Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 08-16-2011, 10:02 AM
Intermediate Member
 
Posts: 19
Default Content Filter Quarantined Email

Hi! This is the first time I have dealt with this in Zimbra. Here is the situation I need help with.

I have a user that is expecting an email from someone, but every time the person tries to email the user, the user gets an email stating:

VIRUS ALERT
Our content checker found
virus: Heuristics.Encrypted.PDF
in an email to you from probably faked sender:xxx.xxx.xxx.x
Content type: Virus
Our internal reference code for your message is 19882-10/HIUBDgAeTUDu

First upstream SMTP client IP address:xx.xxx.xx.xx
According to a 'Received:' trace, the message apparently originated at:
[xxx.xxx.xxx.x], OwnerPC [xxx.xxx.xx.xxx]
The message has been quarantined as: virus-quarantine.tqc4u9kp@fnbandt.com

Please contact your system administrator for details.


The email has an encrypted pdf attachment and I believe this is why it is being blocked. Our email gateway is not blocking it or showing any virus alerts.

This is the first time I have had an email quarantined from the Zimbra server. How do I release this?
Reply With Quote
  #2 (permalink)  
Old 08-16-2011, 10:09 AM
Zimbra Consultant & Moderator
 
Posts: 20,314
Default

Quote:
Originally Posted by valley_girl1919 View Post
This is the first time I have had an email quarantined from the Zimbra server. How do I release this?
You'll find a script in the forums that will do that for you, you should also update your forum profile with the output of the following command:

Code:
zmcontrol -v
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 08-16-2011, 10:12 AM
Intermediate Member
 
Posts: 19
Default

Quote:
Originally Posted by phoenix View Post
You'll find a script in the forums that will do that for you, you should also update your forum profile with the output of the following command:

Code:
zmcontrol -v
Thanks!

Sorry to have to ask, but how do I update my forum profile with the output zmcontrol -v? Where do I type this? Thanks!
Reply With Quote
  #4 (permalink)  
Old 08-16-2011, 12:36 PM
Zimbra Consultant & Moderator
 
Posts: 20,314
Default

Quote:
Originally Posted by valley_girl1919 View Post
Sorry to have to ask, but how do I update my forum profile with the output zmcontrol -v? Where do I type this? Thanks!
I've given you the link to that in my previous post.
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 10-12-2011, 03:57 AM
Member
 
Posts: 14
Default Heuristics.Encrypted.PDF

Can I get this script?

Regards
Reply With Quote
  #6 (permalink)  
Old 10-12-2011, 04:14 AM
Zimbra Consultant & Moderator
 
Posts: 20,314
Default

Quote:
Originally Posted by shoneo View Post
Can I get this script?
Yes, it's in the forums if you do a quick search for it.
__________________
Regards


Bill
Reply With Quote
  #7 (permalink)  
Old 10-12-2011, 04:26 AM
Member
 
Posts: 14
Default

Please, send me a link. I could not find it.

Regards
Reply With Quote
  #8 (permalink)  
Old 10-12-2011, 07:45 AM
Elite Member
 
Posts: 296
Default

Quote:
Originally Posted by valley_girl1919 View Post
The email has an encrypted pdf attachment and I believe this is why it is being blocked. Our email gateway is not blocking it or showing any virus alerts.
someone does know how to avoid it?
can i avoid the ban of encrypted pdf attachment?
should i change amavis .in file?
Reply With Quote
  #9 (permalink)  
Old 10-12-2011, 08:06 AM
Elite Member
 
Posts: 296
Default

no, in clamav.conf.in

in some way this should be set to no

Code:
%%uncomment VAR:zimbraVirusBlockEncryptedArchive%%ArchiveBlockEncrypted yes
Reply With Quote
  #10 (permalink)  
Old 10-12-2011, 08:25 AM
Elite Member
 
Posts: 296
Default

it seems that thsi:
Code:
%%uncomment VAR:zimbraVirusBlockEncryptedArchive%%ArchiveBlockEncrypted yes
should be changed

Code:
%%comment VAR:zimbraVirusBlockEncryptedArchive%%ArchiveBlockEncrypted yes
then restart clamav and u get
Code:
# Mark encrypted archives as viruses (Encrypted.Zip, Encrypted.RAR).
# Default: no
#ArchiveBlockEncrypted yes
hopefully no pdf encrypted wil banned *for ever*
that is what customers pay for....
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.