I can confirm that adding
/etc/ssl/openssl.cnf r,
to /etc/apparmor.d/usr.bin.freshclam and /etc/apparmor.d/usr.sbin.clamd
then run:
apparmor_parser -r /etc/apparmor.d/usr.bin.freshclam
apparmor_parser -r /etc/apparmor.d/usr.sbin.clamd
Makes the apparmor="DENIED" go away.
Also gets rid of the
Public bug reported:
A similar bug seems to have been reported before but keeps returning.
I'm seeing it on an new install of bionic server 18.04 clamav version:
0.100.3+dfsg-0ubuntu0.18.04.1
kern.log keeps reporting the following after installing clamav and
clamav-daemon:
kernel: [ 10.851831
Had the same problem before Zesty and used some of the fixes described
here to have postfix restart through rc.local file after waiting a few
minutes. The bug is still persistent for me after upgrading to Zesty.
What does fix it for me though is adding the "After" line to the Unit:
/lib/systemd/sys