All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] Proxies
@ 2011-03-24  5:37 Russell Coker
  2011-03-24 18:59 ` Christopher J. PeBenito
  0 siblings, 1 reply; 2+ messages in thread
From: Russell Coker @ 2011-03-24  5:37 UTC (permalink / raw)
  To: refpolicy

http://dansguardian.org/

I'm thinking of writing a policy for Dans Guardian, is it worth having a 
separate domain or should I run it in squid_t?  While it's not uncommon to run 
both on the same server there seems little benefit in isolating them, 
generally an attacker would get all the benefit that they are likely to get 
from compromising just one of them.

-- 
My Main Blog         http://etbe.coker.com.au/
My Documents Blog    http://doc.coker.com.au/

^ permalink raw reply	[flat|nested] 2+ messages in thread

* [refpolicy] Proxies
  2011-03-24  5:37 [refpolicy] Proxies Russell Coker
@ 2011-03-24 18:59 ` Christopher J. PeBenito
  0 siblings, 0 replies; 2+ messages in thread
From: Christopher J. PeBenito @ 2011-03-24 18:59 UTC (permalink / raw)
  To: refpolicy

On 03/24/11 01:37, Russell Coker wrote:
> http://dansguardian.org/
> 
> I'm thinking of writing a policy for Dans Guardian, is it worth having a 
> separate domain or should I run it in squid_t?  While it's not uncommon to run 
> both on the same server there seems little benefit in isolating them, 
> generally an attacker would get all the benefit that they are likely to get 
> from compromising just one of them.

I'd tend to go with a separate domain.  If you want to use squid and
dansguardian, you couldn't write a policy that would ensure that all the
traffic went though dansguardian if both services are in the same domain.

-- 
Chris PeBenito
Tresys Technology, LLC
www.tresys.com | oss.tresys.com

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2011-03-24 18:59 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-03-24  5:37 [refpolicy] Proxies Russell Coker
2011-03-24 18:59 ` Christopher J. PeBenito

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.