Manually applying the definition files to ClamAV for RSA Authentication Manager 8.x
Originally Published: 2014-12-21
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.0, 8.1, 8.2
Issue
WARNING: Clamd was NOT notified: Can't connect to clamd through /var/lib/clamav/clamd-socket:
No such file or directoryTasks
- Log on to the RSA Authentication Manager 8.2 operating system with the rsaadmin account, either via the local console or SSH (where SSH has been enabled in the Operations Console).
- ClamAV requires root privileges to be updated or used to scan the operating system files, so elevate privileges with the command sudo su - root.
- Enter the rsaadmin password when prompted.
- Use the command touch /var/lib/clamav/clamd-socket. This will remove the warning regarding the/var/lib/clamav/clamd-socket when running freshclam
Resolution
ClamAV definition files can be manually downloaded from http://database.clamav.net/main.cvd, http://database.clamav.net/daily.cvd and http://database.clamav.net/bytecode.cvd. Note: These files are current as of December 2014.
Steps to manually apply the new definition files and use ClamAV
- Download the ClamAV definition files mentioned above.
- Log on to the RSA Authentication Manager 8.1 operating system with the rsaadmin account, either via the local console or SSH (where SSH has been enabled in the Operations Console).
- ClamAV requires root privileges to be updated or used to scan the operating system files, so elevate privileges with the command sudo su - root.
- Enter the rsaadmin password when prompted.
- Create a working directory in /tmp, for example, /tmp/clamav.
- Using a secure FTP client (such as WinSCP), copy the main.cvd, daily.cvd and bytecode.cvd files to the working folder.
- Copy the *.cvd files to /var/lib/clamav.
- Run the ClamAV software with the command clamscan -r / --exclude-dir=/proc --exclude-dir=/sys --exclude-dir=/opt/rsa/am/rsapgdata --follow-dir-symlinks=0 --follow-file-symlinks=0 --log=/var/log/clamav.log.
- The files being scanned will appear in the session. Review the /var/log/clamav.log file when the command line returns.
login as: rsaadmin Using keyboard-interactive authentication. Password: <enter operating system password> Last login: Tue Jan 24 16:35:53 2017 from jumphost.vcloud.local RSA Authentication Manager Installation Directory: /opt/rsa/am rsaadmin@am81p:~> sudo su - root rsaadmin's password: <enter operating system password> am81p:~ # sudo /usr/bin/freshclam am81p:~ # mkdir /tmp/clamav am81p:~ # cp /tmp/clamav/*.cvd /var/lib/clamav am81p:~ # clamscan -r / --exclude-dir=/proc --exclude-dir=/sys --exclude-dir=/opt/rsa/am/rsapgdata --follow-dir-symlinks=0 --follow-file-symlinks=0 --log=/var/log/clamav.log
Notes
login as: rsaadmin Using keyboard-interactive authentication. Password: <enter operating system password> Last login: Tue Jan 24 16:35:53 2017 from jumphost.vcloud.local RSA Authentication Manager Installation Directory: /opt/rsa/am rsaadmin@am81p:~> sudo su - root rsaadmin's password: <enter operating system password> am81p:~ # sudo /usr/bin/freshclam ClamAV update process started at Sun Dec 21 15:44:56 2014 WARNING: Your ClamAV installation is OUTDATED! WARNING: Local version: 0.98.3 Recommended version: 0.98.5 DON'T PANIC! Read http://www.clamav.net/support/faq Downloading main.cvd [100%] main.cvd updated (version: 55, sigs: 2424225, f-level: 60, builder: neo) Downloading daily.cvd [100%] daily.cvd updated (version: 19815, sigs: 1294259, f-level: 63, builder: neo) nonblock_recv: recv timing out (30 secs) WARNING: getfile: Error while reading database from database.clamav.net (IP: 128.199.133.36): Operation now in progress WARNING: Can't download bytecode.cvd from database.clamav.net Trying again in 5 secs... ClamAV update process started at Sun Dec 21 17:06:51 2014 WARNING: Your ClamAV installation is OUTDATED! WARNING: Local version: 0.98.3 Recommended version: 0.98.5 DON'T PANIC! Read http://www.clamav.net/support/faq main.cvd is up to date (version: 55, sigs: 2424225, f-level: 60, builder: neo) WARNING: getfile: daily-19816.cdiff not found on remote server (IP: 150.214.142.197) WARNING: getpatch: Can't download daily-19816.cdiff from database.clamav.net nonblock_recv: recv timing out (30 secs) WARNING: getfile: Error while reading database from database.clamav.net (IP: 65.19.179.67): Operation now in progress WARNING: getpatch: Can't download daily-19816.cdiff from database.clamav.net Downloading daily-19816.cdiff [100%] daily.cld updated (version: 19816, sigs: 1294480, f-level: 63, builder: neo) Downloading bytecode.cvd [100%] bytecode.cvd updated (version: 244, sigs: 44, f-level: 63, builder: dgoddard) Database updated (3718749 signatures) from database.clamav.net (IP: 200.236.31.1) WARNING: Clamd was NOT notified: Can't connect to clamd through /var/lib/clamav/clamd-socket: No such file or directory rsaadmin@app81p:~>This WARNING can be safely ignored:
WARNING: Clamd was NOT notified: Can't connect to clamd through /var/lib/clamav/clamd-socket: No such file or directory
Related Articles
Error during migration: Error: Failed to massage migrated data org.postgresql.util.PSQLException: ERROR: update or delete… 57Number of Views Windows Agent failing to authenticate local Group Membership with 30 Secs timeout 118Number of Views RSA Authentication Manager 8.1 SP 1 patch 1 backups to a Windows Shared Folder are failing after software upgrade 242Number of Views RSA Identity Governance and Lifecycle RESTful web service response: java.lang.IllegalStateException 275Number of Views Failed to validate remote location error when configuring backups to Windows Shared Folder in RSA Authentication Manager 8.x 1.44KNumber of Views
Trending Articles
How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?