I'm not sure this will help, but can you try using the CURL_CA_BUNDLE 
environment variable to see if that helps?

Ex:

CURL_CA_BUNDLE=/usr/local/share/ca-certificates/cert.crt freshclam

https://docs.clamav.net/faq/faq-freshclam.html?highlight=curl_#problem-with-the-ssl-ca-cert

Regards,
Micah

Micah Snyder
ClamAV Development
Talos
Cisco Systems, Inc.

________________________________
From: clamav-users <clamav-users-boun...@lists.clamav.net> on behalf of Petr 
Novák via clamav-users <clamav-users@lists.clamav.net>
Sent: Monday, April 3, 2023 7:23 AM
To: clamav-users@lists.clamav.net <clamav-users@lists.clamav.net>
Cc: Petr Novák <larry...@gmail.com>
Subject: [clamav-users] ssl peer certificate or ssh remote key was not ok

Hi guys,

I have an issue with freshclam.

We are setting up freshclam clients (Debian 11) which are downloading database 
via private mirror which is using HTTPS. When I tried to use freshclam on my 
Windows client, it worked, but on my Debian Client, I get error message "ssl 
peer certificate or ssh remote key was not ok".

I imported my private mirror's SSL certificate via this method:
cp cert.crt /usr/local/share/ca-certificates/
update-ca-certificates

But even after this, the error still persists.

Is there any way to make this work? I am a beginner in Linux, so I don't really 
know what to do next.

Thanks
_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat

Reply via email to