[clamav-users] Why virus definition DB download url is not https?

Micah Snyder (micasnyd) micasnyd at cisco.com
Wed Dec 18 17:10:45 UTC 2019


Agreed.  We'll have to wait for quite a long time before we can disable plain HTTP. 

Micah

On 12/17/19, 7:38 PM, "clamav-users on behalf of Paul Kosinski via clamav-users" <clamav-users-bounces at lists.clamav.net on behalf of clamav-users at lists.clamav.net> wrote:

    As I understand it, many users of ClamAV just use their distro's
    version, which, in the case of LTS distro versions, may be quite behind
    the latest ClamAV version. Thus *removing* the ability to download the
    DB's via plain HTTP should remain for quite a while, so as not to cut
    off ClamAV users who are not as sophisticated as people on this list.
    
    P.S. Although I have always built ClamAV from source (for several
    different Linux versions) since I started using it (as far back as
    version 0.88.4 at least), I still haven't moved from 0.101.5 to 0.102.x
    (the first HTTPS versions), since I have some other things to do first.
    
    
    On Mon, 16 Dec 2019 22:18:54 +0000
    "Micah Snyder \(micasnyd\) via clamav-users"
    <clamav-users at lists.clamav.net> wrote:
    
    > Freshclam in ClamAV 0.102 will use https by default and will NOT fall
    > back to http.  If you need to use http, you can change the
    > DatabaseMirror option in freshclam.conf to
    > "http://database.clamav.net" and that will force it to use http.  I
    > agree that surprises aren't always funny, which is why there is no
    > automatic fallback. 
    > 
    > Micah
    > 
    > On 12/12/19, 5:39 PM, "clamav-users on behalf of Gene Heskett via
    > clamav-users" <clamav-users-bounces at lists.clamav.net on behalf of
    > clamav-users at lists.clamav.net> wrote:
    > 
    >     On Thursday 12 December 2019 17:15:01 Joel Esler (jesler) via 
    >     clamav-users wrote:
    >     
    >     > They are served over https. But only 102.x supports https.  So
    >     > as soon as everyone moves to https, I’ll gladly decommission
    >     > http.
    >     >
    >     Does freshclam support both, if so, how do we force it to https?  
    >     Surprises aren't always funny.
    >     
    >     Cheers, Gene Heskett
    >     -- 
    >     "There are four boxes to be used in defense of liberty:
    >      soap, ballot, jury, and ammo. Please use in that order."
    >     -Ed Howdershelt (Author)
    >     If we desire respect for the law, we must first make the law
    > respectable.
    >      - Louis D. Brandeis
    >     Genes Web page <http://geneslinuxbox.net:6309/gene>
    
    _______________________________________________
    
    clamav-users mailing list
    clamav-users at lists.clamav.net
    https://lists.clamav.net/mailman/listinfo/clamav-users
    
    
    Help us build a comprehensive ClamAV guide:
    https://github.com/vrtadmin/clamav-faq
    
    http://www.clamav.net/contact.html#ml
    



More information about the clamav-users mailing list