup[17721]: DE9BB1815E1: message-id=<525D4B48.2040801@xxxxxxxx>
Oct 15 16:03:54 poruke postfix/qmgr[2197]: DE9BB1815E1: from=<aleksandar.sasa.glumac@xxxxxxxx>, size=2580, nrcpt=2 (queue active)
Oct 15 16:03:54 poruke postfix/smtpd[17717]: disconnect from unknown[192.168.1.133]
Oct 15 16:03:54 poruke postfix/smtpd[17735]: connect from xxxxxxxx[127.0.0.1]
Oct 15 16:03:54 poruke postfix/smtpd[17735]: 4079618160C: client=xxxxxxxx[127.0.0.1]
Oct 15 16:03:54 poruke postfix/cleanup[17721]: 4079618160C: message-id=<20131015140354.4079618160C@xxxxxxxx>
Oct 15 16:03:54 poruke postfix/smtpd[17736]: connect from xxxxxxxx[127.0.0.1]
Oct 15 16:03:54 poruke postfix/smtpd[17736]: 4958D18160D: client=xxxxxxxx[127.0.0.1]
Oct 15 16:03:54 poruke postfix/cleanup[17737]: 4958D18160D: message-id=<20131015140354.4958D18160D@xxxxxxxx>
Oct 15 16:03:54 poruke postfix/smtpd[17735]: disconnect from xxxxxxxx.hr[127.0.0.1]
Oct 15 16:03:54 poruke postfix/qmgr[2197]: 4079618160C: from=<postmaster@xxxxxxxx>, size=1772, nrcpt=1 (queue active)
Oct 15 16:03:54 poruke postfix/qmgr[2197]: 4958D18160D: from=<postmaster@xxxxxxxx>, size=1772, nrcpt=1 (queue active)
Oct 15 16:03:54 poruke postfix/smtpd[17736]: disconnect from xxxxxxxx[127.0.0.1]
Oct 15 16:03:54 poruke postfix/smtp[17729]: DE9BB1815E1: to=<test1@xxxxxxxx>, relay=127.0.0.1[127.0.0.1]:10024, delay=1.5, delays=1.1/0.02/0.01/0.32, dsn=5.7.0, status=bounced (host 127.0.0.1[127.0.0.1] said: 554 5.7.0 Reject, id=17713-01 - INFECTED: (in reply to end of DATA command))
Oct 15 16:03:55 poruke postfix/pipe[17739]: 4958D18160D: to=<admin@xxxxxxxx>, relay=dovecot, delay=1, delays=0.06/0.04/0/0.92, dsn=2.0.0, status=sent (delivered via dovecot service)
Oct 15 16:03:55 poruke postfix/qmgr[2197]: 4958D18160D: removed
Oct 15 16:03:55 poruke postfix/pipe[17738]: 4079618160C: to=<admin@xxxxxxxx>, relay=dovecot, delay=1.1, delays=0.08/0.02/0/1, dsn=2.0.0, status=sent (delivered via dovecot service)
Oct 15 16:03:55 poruke postfix/qmgr[2197]: 4079618160C: removed
Oct 15 16:03:55 poruke postfix/smtp[17728]: DE9BB1815E1: to=<test3@yyyyyyy>, relay=127.0.0.1[127.0.0.1]:10024, delay=1.6, delays=1.1/0.01/0.01/0.43, dsn=5.7.0, status=bounced (host 127.0.0.1[127.0.0.1] said: 554 5.7.0 Reject, id=17712-01 - INFECTED: (in reply to end of DATA command))
Oct 15 16:03:55 poruke postfix/cleanup[17721]: 8FA1518160C: message-id=<20131015140355.8FA1518160C@xxxxxxxx>
Oct 15 16:03:55 poruke postfix/bounce[17740]: DE9BB1815E1: sender non-delivery notification: 8FA1518160C
Oct 15 16:03:55 poruke postfix/qmgr[2197]: 8FA1518160C: from=<>, size=4980, nrcpt=1 (queue active)
Oct 15 16:03:55 poruke postfix/qmgr[2197]: DE9BB1815E1: removed
Oct 15 16:03:55 poruke postfix/pipe[17739]: 8FA1518160C: to=<aleksandar.sasa.glumac@xxxxxxxx>, relay=dovecot, delay=0.06, delays=0/0/0/0.05, dsn=2.0.0, status=sent (delivered via dovecot service)
Oct 15 16:03:55 poruke postfix/qmgr[2197]: 8FA1518160C: removed
this is the amavisd config :
use strict;
$max_servers = 2; # num of pre-forked children (2..30 is common), -m
$daemon_user = 'amavis'; # (no default; customary: vscan or amavis), -u
$daemon_group = 'amavis'; # (no default; customary: vscan or amavis), -g
$mydomain = "poruke.yyyyyyyyyyyyyyyy"; # = 'example.com'; # a convenient default for other settings
$MYHOME = '/var/spool/amavisd'; # a convenient default for other settings, -H
$TEMPBASE = "$MYHOME/tmp"; # working directory, needs to exist, -T
$ENV{TMPDIR} = $TEMPBASE; # environment variable TMPDIR, used by SA, etc.
$QUARANTINEDIR = "/var/spool/amavisd/quarantine";
$db_home = "$MYHOME/db"; # dir for bdb nanny/cache/snmp databases, -D
$lock_file = "/var/run/amavisd/amavisd.lock"; # -L
$pid_file = "/var/run/amavisd/amavisd.pid"; # -P
$log_level = 1; # verbosity 0..5, -d
$log_recip_templ = undef; # disable by-recipient level-0 log entries
$DO_SYSLOG = 1; # log via syslogd (preferred)
$syslog_facility = 'local6'; # Syslog facility as a string
# e.g.: mail, daemon, user, local0, ... local7
$syslog_priority = 'debug'; # Syslog base (minimal) priority as a string,
# choose from: emerg, alert, crit, err, warning, notice, info, debug
$enable_db = 1; # enable use of BerkeleyDB/libdb (SNMP and nanny)
$enable_global_cache = 1; # enable use of libdb-based cache if $enable_db=1
$nanny_details_level = 2; # nanny verbosity: 1: traditional, 2: detailed
$enable_dkim_verification = 1; # enable DKIM signatures verification
$enable_dkim_signing = 1; # load DKIM signing code, keys defined by dkim_key
@local_domains_maps = ( [".$mydomain","xxxxxxxxxxx"] ); # list of all local domains
@mynetworks = qw( 127.0.0.0/8 [::1] [FE80::]/10 [FEC0::]/10
10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 );
$unix_socketname = "$MYHOME/amavisd.sock"; # amavisd-release or amavis-milter
# option(s) -p overrides $inet_socket_port and $unix_socketname
$inet_socket_port = [10024, 9998];
$policy_bank{'MYNETS'} = { # mail originating from @mynetworks
originating => 1, # is true in MYNETS by default, but let's make it explicit
os_fingerprint_method => undef, # don't query p0f for internal clients
allow_disclaimers => 1, # enables disclaimer insertion if available
};
$interface_policy{'10026'} = 'ORIGINATING';
$policy_bank{'ORIGINATING'} = { # mail supposedly originating from our users
originating => 1, # declare that mail was submitted by our smtp client
allow_disclaimers => 1, # enables disclaimer insertion if available
# notify administrator of locally originating malware
virus_admin_maps => ["admin\@yyyyyyyyyyyyyyyy"],
spam_admin_maps => ["admin\@yyyyyyyyyyyyyyyy"],
warnbadhsender => 1,
# forward to a smtpd service providing DKIM signing service
forward_method => 'smtp:[127.0.0.1]:10027',
# force MTA conversion to 7-bit (e.g. before DKIM signing)
smtpd_discard_ehlo_keywords => ['8BITMIME'],
bypass_banned_checks_maps => [1], # allow sending any file names and types
terminate_dsn_on_notify_success => 0, # don't remove NOTIFY=SUCCESS option
};
$interface_policy{'SOCK'} = 'AM.PDP-SOCK'; # only applies with $unix_socketname
$policy_bank{'AM.PDP-SOCK'} = {
protocol => 'AM.PDP',
auth_required_release => 0, # do not require secret_id for amavisd-release
};
$sa_tag_level_deflt = 2.0; # add spam info headers if at, or above that level
$sa_tag2_level_deflt = 6.2; # add 'spam detected' headers at that level
$sa_kill_level_deflt = 6.9; # triggers spam evasive actions (e.g. blocks mail)
$sa_dsn_cutoff_level = 10; # spam level beyond which a DSN is not sent
$sa_crediblefrom_dsn_cutoff_level = 18; # likewise, but for a likely valid From
$penpals_bonus_score = 8; # (no effect without a @storage_sql_dsn database)
$penpals_threshold_high = $sa_kill_level_deflt; # don't waste time on hi spam
$bounce_killer_score = 100; # spam score points to add for joe-jobbed bounces
$sa_mail_body_size_limit = 400*1024; # don't waste time on SA if mail is larger
$sa_local_tests_only = 0; # only tests which do not require internet access?
$virus_admin = undef; # notifications recip.
$mailfrom_notify_admin = undef; # notifications sender
$mailfrom_notify_recip = undef; # notifications sender
$mailfrom_notify_spamadmin = undef; # notifications sender
$mailfrom_to_quarantine = ''; # null return path; uses original sender if undef
@addr_extension_virus_maps = ('virus');
@addr_extension_banned_maps = ('banned');
@addr_extension_spam_maps = ('spam');
@addr_extension_bad_header_maps = ('badh');
$path = '/usr/local/sbin:/usr/local/bin:/usr/sbin:/sbin:/usr/bin:/bin';
$MAXLEVELS = 14;
$MAXFILES = 1500;
$MIN_EXPANSION_QUOTA = 100*1024; # bytes (default undef, not enforced)
$MAX_EXPANSION_QUOTA = 300*1024*1024; # bytes (default undef, not enforced)
$sa_spam_subject_tag = '***SPAM*** ';
$defang_virus = 1; # MIME-wrap passed infected mail
$defang_banned = 0; # MIME-wrap passed mail containing banned name
$defang_by_ccat{+CC_BADH.",3"} = 1; # NUL or CR character in header
$defang_by_ccat{+CC_BADH.",5"} = 1; # header line longer than 998 characters
$defang_by_ccat{+CC_BADH.",6"} = 1; # header field syntax error
@keep_decoded_original_maps = (new_RE(
qr'^MAIL$', # retain full original message for virus checking
qr'^MAIL-UNDECIPHERABLE$', # recheck full mail if it contains undecipherables
qr'^(ASCII(?! cpio)|text|uuencoded|xxencoded|binhex)'i,
));
$banned_filename_re = new_RE(
qr'^\.(exe-ms|dll)$', # banned file(1) types, rudimentary
### BLOCK THE FOLLOWING, EXCEPT WITHIN UNIX ARCHIVES:
# [ qr'^\.(gz|bz2)$' => 0 ], # allow any in gzip or bzip2
[ qr'^\.(rpm|cpio|tar)$' => 0 ], # allow any in Unix-type archives
qr'.\.(pif|scr)$'i, # banned extensions - rudimentary
qr'^application/x-msdownload$'i, # block these MIME types
qr'^application/x-msdos-program$'i,
qr'^application/hta$'i,
qr'^(?!cid:).*\.[^./]*[A-Za-z][^./]*\.\s*(exe|vbs|pif|scr|bat|cmd|com|cpl|dll)[.\s]*$'i,
qr'.\.(exe|vbs|pif|scr|cpl)$'i, # banned extension - basic
);
@score_sender_maps = ({ # a by-recipient hash lookup table,
# results from all matching recipient tables are summed
## site-wide opinions about senders (the '.' matches any recipient)
'.' => [ # the _first_ matching sender determines the score boost
new_RE( # regexp-type lookup table, just happens to be all soft-blacklist
[qr'^(bulkmail|offers|cheapbenefits|earnmoney|foryou)@'i => 5.0],
[qr'^(greatcasino|investments|lose_weight_today|market\.alert)@'i=> 5.0],
[qr'^(money2you|MyGreenCard|new\.tld\.registry|opt-out|opt-in)@'i=> 5.0],
[qr'^(optin|saveonlsmoking2002k|specialoffer|specialoffers)@'i => 5.0],
[qr'^(stockalert|stopsnoring|wantsome|workathome|yesitsfree)@'i => 5.0],
[qr'^(your_friend|greatoffers)@'i => 5.0],
[qr'^(inkjetplanet|marketopt|MakeMoney)\d*@'i => 5.0],
),
# read_hash("/var/amavis/sender_scores_sitewide"),
{ # a hash-type lookup table (associative array)
'nobody@cert.org' => -3.0,
'cert-advisory@us-cert.gov' => -3.0,
'owner-alert@iss.net' => -3.0,
'slashdot@slashdot.org' => -3.0,
'securityfocus.com' => -3.0,
'ntbugtraq@listserv.ntbugtraq.com' => -3.0,
'security-alerts@linuxsecurity.com' => -3.0,
'mailman-announce-admin@python.org' => -3.0,
'amavis-user-admin@lists.sourceforge.net'=> -3.0,
'amavis-user-bounces@lists.sourceforge.net' => -3.0,
'spamassassin.apache.org' => -3.0,
'notification-return@lists.sophos.com' => -3.0,
'owner-postfix-users@postfix.org' => -3.0,
'owner-postfix-announce@postfix.org' => -3.0,
'owner-sendmail-announce@lists.sendmail.org' => -3.0,
'sendmail-announce-request@lists.sendmail.org' => -3.0,
'donotreply@sendmail.org' => -3.0,
'ca+envelope@sendmail.org' => -3.0,
'noreply@freshmeat.net' => -3.0,
'owner-technews@postel.acm.org' => -3.0,
'ietf-123-owner@loki.ietf.org' => -3.0,
'cvs-commits-list-admin@gnome.org' => -3.0,
'rt-users-admin@lists.fsck.com' => -3.0,
'clp-request@comp.nus.edu.sg' => -3.0,
'surveys-errors@lists.nua.ie' => -3.0,
'emailnews@genomeweb.com' => -5.0,
'yahoo-dev-null@yahoo-inc.com' => -3.0,
'returns.groups.yahoo.com' => -3.0,
'clusternews@linuxnetworx.com' => -3.0,
lc('lvs-users-admin@LinuxVirtualServer.org') => -3.0,
lc('owner-textbreakingnews@CNNIMAIL12.CNN.COM') => -5.0,
# soft-blacklisting (positive score)
'sender@example.net' => 3.0,
'.example.net' => 1.0,
},
], # end of site-wide tables
});
@decoders = (
['mail', \&do_mime_decode],
['asc', \&do_ascii],
['uue', \&do_ascii],
['hqx', \&do_ascii],
['ync', \&do_ascii],
['F', \&do_uncompress, ['unfreeze','freeze -d','melt','fcat'] ],
['Z', \&do_uncompress, ['uncompress','gzip -d','zcat'] ],
['gz', \&do_uncompress, 'gzip -d'],
['gz', \&do_gunzip],
['bz2', \&do_uncompress, 'bzip2 -d'],
['lzo', \&do_uncompress, 'lzop -d'],
['rpm', \&do_uncompress, ['rpm2cpio.pl','rpm2cpio'] ],
['cpio', \&do_pax_cpio, ['pax','gcpio','cpio'] ],
['tar', \&do_pax_cpio, ['pax','gcpio','cpio'] ],
['deb', \&do_ar, 'ar'],
# ['a', \&do_ar, 'ar'], # unpacking .a seems an overkill
['zip', \&do_unzip],
['7z', \&do_7zip, ['7zr','7za','7z'] ],
['rar', \&do_unrar, ['rar','unrar'] ],
['arj', \&do_unarj, ['arj','unarj'] ],
['arc', \&do_arc, ['nomarch','arc'] ],
['zoo', \&do_zoo, ['zoo','unzoo'] ],
['lha', \&do_lha, 'lha'],
# ['doc', \&do_ole, 'ripole'],
['cab', \&do_cabextract, 'cabextract'],
['tnef', \&do_tnef_ext, 'tnef'],
['tnef', \&do_tnef],
# ['sit', \&do_unstuff, 'unstuff'], # broken/unsafe decoder
['exe', \&do_executable, ['rar','unrar'], 'lha', ['arj','unarj'] ],
);
$sa_debug = 0;
$myhostname = "poruke.yyyyyyyyyyyyyyyy";
$notify_method = 'smtp:[127.0.0.1]:10025';
$forward_method = 'smtp:[127.0.0.1]:10025';
$final_virus_destiny = D_REJECT;
$final_banned_destiny = D_PASS;
$final_spam_destiny = D_PASS;
$final_bad_header_destiny = D_PASS;
@av_scanners = (
#### http://www.clamav.net/
['ClamAV-clamd',
\&ask_daemon, ["CONTSCAN {}\n", "/tmp/clamd.socket"],
qr/\bOK$/, qr/\bFOUND$/,
qr/^.*?: (?!Infected Archive)(.*) FOUND$/ ],
);
@av_scanners_backup = (
### http://www.clamav.net/ - backs up clamd or Mail::ClamAV
['ClamAV-clamscan', 'clamscan',
"--stdout --disable-summary -r --tempdir=$TEMPBASE {}", [0], [1],
qr/^.*?: (?!Infected Archive)(.*) FOUND$/ ],
);
$policy_bank{'MYUSERS'} = {
# declare that mail was submitted by our smtp client
originating => 1,
# enables disclaimer insertion if available
allow_disclaimers => 1,
# notify administrator of locally originating malware
virus_admin_maps => ["admin\@yyyyyyyyyyyyyyyy"],
spam_admin_maps => ["admin\@yyyyyyyyyyyyyyyy"],
warnbadhsender => 0,
# forward to a smtpd service providing DKIM signing service
#forward_method => 'smtp:[127.0.0.1]:10027',
# force MTA conversion to 7-bit (e.g. before DKIM signing)
smtpd_discard_ehlo_keywords => ['8BITMIME'],
# don't remove NOTIFY=SUCCESS option
terminate_dsn_on_notify_success => 0,
# don't perform spam/virus/header check.
#bypass_spam_checks_maps => [1],
#bypass_virus_checks_maps => [1],
#bypass_header_checks_maps => [1],
# allow sending any file names and types
#bypass_banned_checks_maps => [1],
};
protocol => 'AM.PDP', # select Amavis policy delegation protocol
inet_acl => [qw( 127.0.0.1 [::1] )], # restrict access to these IP addresses
auth_required_release => 1, # 0 - don't require secret_id for amavisd-release
#log_level => 4,
#always_bcc_by_ccat => {CC_CLEAN, 'admin@example.com'},
};
#########################
# Quarantine mails.
#
# Don't quarantine mails with bad header.
$bad_header_quarantine_method = undef;
$spam_quarantine_method = undef;
#########################
# Quarantine VIRUS mails.
#
$virus_quarantine_to = 'virus-quarantine';
$virus_quarantine_method = 'sql:';
#########################
# Quarantine BANNED mails.
$banned_files_quarantine_method = undef;
$sa_spam_modifies_subj = 1;
$warnvirussender = 1;
$warnspamsender = 0;
$warnbannedsender = 0;
$warnbadhsender = 0;
$warn_offsite = 1;
$notify_sender_templ = read_text('/var/amavis/notify_sender.txt');
$notify_virus_sender_templ= read_text('/var/amavis/notify_virus_sender.txt');
$notify_virus_admin_templ = read_text('/var/amavis/notify_virus_admin.txt');
$notify_virus_recips_templ= read_text('/var/amavis/notify_virus_recips.txt');
$notify_spam_sender_templ = read_text('/var/amavis/notify_spam_sender.txt');
$notify_spam_admin_templ = read_text('/var/amavis/notify_spam_admin.txt');
$sql_allow_8bit_address = 1;
$timestamp_fmt_mysql = 1;
$undecipherable_subject_tag = undef;
$smtp_connection_cache_enable = 0;
$signed_header_fields{'received'} = 0;
$signed_header_fields{'to'} = 1;
$originating = 1;
# Add dkim_key here.
dkim_key("yyyyyyyyyyyyyyyy", "dkim", "/var/lib/dkim/yyyyyyyyyyyyyyyy.pem");
@dkim_signature_options_bysender_maps = ( {
# ------------------------------------
# For domain: yyyyyyyyyyyyyyyy.
# ------------------------------------
# 'd' defaults to a domain of an author/sender address,
# 's' defaults to whatever selector is offered by a matching key
#'postmaster@yyyyyyyyyyyyyyyy' => { d => "yyyyyyyyyyyyyyyy", a => 'rsa-sha256', ttl => 7*24*3600 },
#"spam-reporter@yyyyyyyyyyyyyyyy" => { d => "yyyyyyyyyyyyyyyy", a => 'rsa-sha256', ttl => 7*24*3600 },
# explicit 'd' forces a third-party signature on foreign (hosted) domains
"yyyyyyyyyyyyyyyy" => { d => "yyyyyyyyyyyyyyyy", a => 'rsa-sha256', ttl => 10*24*3600 },
#"host1.yyyyyyyyyyyyyyyy" => { d => "host1.yyyyyyyyyyyyyyyy", a => 'rsa-sha256', ttl => 10*24*3600 },
#"host2.yyyyyyyyyyyyyyyy" => { d => "host2.yyyyyyyyyyyyyyyy", a => 'rsa-sha256', ttl => 10*24*3600 },
# ---- End domain: yyyyyyyyyyyyyyyy ----
# catchall defaults
'.' => { a => 'rsa-sha256', c => 'relaxed/simple', ttl => 30*24*3600 },
} );
$altermime = '/usr/bin/altermime';
# Disclaimer in plain text formart.
@altermime_args_disclaimer = qw(--disclaimer=/etc/postfix/disclaimer/_OPTION_.txt --disclaimer-html=/etc/postfix/disclaimer/_OPTION_.txt --force-for-bad-html);
@disclaimer_options_bysender_maps = ({
# Per-domain disclaimer setting: /etc/postfix/disclaimer/host1.iredmail.org.txt
#'host1.iredmail.org' => 'host1.iredmail.org',
# Sub-domain disclaimer setting: /etc/postfix/disclaimer/iredmail.org.txt
#'.iredmail.org' => 'iredmail.org',
# Per-user disclaimer setting: /etc/postfix/disclaimer/boss.iredmail.org.txt
#'boss@iredmail.org' => 'boss.iredmail.org',
# Catch-all disclaimer setting: /etc/postfix/disclaimer/default.txt
'.' => 'default',
},);
# ------------ End Disclaimer Setting ---------------
@storage_sql_dsn = (
['DBI:mysql:database=amavisd;host=127.0.0.1;port=3306', 'amavisd', '2w8EyPWCDZOnRjAjbirg41st9nnTOr'],
);
# Uncomment below two lines to lookup virtual mail domains from MySQL database.
#@lookup_sql_dsn = (
# ['DBI:mysql:database=vmail;host=127.0.0.1;port=3306', 'vmail', 'WcMVoAXZh6vHuqpxKJ5oE67BYjiU6U'],
#);
# For Amavisd-new-2.7.0 and later versions. Placeholder '%d' is available in Amavisd-2.7.0+.
#$sql_select_policy = "SELECT domain FROM domain WHERE domain='%d'";
# For Amavisd-new-2.6.x.
# WARNING: IN() may cause MySQL lookup performance issue.
#$sql_select_policy = "SELECT domain FROM domain WHERE CONCAT('@', domain) IN (%k)";
1; # insure a defined return