| Server IP : 93.86.61.54 / Your IP : 216.73.216.156 Web Server : Apache/2.4.62 (Ubuntu) System : Linux rasin.ddns.net 6.8.0-124-generic #124~22.04.1-Ubuntu SMP PREEMPT_DYNAMIC Tue May 26 21:05:19 UTC x86_64 User : www-data ( 33) PHP Version : 8.4.22 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : ON Directory : /var/www/html/projects/nextcloud/core/doc/admin/configuration_server/ |
Upload File : |
<!DOCTYPE html>
<html class="writer-html5" lang="en" >
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Antivirus scanner — Nextcloud latest Administration Manual latest documentation</title>
<link rel="stylesheet" href="../_static/css/theme.css" type="text/css" />
<link rel="stylesheet" href="../_static/pygments.css" type="text/css" />
<link rel="stylesheet" href="../_static/custom.css" type="text/css" />
<!--[if lt IE 9]>
<script src="../_static/js/html5shiv.min.js"></script>
<![endif]-->
<script type="text/javascript" id="documentation_options" data-url_root="../" src="../_static/documentation_options.js"></script>
<script src="../_static/jquery.js"></script>
<script src="../_static/underscore.js"></script>
<script src="../_static/doctools.js"></script>
<script src="../_static/language_data.js"></script>
<script type="text/javascript" src="../_static/js/theme.js"></script>
<link rel="index" title="Index" href="../genindex.html" />
<link rel="search" title="Search" href="../search.html" />
<link rel="next" title="Reverse proxy" href="reverse_proxy_configuration.html" />
<link rel="prev" title="Logging" href="logging_configuration.html" />
</head>
<body class="wy-body-for-nav">
<div class="wy-grid-for-nav">
<nav data-toggle="wy-nav-shift" class="wy-nav-side">
<div class="wy-side-scroll">
<div class="wy-side-nav-search" >
<a href="../contents.html">
<img src="../_static/logo-white.png" class="logo" alt="Logo"/>
</a>
<div role="search">
<form id="rtd-search-form" class="wy-form" action="../search.html" method="get">
<input type="text" name="q" placeholder="Search docs" />
<input type="hidden" name="check_keywords" value="yes" />
<input type="hidden" name="area" value="default" />
</form>
</div>
</div>
<div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="main navigation">
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="../index.html">Introduction</a></li>
<li class="toctree-l1"><a class="reference internal" href="../release_notes.html">Release notes</a></li>
<li class="toctree-l1"><a class="reference internal" href="../release_schedule.html">Maintenance and release schedule</a></li>
<li class="toctree-l1"><a class="reference internal" href="../installation/index.html">Installation and server configuration</a></li>
<li class="toctree-l1 current"><a class="reference internal" href="index.html">Nextcloud configuration</a><ul class="current">
<li class="toctree-l2"><a class="reference internal" href="security_setup_warnings.html">Warnings on admin page</a></li>
<li class="toctree-l2"><a class="reference internal" href="occ_command.html">Using the occ command</a></li>
<li class="toctree-l2"><a class="reference internal" href="activity_configuration.html">Activity app</a></li>
<li class="toctree-l2"><a class="reference internal" href="caching_configuration.html">Memory caching</a></li>
<li class="toctree-l2"><a class="reference internal" href="background_jobs_configuration.html">Background jobs</a></li>
<li class="toctree-l2"><a class="reference internal" href="config_sample_php_parameters.html">Configuration Parameters</a></li>
<li class="toctree-l2"><a class="reference internal" href="email_configuration.html">Email</a></li>
<li class="toctree-l2"><a class="reference internal" href="external_sites.html">Linking external sites</a></li>
<li class="toctree-l2"><a class="reference internal" href="language_configuration.html">Language & Locale</a></li>
<li class="toctree-l2"><a class="reference internal" href="logging_configuration.html">Logging</a></li>
<li class="toctree-l2 current"><a class="current reference internal" href="#">Antivirus scanner</a><ul>
<li class="toctree-l3"><a class="reference internal" href="#installing-clamav">Installing ClamAV</a></li>
<li class="toctree-l3"><a class="reference internal" href="#enabling-the-antivirus-app-for-files">Enabling the antivirus app for files</a></li>
<li class="toctree-l3"><a class="reference internal" href="#configuring-clamav-on-nextcloud">Configuring ClamAV on Nextcloud</a></li>
</ul>
</li>
<li class="toctree-l2"><a class="reference internal" href="reverse_proxy_configuration.html">Reverse proxy</a></li>
<li class="toctree-l2"><a class="reference internal" href="bruteforce_configuration.html">Brute force protection</a></li>
<li class="toctree-l2"><a class="reference internal" href="automatic_configuration.html">Automatic setup</a></li>
<li class="toctree-l2"><a class="reference internal" href="theming.html">Theming</a></li>
<li class="toctree-l2"><a class="reference internal" href="oauth2.html">OAuth2</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="../apps_management.html">Apps management</a></li>
<li class="toctree-l1"><a class="reference internal" href="../configuration_user/index.html">User management</a></li>
<li class="toctree-l1"><a class="reference internal" href="../configuration_files/index.html">File sharing and management</a></li>
<li class="toctree-l1"><a class="reference internal" href="../file_workflows/index.html">File workflows</a></li>
<li class="toctree-l1"><a class="reference internal" href="../groupware/index.html">Groupware</a></li>
<li class="toctree-l1"><a class="reference internal" href="../configuration_database/index.html">Database configuration</a></li>
<li class="toctree-l1"><a class="reference internal" href="../configuration_mimetypes/index.html">Mimetypes management</a></li>
<li class="toctree-l1"><a class="reference internal" href="../maintenance/index.html">Maintenance</a></li>
<li class="toctree-l1"><a class="reference internal" href="../issues/index.html">Issues and troubleshooting</a></li>
<li class="toctree-l1"><a class="reference internal" href="../gdpr/index.html">GDPR</a></li>
</ul>
</div>
</div>
</nav>
<section data-toggle="wy-nav-shift" class="wy-nav-content-wrap">
<nav class="wy-nav-top" aria-label="top navigation">
<i data-toggle="wy-nav-top" class="fa fa-bars"></i>
<a href="../contents.html">Nextcloud latest Administration Manual</a>
</nav>
<div class="wy-nav-content">
<div class="rst-content style-external-links">
<div role="navigation" aria-label="breadcrumbs navigation">
<ul class="wy-breadcrumbs">
<li><a href="../contents.html" class="icon icon-home"></a> »</li>
<li><a href="index.html">Nextcloud configuration</a> »</li>
<li>Antivirus scanner</li>
<li class="wy-breadcrumbs-aside">
<a href="https://github.com/nextcloud/documentation/edit/master/admin_manual/configuration_server/antivirus_configuration.rst" class="fa fa-github"> Edit on GitHub</a>
</li>
</ul>
<hr/>
</div>
<div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article">
<div itemprop="articleBody">
<div class="section" id="antivirus-scanner">
<h1>Antivirus scanner<a class="headerlink" href="#antivirus-scanner" title="Permalink to this headline">¶</a></h1>
<p>You can configure your Nextcloud server to automatically run a virus scan on
newly-uploaded files with the Antivirus app for Files. The Antivirus app for
Files integrates the open source anti-virus engine <a class="reference external" href="https://www.clamav.net/index.html">ClamAV</a> with Nextcloud. ClamAV detects all forms
of malware including Trojan horses, viruses, and worms, and it operates on all
major file types including Windows, Linux, and Mac files, compressed files,
executables, image files, Flash, PDF, and many others. ClamAV’s Freshclam
daemon automatically updates its malware signature database at scheduled
intervals.</p>
<p>ClamAV runs on Linux and any Unix-type operating system, and Microsoft Windows.
However, it has only been tested with Nextcloud on Linux, so these instructions
are for Linux systems. You must first install ClamAV, and then install and
configure the Antivirus app for Files on Nextcloud.</p>
<div class="section" id="installing-clamav">
<h2>Installing ClamAV<a class="headerlink" href="#installing-clamav" title="Permalink to this headline">¶</a></h2>
<p>As always, the various Linux distributions manage installing and configuring
ClamAV in different ways.</p>
<dl>
<dt>Debian, Ubuntu, Linux Mint</dt><dd><p>On Debian and Ubuntu systems, and their many variants, install ClamAV with
these commands:</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">apt</span><span class="o">-</span><span class="n">get</span> <span class="n">install</span> <span class="n">clamav</span> <span class="n">clamav</span><span class="o">-</span><span class="n">daemon</span>
</pre></div>
</div>
</dd>
</dl>
<p>The installer automatically creates default configuration files and launches the
<code class="docutils literal notranslate"><span class="pre">clamd</span></code> and <code class="docutils literal notranslate"><span class="pre">freshclam</span></code> daemons. You don’t have to do anything more, though
it’s a good idea to review the ClamAV documentation and your settings in
<code class="docutils literal notranslate"><span class="pre">/etc/clamav/</span></code>. Enable verbose logging in both <code class="docutils literal notranslate"><span class="pre">clamd.conf</span></code> and
<code class="docutils literal notranslate"><span class="pre">freshclam.conf</span></code> until you get any kinks worked out.</p>
<dl>
<dt>RedHat Enterprise Linux 7, CentOS 7</dt><dd><p>On RedHat Enterprise Linux 7 and related systems you must install the Extra Packages for
Enterprise Linux (EPEL) repository, and then install ClamAV:</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">yum</span> <span class="n">install</span> <span class="n">epel</span><span class="o">-</span><span class="n">release</span>
<span class="n">yum</span> <span class="n">install</span> <span class="n">clamav</span> <span class="n">clamav</span><span class="o">-</span><span class="n">scanner</span> <span class="n">clamav</span><span class="o">-</span><span class="n">scanner</span><span class="o">-</span><span class="n">systemd</span> <span class="n">clamav</span><span class="o">-</span><span class="n">server</span>
<span class="n">clamav</span><span class="o">-</span><span class="n">server</span><span class="o">-</span><span class="n">systemd</span> <span class="n">clamav</span><span class="o">-</span><span class="n">update</span>
</pre></div>
</div>
</dd>
</dl>
<p>This installs two configuration files: <code class="docutils literal notranslate"><span class="pre">/etc/freshclam.conf</span></code> and
<code class="docutils literal notranslate"><span class="pre">/etc/clamd.d/scan.conf</span></code>. You must edit both of these before you can run
ClamAV. Both files are well-commented, and <code class="docutils literal notranslate"><span class="pre">man</span> <span class="pre">clamd.conf</span></code> and <code class="docutils literal notranslate"><span class="pre">man</span>
<span class="pre">freshclam.conf</span></code> explain all the options. Refer to <code class="docutils literal notranslate"><span class="pre">/etc/passwd</span></code> and
<code class="docutils literal notranslate"><span class="pre">/etc/group</span></code> when you need to verify the ClamAV user and group.</p>
<p>First edit <code class="docutils literal notranslate"><span class="pre">/etc/freshclam.conf</span></code> and configure your options.
<code class="docutils literal notranslate"><span class="pre">freshclam</span></code> updates your malware database, so you want it to run frequently to
get updated malware signatures. Run it manually post-installation to download
your first set of malware signatures:</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">freshclam</span>
</pre></div>
</div>
<p>The EPEL packages do not include an init file for <code class="docutils literal notranslate"><span class="pre">freshclam</span></code>, so the quick
and easy way to set it up for regular checks is with a cron job. This example
runs it every hour at 47 minutes past the hour:</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="c1"># m h dom mon dow command</span>
<span class="mi">47</span> <span class="o">*</span> <span class="o">*</span> <span class="o">*</span> <span class="o">*</span> <span class="o">/</span><span class="n">usr</span><span class="o">/</span><span class="nb">bin</span><span class="o">/</span><span class="n">freshclam</span> <span class="o">--</span><span class="n">quiet</span>
</pre></div>
</div>
<p>Please avoid any multiples of 10, because those are when the ClamAV servers are
hit the hardest for updates.</p>
<p>Next, edit <code class="docutils literal notranslate"><span class="pre">/etc/clamd.d/scan.conf</span></code>. When you’re finished you must enable
the <code class="docutils literal notranslate"><span class="pre">clamd</span></code> service file and start <code class="docutils literal notranslate"><span class="pre">clamd</span></code>:</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">systemctl</span> <span class="n">enable</span> <span class="n">clamd</span><span class="nd">@scan</span><span class="o">.</span><span class="n">service</span>
<span class="n">systemctl</span> <span class="n">start</span> <span class="n">clamd</span><span class="nd">@scan</span><span class="o">.</span><span class="n">service</span>
</pre></div>
</div>
<p>That should take care of everything. Enable verbose logging in <code class="docutils literal notranslate"><span class="pre">scan.conf</span></code>
and <code class="docutils literal notranslate"><span class="pre">freshclam.conf</span></code> until it is running the way you want.</p>
<dl class="simple">
<dt>Docker, Docker-compose</dt><dd><p>To install ClamAV via docker or docker compose you can take one of unofficial images of ClamAV, or build one by yourself.
This example is based on docker image from <a class="reference external" href="https://github.com/UKHomeOffice/docker-clamav">https://github.com/UKHomeOffice/docker-clamav</a>.</p>
</dd>
</dl>
<p>You can mount ClamAV Socket from the Docker Container to the host System as volume. In this case you do not need to expose any port outside of container.
Also you need to edit config files as described above and added configuration for a local Socket. In this particular Image configuration parameters could be passed via <code class="docutils literal notranslate"><span class="pre">CLAMD_SETTINGS_CSV</span></code>.</p>
<p>For a Docker run this command:</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">docker</span> <span class="n">run</span> <span class="o">--</span><span class="n">name</span> <span class="n">clamav</span> <span class="o">-</span><span class="n">d</span> <span class="o">-</span><span class="n">v</span> <span class="o">/</span><span class="n">var</span><span class="o">/</span><span class="n">run</span><span class="o">/</span><span class="n">clamav</span><span class="o">/</span><span class="p">:</span><span class="o">/</span><span class="n">var</span><span class="o">/</span><span class="n">run</span><span class="o">/</span><span class="n">clamav</span><span class="o">/</span> <span class="o">-</span><span class="n">e</span> <span class="n">CLAMD_SETTINGS_CSV</span><span class="o">=</span><span class="s2">"LocalSocket=/var/run/clamav/clamd.ctl"</span> <span class="n">quay</span><span class="o">.</span><span class="n">io</span><span class="o">/</span><span class="n">ukhomeofficedigital</span><span class="o">/</span><span class="n">clamav</span><span class="p">:</span><span class="n">latest</span>
</pre></div>
</div>
<p>For a Docker-compose use following settings:</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">version</span><span class="p">:</span> <span class="s2">"3.6"</span>
<span class="n">services</span><span class="p">:</span>
<span class="n">clamav</span><span class="p">:</span>
<span class="n">image</span><span class="p">:</span> <span class="s2">"quay.io/ukhomeofficedigital/clamav:latest"</span>
<span class="n">container_name</span><span class="p">:</span> <span class="s2">"clamav"</span>
<span class="n">volumes</span><span class="p">:</span>
<span class="o">-</span> <span class="o">/</span><span class="n">var</span><span class="o">/</span><span class="n">run</span><span class="o">/</span><span class="n">clamav</span><span class="o">/</span><span class="p">:</span><span class="o">/</span><span class="n">var</span><span class="o">/</span><span class="n">run</span><span class="o">/</span><span class="n">clamav</span><span class="o">/</span>
<span class="n">restart</span><span class="p">:</span> <span class="n">unless</span><span class="o">-</span><span class="n">stopped</span>
<span class="n">environment</span><span class="p">:</span>
<span class="o">-</span> <span class="n">CLAMD_SETTINGS_CSV</span><span class="o">=</span><span class="n">LocalSocket</span><span class="o">=/</span><span class="n">var</span><span class="o">/</span><span class="n">run</span><span class="o">/</span><span class="n">clamav</span><span class="o">/</span><span class="n">clamd</span><span class="o">.</span><span class="n">ctl</span>
</pre></div>
</div>
</div>
<div class="section" id="enabling-the-antivirus-app-for-files">
<h2>Enabling the antivirus app for files<a class="headerlink" href="#enabling-the-antivirus-app-for-files" title="Permalink to this headline">¶</a></h2>
<p>Place the <code class="docutils literal notranslate"><span class="pre">files_antivirus</span></code> app into the <code class="docutils literal notranslate"><span class="pre">apps</span></code> directory of your Nextcloud
server. Then the app shows up on the Nextcloud Apps page where it simply can be
enabled.</p>
<div class="figure align-default">
<img alt="../_images/antivirus-app.png" src="../_images/antivirus-app.png" />
</div>
</div>
<div class="section" id="configuring-clamav-on-nextcloud">
<h2>Configuring ClamAV on Nextcloud<a class="headerlink" href="#configuring-clamav-on-nextcloud" title="Permalink to this headline">¶</a></h2>
<p>Next, go to your Nextcloud Admin page and set your Nextcloud logging level to
Everything.</p>
<div class="figure align-default">
<img alt="../_images/antivirus-logging.png" src="../_images/antivirus-logging.png" />
</div>
<p>Now find your Antivirus Configuration panel on your Admin page.</p>
<div class="figure align-default">
<img alt="../_images/antivirus-config.png" src="../_images/antivirus-config.png" />
</div>
<p>ClamAV runs in one of three modes:</p>
<ul class="simple">
<li><p>Daemon (Socket): ClamAV is running on the same server as Nextcloud. The ClamAV
daemon, <code class="docutils literal notranslate"><span class="pre">clamd</span></code>, runs in the background. When there is no activity <code class="docutils literal notranslate"><span class="pre">clamd</span></code>
places a minimal load on your system. If your users upload large volumes of
files you will see high CPU usage.</p></li>
<li><p>Daemon: ClamAV is running on a different server. This is a good option
for Nextcloud servers with high volumes of file uploads.</p></li>
<li><p>Executable: ClamAV is running on the same server as Nextcloud, and the
<code class="docutils literal notranslate"><span class="pre">clamscan</span></code> command is started and then stopped with each file upload.
<code class="docutils literal notranslate"><span class="pre">clamscan</span></code> is slow and not always reliable for on-demand usage; it is
better to use one of the daemon modes.</p></li>
</ul>
<dl>
<dt>Daemon (Socket)</dt><dd><p>Nextcloud should detect your <code class="docutils literal notranslate"><span class="pre">clamd</span></code> socket and fill in the <code class="docutils literal notranslate"><span class="pre">Socket</span></code>
field. This is the <code class="docutils literal notranslate"><span class="pre">LocalSocket</span></code> option in <code class="docutils literal notranslate"><span class="pre">clamd.conf</span></code>. You can
run <code class="docutils literal notranslate"><span class="pre">netstat</span></code> to verify:</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">netstat</span> <span class="o">-</span><span class="n">a</span><span class="o">|</span><span class="n">grep</span> <span class="n">clam</span>
<span class="n">unix</span> <span class="mi">2</span> <span class="p">[</span> <span class="n">ACC</span> <span class="p">]</span> <span class="n">STREAM</span> <span class="n">LISTENING</span> <span class="mi">15857</span> <span class="o">/</span><span class="n">var</span><span class="o">/</span><span class="n">run</span><span class="o">/</span><span class="n">clamav</span><span class="o">/</span><span class="n">clamd</span><span class="o">.</span><span class="n">ctl</span>
</pre></div>
</div>
<div class="figure align-default">
<img alt="../_images/antivirus-daemon-socket.png" src="../_images/antivirus-daemon-socket.png" />
</div>
<p>The <code class="docutils literal notranslate"><span class="pre">Stream</span> <span class="pre">Length</span></code> value sets the number of bytes read in one pass.
10485760 bytes, or ten megabytes, is the default. This value should be
no larger than the PHP <code class="docutils literal notranslate"><span class="pre">memory_limit</span></code> settings, or physical memory if
<code class="docutils literal notranslate"><span class="pre">memory_limit</span></code> is set to -1 (no limit).</p>
<p><code class="docutils literal notranslate"><span class="pre">Action</span> <span class="pre">for</span> <span class="pre">infected</span> <span class="pre">files</span> <span class="pre">found</span> <span class="pre">while</span> <span class="pre">scanning</span></code> gives you the choice of
logging any alerts without deleting the files, or immediately deleting
infected files.</p>
</dd>
<dt>Daemon</dt><dd><p>For the Daemon option you need the hostname or IP address of the remote
server running ClamAV, and the server’s port number.</p>
<div class="figure align-default">
<img alt="../_images/antivirus-daemon.png" src="../_images/antivirus-daemon.png" />
</div>
</dd>
<dt>Executable</dt><dd><p>The Executable option requires the path to <code class="docutils literal notranslate"><span class="pre">clamscan</span></code>, which is the
interactive ClamAV scanning command. Nextcloud should find it automatically.</p>
<div class="figure align-default">
<img alt="../_images/antivirus-executable.png" src="../_images/antivirus-executable.png" />
</div>
</dd>
</dl>
<p>When you are satisfied with how ClamAV is operating, you might want to go
back and change all of your logging to less verbose levels.</p>
</div>
</div>
</div>
</div>
<footer>
<div class="rst-footer-buttons" role="navigation" aria-label="footer navigation">
<a href="reverse_proxy_configuration.html" class="btn btn-neutral float-right" title="Reverse proxy" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right"></span></a>
<a href="logging_configuration.html" class="btn btn-neutral float-left" title="Logging" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left"></span> Previous</a>
</div>
<hr/>
<div role="contentinfo">
<p>
© Copyright 2020 Nextcloud GmbH
</p>
</div>
</footer>
</div>
</div>
</section>
</div>
<div class="rst-versions" data-toggle="rst-versions" role="note" aria-label="versions">
<span class="rst-current-version" data-toggle="rst-current-version">
<span class="fa fa-book"> Read the Docs</span>
v: latest
<span class="fa fa-caret-down"></span>
</span>
<div class="rst-other-versions">
<dl>
<dt>Versions</dt>
<dd><a href="https://docs.nextcloud.com/server/17/admin_manual">17</a></dd>
<dd><a href="https://docs.nextcloud.com/server/18/admin_manual">18</a></dd>
<dd><a href="https://docs.nextcloud.com/server/19/admin_manual">19</a></dd>
<dd><a href="https://docs.nextcloud.com/server/stable/admin_manual">stable</a></dd>
<dd><a href="https://docs.nextcloud.com/server/latest/admin_manual">latest</a></dd>
</dl>
<dl>
<dt>Downloads</dt>
</dl>
<dl>
<dt>On Read the Docs</dt>
<dd>
<a href="///projects//?fromdocs=">Project Home</a>
</dd>
<dd>
<a href="///builds//?fromdocs=">Builds</a>
</dd>
</dl>
</div>
</div>
<script type="text/javascript">
jQuery(function () {
SphinxRtdTheme.Navigation.enable(true);
});
</script>
</body>
</html>