Re: Security Concerns

From: Robert Collins <robertc@dont-contact.us>
Date: Mon, 26 Jan 2004 11:30:24 +1100

On Mon, 2004-01-26 at 10:39, Henrik Nordstrom wrote:
> This question got me thinking, and maybe we should restrict Squid to plain
> refuse to start if access rules say "http_access allow all".
>
> A simple 2.5 patch for doing this and also detecting if "acl all" is
> redefined as something else than intended is attached to this message.
>
> Opinions please.

allow all is valid in some scenarios, so I don't like that. However
redefining acl all is bad IMO.

Rob

-- 
GPG key available at: <http://www.robertcollins.net/keys.txt>.

Received on Sun Jan 25 2004 - 17:30:27 MST

This archive was generated by hypermail pre-2.1.9 : Sat Jan 31 2004 - 12:00:10 MST