Great Circle Associates Firewalls
(October 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: CERN/W3C HTTPd as proxy
From: sazah @ ibu . sj . nec . com (Sunny Azah)
Date: Mon, 21 Oct 1996 14:08:31 -0700 (PDT)
To: dmiller @ vitnet . com . sg (Damien Miller)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <Pine . LNX . 3 . 92 . 961020153845 . 14647A-100000 @ mothra . io . com . au> from "Damien Miller" at Oct 20, 96 03:40:07 pm

> From: Damien Miller <dmiller @
 vitnet .
 com .
 sg>
> To: firewalls @
 GreatCircle .
 COM
> Subject: CERN/W3C HTTPd as proxy
> Sender: firewalls-owner @
 GreatCircle .
 COM


> Does anyone have any comments/criticisms about the use of W3c (CERN) HTTPd
> as a caching proxy on a firewall?

I would avoid using large complex programs on a firewall.
Small simple programs are much easier to verify for correctness
and this is crucial to maintain security.  I don't have a specific
recommendation, but look for something small, simple, and well-written
to use a base.

Try to disable or remove as much functionality as you can.
Then compartment it off as best you can: run it chroot()ed,
run it with no privileges, etc.  Better yet, run it on a separate machine.


-- 
Regards,

--------------------------------------------------------------------------
Sunny Azah - sazah @
 ibu .
 sj .
 nec .
 com 

                            Internet Business Unit, Home of the PrivateNet
                            NEC Technologies, Inc.
                            110 Rio Robles San Jose, CA 95134
                            Tel:(408) 433-2161 FAX:(408) 433-1230

http://www.privatenet.nec.com
--------------------------------------------------------------------------
    



Follow-Ups:
References:
Indexed By Date Previous: re: IP addresses
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Next: Firewall MIB being developed, Ready or Not
From: "Philip C. Hyland" <pchyland @ uranus . aitc . rest . tasc . com>
Indexed By Thread Previous: Re: CERN/W3C HTTPd as proxy
From: Todd Graham Lewis <lists @ reflections . mindspring . com>
Next: Re: CERN/W3C HTTPd as proxy
From: Michael Dillon <michael @ memra . com>

Google
 
Search Internet Search www.greatcircle.com