On 08/01/2010 20:47, Chris Gerhard wrote:
On 08/01/2010 19:52, Joyce McIntosh wrote:
The output of vscan.d shows that it interprets the result from the
scan engine as a successful scan with no virus found. IIRC, it looks
like this is being determined from the scan preview without the need
for a full scan.
Can you get a network packet capture so that we can look in detail at
the scan engine response.
It is attached. We don't appear to be sending the full file to the icap
server.
Comparing the snoop from nvscan to the snoop from icap-client the
options are different. If I use the same options to icap-client then it
will also fail to find the virus. Seems to be a problem with the c-icap
server.
$ /opt/cjgsw/bin/icap\-client -f virus.d/clam.pdf -s "avscan"
ICAP server:localhost, ip:127.0.0.1, port:1344
No modification needed (Allow 204 response)
$
I'll take it up with the c-icap people.
Many thanks
--
Sent from my OpenSolaris Laptop
_______________________________________________
cifs-discuss mailing list
[email protected]
http://mail.opensolaris.org/mailman/listinfo/cifs-discuss