Install and Configure ClamAV on CentOS 6 with Atomic OSSEC
This guide explains how to install and configure ClamAV on a CentOS 6 system running the Atomic OSSEC agent.
ClamAV packages are installed from the Atomicorp repository. The Atomic OSSEC agent should be installed and connected to the HUB before completing these steps.
Prerequisites
Install the Atomic OSSEC Agent
Install and register the Atomic OSSEC agent before installing ClamAV.
Follow the Linux Local Installer instructions:
https://docs.atomicorp.com/AEO/agents/installation/index.html#linux-local-installer
Once the agent is installed and connected to the HUB, continue with the steps below.
CentOS 6 Repository Requirements
CentOS 6 is end-of-life.
The system must have working CentOS 6 Vault repositories configured so any required operating-system dependencies can be installed.
This guide does not cover CentOS Vault repository configuration.
1. Verify the Atomicorp Repository
Confirm that the Atomic OSSEC repository is configured:
yum repolist all | grep -Ei 'atomic|ossec'
The output should include:
atomicorp-ossec
If atomicorp-ossec is not listed, correct the Atomic OSSEC repository configuration before continuing.
2. Install ClamAV
Install ClamAV and the ClamAV daemon from the Atomicorp repository:
yum --disablerepo='*' --enablerepo=atomicorp-ossec install clamav clamd -y
The installation should include packages such as:
clamav clamav-db clamd
Additional dependencies may also be installed.
3. Verify the Package Source
Confirm that ClamAV was installed from the Atomicorp repository:
yum info installed clamav clamd
The output should include:
From repo : atomicorp-ossec
You can also verify the installed packages with:
rpm -qa | grep -i clam
Atomicorp package releases normally contain .art, for example:
clamav-0.103.10-38477.el6.art.x86_64 clamav-db-0.103.10-38477.el6.art.x86_64 clamd-0.103.10-38477.el6.art.x86_64
Check the installed ClamAV version:
clamscan --version
Because CentOS 6 is a legacy operating system, the available ClamAV version may be older than the current upstream release.
This is expected.
4. Verify the FreshClam Configuration
Review the active FreshClam configuration:
grep -v '^#' /etc/freshclam.conf | grep -v '^$'
To display only the configured signature sources:
grep -Ei '^(DatabaseDirectory|DatabaseCustomURL|DatabaseMirror|PrivateMirror)' /etc/freshclam.conf
The configuration should include Atomicorp custom signature URLs similar to:
DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.fp DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.hdb DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.hdu DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.hsb DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.hsu DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.idb DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.ign2 DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.ldb DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.ldu DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.ndb DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.ndu DatabaseCustomURL https://rule-updates.atomicorp.com/channels/rules/anti-malware/Atomicorp-Linux.sfp
5. Update the ClamAV Signatures
Run:
freshclam
A successful update should show the Atomicorp signature files being updated or reported as current.
For example:
Atomicorp-Linux.fp is up-to-date Atomicorp-Linux.hdb is up-to-date Atomicorp-Linux.ign2 is up-to-date Atomicorp-Linux.ldb is up-to-date Atomicorp-Linux.ndb is up-to-date
You may also see a warning indicating that the installed ClamAV version is outdated.
For example:
WARNING: Your ClamAV installation is OUTDATED!
This is expected on CentOS 6 because the operating system is end-of-life and requires an older compatible ClamAV release.
6. Verify the Signature Database
Check the ClamAV database directory:
ls -lah /var/lib/clamav/
You should see Atomicorp signature files such as:
Atomicorp-Linux.fp Atomicorp-Linux.hdb Atomicorp-Linux.hdu Atomicorp-Linux.hsb Atomicorp-Linux.hsu Atomicorp-Linux.idb Atomicorp-Linux.ign2 Atomicorp-Linux.ldb Atomicorp-Linux.ldu Atomicorp-Linux.ndb Atomicorp-Linux.ndu Atomicorp-Linux.sfp
If these files are not present, do not start clamd until the signature update issue is resolved.
7. Configure SELinux
CentOS 6 systems may have SELinux enabled.
Check the current SELinux mode:
getenforce
The result may be:
Enforcing Permissive Disabled
SELinux does not need to be disabled for ClamAV to operate.
If SELinux is Enforcing
Check whether the antivirus scanning policy is enabled:
getsebool antivirus_can_scan_system
If the result is:
antivirus_can_scan_system --> off
enable it permanently:
setsebool -P antivirus_can_scan_system 1Verify:
getsebool antivirus_can_scan_system
The expected result is:
antivirus_can_scan_system --> on
Restore the expected SELinux contexts on the ClamAV database directory:
restorecon -Rv /var/lib/clamav
SELinux may otherwise prevent clamd from reading its signature database even when the files exist and standard Unix permissions appear correct.
8. Start the ClamAV Daemon
Start clamd with:
service clamd start
Check the service status:
service clamd status
Enable the service at boot:
chkconfig clamd on
Verify:
chkconfig --list clamd
9. Test ClamAV
Create the standard EICAR antivirus test file or download here:
echo 'X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*' > /tmp/eicar.com
Scan the file:
clamscan /tmp/eicar.com
A successful detection should report:
Eicar-Signature FOUND
Remove the test file when finished:
rm -f /tmp/eicar.com
Troubleshooting
Atomicorp Repository Is Missing
Run:
yum repolist all | grep -Ei 'atomic|ossec'
If atomicorp-ossec is not listed, correct the Atomic OSSEC repository configuration before installing ClamAV.
Yum Cannot Resolve Dependencies
CentOS 6 is end-of-life and the standard CentOS mirrors are no longer available.
The system must have working CentOS 6 Vault repositories configured for required operating-system dependencies.
FreshClam Reports an Example Configuration
If FreshClam reports:
ERROR: Please edit the example config file /etc/freshclam.conf
review /etc/freshclam.conf and verify that the example configuration directive has been disabled and that the Atomicorp DatabaseCustomURL entries are present.
You can review active settings with:
grep -v '^#' /etc/freshclam.conf | grep -v '^$'
clamd Reports That Signature Files Cannot Be Opened
For example:
LibClamAV Error: cli_load(): Can't open file /var/lib/clamav/Atomicorp-Linux.ign2 LibClamAV Error: cli_loaddbdir(): No supported database files found in /var/lib/clamav
First verify that the signature files exist:
ls -lah /var/lib/clamav/
If the files exist, check SELinux:
getenforce getsebool antivirus_can_scan_system
If SELinux is Enforcing and antivirus scanning is disabled:
setsebool -P antivirus_can_scan_system 1 restorecon -Rv /var/lib/clamav
Then retry:
service clamd start
Troubleshoot SELinux Denials
Review recent SELinux audit messages:
grep -i clam /var/log/audit/audit.log | tail -30
For troubleshooting only, SELinux can temporarily be placed into Permissive mode:
setenforce 0Retry:
service clamd start
If clamd starts successfully in Permissive mode, the issue is related to SELinux policy or file context.
Return SELinux to Enforcing mode after testing:
setenforce 1
Do not permanently disable SELinux as a workaround.
clamd Does Not Start at Boot
Verify that it is enabled:
chkconfig --list clamd
If necessary:
chkconfig clamd on
Information to Provide to Atomicorp Support
If ClamAV installation, signature updates, or clamd startup still fail, provide the output of:
cat /etc/centos-release yum repolist all | grep -Ei 'atomic|ossec' rpm -qa | grep -i clam yum info installed clamav clamd clamscan --version grep -v '^#' /etc/freshclam.conf | grep -v '^$' ls -lah /var/lib/clamav/ getenforce getsebool antivirus_can_scan_system service clamd status freshclam
If SELinux appears to be involved, also provide:
grep -i clam /var/log/audit/audit.log | tail -30