2011-03-24 05:37:28

by Russell Coker

[permalink] [raw]
Subject: [refpolicy] Proxies

http://dansguardian.org/

I'm thinking of writing a policy for Dans Guardian, is it worth having a
separate domain or should I run it in squid_t? While it's not uncommon to run
both on the same server there seems little benefit in isolating them,
generally an attacker would get all the benefit that they are likely to get
from compromising just one of them.

--
My Main Blog http://etbe.coker.com.au/
My Documents Blog http://doc.coker.com.au/


2011-03-24 18:59:59

by cpebenito

[permalink] [raw]
Subject: [refpolicy] Proxies

On 03/24/11 01:37, Russell Coker wrote:
> http://dansguardian.org/
>
> I'm thinking of writing a policy for Dans Guardian, is it worth having a
> separate domain or should I run it in squid_t? While it's not uncommon to run
> both on the same server there seems little benefit in isolating them,
> generally an attacker would get all the benefit that they are likely to get
> from compromising just one of them.

I'd tend to go with a separate domain. If you want to use squid and
dansguardian, you couldn't write a policy that would ensure that all the
traffic went though dansguardian if both services are in the same domain.

--
Chris PeBenito
Tresys Technology, LLC
http://www.tresys.com | oss.tresys.com