You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(55) |
Oct
(44) |
Nov
(156) |
Dec
(123) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(130) |
Feb
(156) |
Mar
(162) |
Apr
(171) |
May
(97) |
Jun
(127) |
Jul
(58) |
Aug
(81) |
Sep
(86) |
Oct
(45) |
Nov
(41) |
Dec
(84) |
| 2003 |
Jan
(71) |
Feb
(87) |
Mar
(133) |
Apr
(152) |
May
(151) |
Jun
(232) |
Jul
(320) |
Aug
(237) |
Sep
(271) |
Oct
(536) |
Nov
(301) |
Dec
(393) |
| 2004 |
Jan
(393) |
Feb
(184) |
Mar
(314) |
Apr
(225) |
May
(139) |
Jun
(77) |
Jul
(87) |
Aug
(75) |
Sep
(139) |
Oct
(50) |
Nov
(8) |
Dec
(28) |
| 2005 |
Jan
(66) |
Feb
(63) |
Mar
(14) |
Apr
(14) |
May
(8) |
Jun
(23) |
Jul
(21) |
Aug
(6) |
Sep
(29) |
Oct
(55) |
Nov
(38) |
Dec
(8) |
| 2006 |
Jan
(5) |
Feb
(10) |
Mar
(1) |
Apr
(15) |
May
(32) |
Jun
(44) |
Jul
(11) |
Aug
(8) |
Sep
(9) |
Oct
(14) |
Nov
(4) |
Dec
(3) |
| 2007 |
Jan
(3) |
Feb
(3) |
Mar
(2) |
Apr
|
May
|
Jun
|
Jul
(35) |
Aug
(49) |
Sep
(8) |
Oct
(42) |
Nov
(44) |
Dec
(7) |
| 2008 |
Jan
(2) |
Feb
(7) |
Mar
(8) |
Apr
(80) |
May
(74) |
Jun
(29) |
Jul
(5) |
Aug
(7) |
Sep
(6) |
Oct
(1) |
Nov
|
Dec
|
| 2009 |
Jan
(8) |
Feb
(19) |
Mar
(3) |
Apr
(24) |
May
(22) |
Jun
(23) |
Jul
(8) |
Aug
(23) |
Sep
(8) |
Oct
(27) |
Nov
(52) |
Dec
(27) |
| 2010 |
Jan
(36) |
Feb
(29) |
Mar
(17) |
Apr
(28) |
May
(21) |
Jun
(4) |
Jul
|
Aug
(28) |
Sep
(18) |
Oct
(6) |
Nov
(34) |
Dec
(16) |
| 2011 |
Jan
(18) |
Feb
(12) |
Mar
|
Apr
|
May
(9) |
Jun
(1) |
Jul
(5) |
Aug
(5) |
Sep
(7) |
Oct
(16) |
Nov
(26) |
Dec
(17) |
| 2012 |
Jan
(6) |
Feb
(34) |
Mar
(52) |
Apr
(10) |
May
(3) |
Jun
|
Jul
|
Aug
(1) |
Sep
|
Oct
(4) |
Nov
(1) |
Dec
(4) |
| 2013 |
Jan
(5) |
Feb
|
Mar
|
Apr
(5) |
May
(4) |
Jun
|
Jul
|
Aug
(14) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2014 |
Jan
|
Feb
(2) |
Mar
(5) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(3) |
Dec
(11) |
| 2015 |
Jan
(5) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(1) |
Sep
(1) |
Oct
(1) |
Nov
|
Dec
|
| 2016 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2017 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2018 |
Jan
(2) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Serge L. <fi...@in...> - 2005-09-22 07:22:09
|
Dear Sirs, this patch is intended for applying rtos and vhz patches together -- Best regards, Serge mailto:fi...@in... |
|
From: Marcel W. <mw...@ma...> - 2005-09-17 09:38:14
|
Indeed. Heimdal is disabled. When I enable it and build the system again, with freeradius already built, heimdal builds just fine. Later I forced a rebuild of freeradius and it fails. Is heimdal overwriting some libraries? Would it help by changing the build order so freeradius builds first and heimdal afterwards? Marcel On 9/14/05, Heiko Zuerker <he...@zu...> wrote: >=20 > On Mon, August 29, 2005 02:03, Marcel Wiget wrote: > > Hi, > > > > > > I was in need of freeradius in devl-linux 1.2.x, so I created the > > required files and attached the patches to this email. The freeradius > > source file I used and placed into build/src is: > > > > ftp://ftp.freeradius.org/pub/radius/freeradius-1.0.4.tar.gz > > > > > > Maybe this is as useful for others as it is to my project with devil- > > linux (wireless 802.1x authentication server). >=20 > I can't get freeradius compiled, it has issues with krb5. > Did you have Heimdal disabled by any chance, when you tested it? >=20 > -- >=20 > Regards > Heiko Zuerker > http://www.devil-linux.org >=20 >=20 >=20 >=20 > ------------------------------------------------------- > SF.Net email is sponsored by: > Tame your development challenges with Apache's Geronimo App Server. Downl= oad > it for free - -and be entered to win a 42" plasma tv or your very own > Sony(tm)PSP. Click here to play: http://sourceforge.net/geronimo.php > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop > |
|
From: Marcel W. <mw...@li...> - 2005-09-17 09:33:54
|
Indeed. Heimdal is disabled. When I enable it and build the system again, with freeradius already built, heimdal builds just fine. Later I forced a rebuild of freeradius and it fails. Is heimdal overwriting some libraries? Would it help by changing the build order so freeradius builds first and heimdal afterwards? Marcel On 9/14/05 9:31 PM, "Heiko Zuerker" <he...@zu...> wrote: > > > On Mon, August 29, 2005 02:03, Marcel Wiget wrote: >> > Hi, >> > >> > >> > I was in need of freeradius in devl-linux 1.2.x, so I created the >> > required files and attached the patches to this email. The freeradius >> > source file I used and placed into build/src is: >> > >> > ftp://ftp.freeradius.org/pub/radius/freeradius-1.0.4.tar.gz >> > >> > >> > Maybe this is as useful for others as it is to my project with devil- >> > linux (wireless 802.1x authentication server). > > I can't get freeradius compiled, it has issues with krb5. > Did you have Heimdal disabled by any chance, when you tested it? > > -- > > Regards > Heiko Zuerker > http://www.devil-linux.org > > > > > ------------------------------------------------------- > SF.Net email is sponsored by: > Tame your development challenges with Apache's Geronimo App Server. Download > it for free - -and be entered to win a 42" plasma tv or your very own > Sony(tm)PSP. Click here to play: http://sourceforge.net/geronimo.php > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop > |
|
From: Martin G. <sou...@gl...> - 2005-09-16 21:37:32
|
On September 12, 2005 09:56, Heiko Zuerker wrote: > On Mon, September 12, 2005 10:40, Martin Glazer wrote: > >> On Sun, September 11, 2005 22:55, Martin Glazer wrote: > >>> On September 11, 2005 19:38, Heiko Zuerker wrote: > >>>> On Fri, September 9, 2005 18:29, Martin Glazer wrote: > >>>>> Hi, > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> There is still an issue with postfix using saslauthd in the > >>>>> latest devil-linx - the problem is that cyrus-sasl puts its > >>>>> configuration file smtpd.conf in /usr/lib/sasl2/ which of course > >>>>> is non writable on the CD. > >>>>> > >>>>> There are a number of possible solutions to this: > >>>>> 1) Friedrich's solution of exporting the SASL_PATH in postfix > >>>>> (see: > >>>>> http://sourceforge.net/mailarchive/message.php?msg_id=11144397) > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> 2) cyrus-sasl-configdir patch > >>>>> - found a gentoo patch here > >>>>> http://prometheus.cs.wmich.edu/gentoo/rsync/dev-libs/cyrus-sasl/fi > >>>>> les/ cyr u s-sasl-2.1.20-configdir.patch which appears to apply > >>>>> cleanly > >>>>> > >>>>> 3) Create a symlink from /usr/lib/sasl2 to somewhere writeable > >>>>> (in > >>>>> /etc) > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> Anybody have a preferred method of resolving this? > >>>> > >>>> We probably should think about using the patch, because the symlink > >>>> would require us to move the libraries too. > >>> > >>> Sorry, I wasn't clear - all that needs to be symlinked is the config > >>> file smtpd.conf, no libraries. > >>> > >>> ln -sf /usr/lib/sasl2/smtpd.conf /etc/sasl/smtpd.conf > >> > >> I'm lagging the knowledge about sasl, but wouldn't there be other > >> instances, where somebody would have more then this one config file? > > > > I've been trying to look further into the documentation and it does > > appear that there may be times when there is more than 1 config file - > > this depends on what application is actually going to be using sasl. > > > > In our case, as far as I'm aware, postfix is the only application that > > may use sasl, hence the smtpd.conf file and only the need for us to > > "move" this one file. > > > > Are there any other application on DL that use sasl? > > That's a definite maybe. ;-) > > I'm almost certain that quite a few more apps are configured to use SASL. > Because of this, I would favor the patch. OK, attached is the patch for the build/scripts/cyrus-sasl script as well as a sample smtpd.conf file (to be placed in build/scripts/scripts). Also, the actual cyrus-sasl configdir patch is attached. This should be placed in the src directory. I obtained this from one of the Gentoo mirrors for cyrus-sasl-2.1.20 http://prometheus.cs.wmich.edu/gentoo/rsync/dev-libs/cyrus-sasl/files/ Thanks Martin |
|
From: Serge L. <fi...@in...> - 2005-09-15 04:48:55
|
Dear Sirs, Patch for adding kernel nfsd to DL. Source file (nfs-utils) http://prdownloads.sourceforge.net/nfs/nfs-utils-1.0.7.tar.gz -- Best regards, Serge mailto:fi...@in... |
|
From: Heiko Z. <he...@zu...> - 2005-09-14 19:32:53
|
On Mon, August 29, 2005 02:03, Marcel Wiget wrote: > Hi, > > > I was in need of freeradius in devl-linux 1.2.x, so I created the > required files and attached the patches to this email. The freeradius > source file I used and placed into build/src is: > > ftp://ftp.freeradius.org/pub/radius/freeradius-1.0.4.tar.gz > > > Maybe this is as useful for others as it is to my project with devil- > linux (wireless 802.1x authentication server). I can't get freeradius compiled, it has issues with krb5. Did you have Heimdal disabled by any chance, when you tested it? -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Heiko Z. <he...@zu...> - 2005-09-12 15:57:12
|
On Mon, September 12, 2005 10:40, Martin Glazer wrote: >> >> On Sun, September 11, 2005 22:55, Martin Glazer wrote: >> >>> On September 11, 2005 19:38, Heiko Zuerker wrote: >>> >>> >>>> On Fri, September 9, 2005 18:29, Martin Glazer wrote: >>>> >>>> >>>>> Hi, >>>>> >>>>> >>>>> >>>>> >>>>> There is still an issue with postfix using saslauthd in the >>>>> latest devil-linx - the problem is that cyrus-sasl puts its >>>>> configuration file smtpd.conf in /usr/lib/sasl2/ which of course >>>>> is non writable on the CD. >>>>> >>>>> There are a number of possible solutions to this: >>>>> 1) Friedrich's solution of exporting the SASL_PATH in postfix >>>>> (see: >>>>> http://sourceforge.net/mailarchive/message.php?msg_id=11144397) >>>>> >>>>> >>>>> >>>>> >>>>> 2) cyrus-sasl-configdir patch >>>>> - found a gentoo patch here >>>>> http://prometheus.cs.wmich.edu/gentoo/rsync/dev-libs/cyrus-sasl/fi >>>>> les/ cyr u s-sasl-2.1.20-configdir.patch which appears to apply >>>>> cleanly >>>>> >>>>> 3) Create a symlink from /usr/lib/sasl2 to somewhere writeable >>>>> (in >>>>> /etc) >>>>> >>>>> >>>>> >>>>> >>>>> Anybody have a preferred method of resolving this? >>>>> >>>>> >>>> >>>> We probably should think about using the patch, because the symlink >>>> would require us to move the libraries too. >>> >>> Sorry, I wasn't clear - all that needs to be symlinked is the config >>> file smtpd.conf, no libraries. >>> >>> ln -sf /usr/lib/sasl2/smtpd.conf /etc/sasl/smtpd.conf >> >> I'm lagging the knowledge about sasl, but wouldn't there be other >> instances, where somebody would have more then this one config file? >> > > I've been trying to look further into the documentation and it does > appear that there may be times when there is more than 1 config file - > this depends on what application is actually going to be using sasl. > > In our case, as far as I'm aware, postfix is the only application that > may use sasl, hence the smtpd.conf file and only the need for us to "move" > this one file. > > Are there any other application on DL that use sasl? That's a definite maybe. ;-) I'm almost certain that quite a few more apps are configured to use SASL. Because of this, I would favor the patch. -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Martin G. <sou...@gl...> - 2005-09-12 15:40:11
|
> > On Sun, September 11, 2005 22:55, Martin Glazer wrote: >> On September 11, 2005 19:38, Heiko Zuerker wrote: >> >>> On Fri, September 9, 2005 18:29, Martin Glazer wrote: >>> >>>> Hi, >>>> >>>> >>>> >>>> There is still an issue with postfix using saslauthd in the latest >>>> devil-linx - the problem is that cyrus-sasl puts its configuration >>>> file smtpd.conf in /usr/lib/sasl2/ which of course is non writable on >>>> the CD. >>>> >>>> There are a number of possible solutions to this: >>>> 1) Friedrich's solution of exporting the SASL_PATH in postfix >>>> (see: http://sourceforge.net/mailarchive/message.php?msg_id=11144397) >>>> >>>> >>>> >>>> 2) cyrus-sasl-configdir patch >>>> - found a gentoo patch here >>>> http://prometheus.cs.wmich.edu/gentoo/rsync/dev-libs/cyrus-sasl/files/ >>>> cyr u s-sasl-2.1.20-configdir.patch which appears to apply cleanly >>>> >>>> 3) Create a symlink from /usr/lib/sasl2 to somewhere writeable (in >>>> /etc) >>>> >>>> >>>> >>>> Anybody have a preferred method of resolving this? >>>> >>> >>> We probably should think about using the patch, because the symlink >>> would require us to move the libraries too. >> >> Sorry, I wasn't clear - all that needs to be symlinked is the config >> file smtpd.conf, no libraries. >> >> ln -sf /usr/lib/sasl2/smtpd.conf /etc/sasl/smtpd.conf > > I'm lagging the knowledge about sasl, but wouldn't there be other > instances, where somebody would have more then this one config file? > I've been trying to look further into the documentation and it does appear that there may be times when there is more than 1 config file - this depends on what application is actually going to be using sasl. In our case, as far as I'm aware, postfix is the only application that may use sasl, hence the smtpd.conf file and only the need for us to "move" this one file. Are there any other application on DL that use sasl? Martin |
|
From: Heiko Z. <he...@zu...> - 2005-09-12 14:55:18
|
On Sun, September 11, 2005 22:55, Martin Glazer wrote: > On September 11, 2005 19:38, Heiko Zuerker wrote: > >> On Fri, September 9, 2005 18:29, Martin Glazer wrote: >> >>> Hi, >>> >>> >>> >>> There is still an issue with postfix using saslauthd in the latest >>> devil-linx - the problem is that cyrus-sasl puts its configuration >>> file smtpd.conf in /usr/lib/sasl2/ which of course is non writable on >>> the CD. >>> >>> There are a number of possible solutions to this: >>> 1) Friedrich's solution of exporting the SASL_PATH in postfix >>> (see: http://sourceforge.net/mailarchive/message.php?msg_id=11144397) >>> >>> >>> >>> 2) cyrus-sasl-configdir patch >>> - found a gentoo patch here >>> http://prometheus.cs.wmich.edu/gentoo/rsync/dev-libs/cyrus-sasl/files/ >>> cyr u s-sasl-2.1.20-configdir.patch which appears to apply cleanly >>> >>> 3) Create a symlink from /usr/lib/sasl2 to somewhere writeable (in >>> /etc) >>> >>> >>> >>> Anybody have a preferred method of resolving this? >>> >> >> We probably should think about using the patch, because the symlink >> would require us to move the libraries too. > > Sorry, I wasn't clear - all that needs to be symlinked is the config > file smtpd.conf, no libraries. > > ln -sf /usr/lib/sasl2/smtpd.conf /etc/sasl/smtpd.conf I'm lagging the knowledge about sasl, but wouldn't there be other instances, where somebody would have more then this one config file? -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Serge L. <fi...@in...> - 2005-09-12 13:07:02
|
Dear Sirs, > Bugs item #1034025, was opened at 2004-09-24 08:15 > Message generated for change (Tracker Item Submitted) made by Item Submitter > You can respond by visiting: > https://sourceforge.net/tracker/?func=detail&atid=410643&aid=1034025&group_id=34096 dirty, but working patch. For your consideration. -- Best regards, Serge mailto:fi...@in... |
|
From: Martin G. <sou...@gl...> - 2005-09-12 03:55:28
|
On September 11, 2005 19:38, Heiko Zuerker wrote: > On Fri, September 9, 2005 18:29, Martin Glazer wrote: > > Hi, > > > > > > There is still an issue with postfix using saslauthd in the latest > > devil-linx - the problem is that cyrus-sasl puts its configuration file > > smtpd.conf in /usr/lib/sasl2/ which of course is non writable on the CD. > > > > There are a number of possible solutions to this: > > 1) Friedrich's solution of exporting the SASL_PATH in postfix > > (see: http://sourceforge.net/mailarchive/message.php?msg_id=11144397) > > > > > > 2) cyrus-sasl-configdir patch > > - found a gentoo patch here > > http://prometheus.cs.wmich.edu/gentoo/rsync/dev-libs/cyrus-sasl/files/cyr > >u s-sasl-2.1.20-configdir.patch which appears to apply cleanly > > > > 3) Create a symlink from /usr/lib/sasl2 to somewhere writeable (in /etc) > > > > > > Anybody have a preferred method of resolving this? > > We probably should think about using the patch, because the symlink would > require us to move the libraries too. Sorry, I wasn't clear - all that needs to be symlinked is the config file smtpd.conf, no libraries. ln -sf /usr/lib/sasl2/smtpd.conf /etc/sasl/smtpd.conf Martin |
|
From: Heiko Z. <he...@zu...> - 2005-09-12 01:38:38
|
On Fri, September 9, 2005 18:29, Martin Glazer wrote: > Hi, > > > There is still an issue with postfix using saslauthd in the latest > devil-linx - the problem is that cyrus-sasl puts its configuration file > smtpd.conf in /usr/lib/sasl2/ which of course is non writable on the CD. > > There are a number of possible solutions to this: > 1) Friedrich's solution of exporting the SASL_PATH in postfix > (see: http://sourceforge.net/mailarchive/message.php?msg_id=11144397) > > > 2) cyrus-sasl-configdir patch > - found a gentoo patch here > http://prometheus.cs.wmich.edu/gentoo/rsync/dev-libs/cyrus-sasl/files/cyru > s-sasl-2.1.20-configdir.patch which appears to apply cleanly > > 3) Create a symlink from /usr/lib/sasl2 to somewhere writeable (in /etc) > > > Anybody have a preferred method of resolving this? We probably should think about using the patch, because the symlink would require us to move the libraries too. -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Martin G. <sou...@gl...> - 2005-09-09 23:29:59
|
Hi, There is still an issue with postfix using saslauthd in the latest devil-linx - the problem is that cyrus-sasl puts its configuration file smtpd.conf in /usr/lib/sasl2/ which of course is non writable on the CD. There are a number of possible solutions to this: 1) Friedrich's solution of exporting the SASL_PATH in postfix (see: http://sourceforge.net/mailarchive/message.php?msg_id=11144397) 2) cyrus-sasl-configdir patch - found a gentoo patch here http://prometheus.cs.wmich.edu/gentoo/rsync/dev-libs/cyrus-sasl/files/cyrus-sasl-2.1.20-configdir.patch which appears to apply cleanly 3) Create a symlink from /usr/lib/sasl2 to somewhere writeable (in /etc) Anybody have a preferred method of resolving this? Martin |
|
From: Bruce S. <bw...@ar...> - 2005-09-09 13:45:12
|
> > Has anyone actually tried the program? > > I'd like to hear how well it really works (or not). > > Sorry, I cannot help here. I was just thinking it'd be nice to hear from someone who's actually used it before we go to the work of including it in DL. To make sure it works as advertised, etc. :-) > > Also, looking at the docs, it appears that it does not work directly > > with squid, but it's a standalone proxy server and squid can be setup to > > proxy it's traffic through it. Not the best way to integrate it with > > Squid, IMO. > > True, but this gives the option not to cache, but just filter/check for > viruses, and you can get by without Squid. I'd still rather have it be part of squid. I use squid sometimes when I don't want to cache. i.e If I want to enforce authentication, or if I want to create usage logs. I've even installed squid on a standalone workstation and pointed the browsers to localhost. For some reason the browsers seem to run faster when going through squid, instead of using their own cache (weird, I know). > > I'm curious why you picked this one over the others listed? > > Good question :-) Yeah, it seemed to me like it'd be a good idea to compare all the options before choosing one to be included in DL. And it's also be nice to talk to someone who's used it to make sure it runs. :-) It looks like you compared the features below and found the best fit for DL. Are you offering to provide us a patch to add HAVP, or is this a feature request? If you're going to provide us a patch, please burn a CD and test it out before you submit the patch. :-) - BS |
|
From: Kari M. <ka...@tr...> - 2005-09-08 21:59:00
|
I'll continue myself, see below: Kari Mattsson wrote: > Bruce Smith wrote: >=20 >> Has anyone actually tried the program? >> I'd like to hear how well it really works (or not). >=20 >=20 > Sorry, I cannot help here. >=20 >> Also, I see there are some other AV addons for squid listed on the >> http://www.clamav.net/3rdparty.html#webftp page mentioned. Is this=20 >> one the "best" one for DL? >=20 >=20 > Dunno. Se below.. >=20 >> Also, looking at the docs, it appears that it does not work directly >> with squid, but it's a standalone proxy server and squid can be setup = to >> proxy it's traffic through it. Not the best way to integrate it with >> Squid, IMO. >=20 >=20 > True, but this gives the option not to cache, but just filter/check for= =20 > viruses, and you can get by without Squid. >=20 >> I'm curious why you picked this one over the others listed?=20 >=20 >=20 > Good question :-) >=20 >> (unless you don't plan on using Squid, then I understand) >> As you can probably tell, I use and like Squid. :-) >=20 >=20 > I like Squid too. It is just not required in all installations. >=20 > I go through all the choices on the above mentioned clamav page: >=20 > DansGuardian Anti-Virus Patch - takes the Virus Scanning capabilities o= f=20 > ClamAV and integrates them into the content filtering web proxy=20 > DansGuardian. > Latest: Antivirus plugin stable version 6.4.3 for DansGuardian 2.8.0.6 > I'm not sure if this DansGuardian 2.8.0.6 is a proxy which has to be=20 > installed, too. > OK. This one looks good feature-wise, but that additional requirement..= .=20 > Hmm... >=20 > Frox - Frox is a transparent ftp proxy. > Not for the intended usage? > Otherwise, Frox might be a nice addon, if ftp proxy is required. > ...or does Squid do ftp proxying really well nowadays? >=20 > HAVP - proxy with an antivirus filter. It does not cache or filter=20 > content. At the moment the complete traffic is scanned. A reason for=20 > that is the chance of malicious code in nearly every filetypes e.g. HTM= L=20 > (JavaScript) or Jpeg. >=20 > mod_clamav - Apache virus scanning filter > Not for the intended usage. >=20 > ClamAV module for ProFTPD - This is an add on module for ProFTPD > Not for the intended usage. >=20 > SafeSquid - if I understand right, the free version is a cache only, an= d=20 > does not have ClamAV support. Commercial version has it all. > If I'm wrong, the this might be the best one. >=20 > SquidClamAV Redirector - 404 Not Found ... >=20 > Squidclam - this is really not ready yet >=20 > Viralator - Viralator is a perl script that virus scans http downloads=20 > on a linux server after passing through the squid proxy server. > Future Enhancements: > 1. Remove the use of Wget and use LWP Perl module to download the files > 2. Fix Internet Explorer anonomous FTP problem > 3. Fix websites that use .exe as a web page extension >=20 >=20 > So, >=20 > DansGuradian > HAVP > SafeSquid >=20 > These are the only three options I see. >=20 > If DG requires another proxy to be installed, and SS does not have=20 > ClamAV support in the free version, we only have HAVP left. SafeSquid only allows commercial use with theis $50 commercial version of the software. So, ignore it here. DansGuardian, on the other hand, looks good... but: http://dansguardian.org/?page=3Dcopyright2 So the situation is about the same as with SafeSquid. In the end: go for HAVP. >> - BS >> >> >> >> >>> You got my OK. >>> Anybody wants to submit a patch? >>> >>> Heiko >>> >>> On Thu, September 8, 2005 15:45, Kari Mattsson wrote: >>> >>>> from their web site: >>>> >>>> HAVP (HTTP Antivirus Proxy) is a proxy with a ClamAV anti-virus=20 >>>> scanner. >>>> The main aims are continuous, non-blocking downloads and smooth=20 >>>> scanning >>>> of dynamic and password protected HTTP traffic. Havp antivirus proxy= =20 >>>> has a >>>> parent and transparent proxy mode. It can be used with squid or >>>> standalone. >>>> >>>> # HTTP Antivirus proxy >>>> # Scans complete incomming traffic >>>> # Nonblocking downloads >>>> # Smooth scanning of dynamic and password protected traffic >>>> # Can used with squid or other proxy >>>> # Parent proxy support >>>> # Transparent proxy support >>>> # Logfile >>>> # Process change to defined user and group >>>> # Daemon >>>> # Use Clamav (GPL antivirus) >>>> # Operating System: Linux >>>> # Written in C++ >>>> # Released under GPL >>>> >>>> >>>> http://www.server-side.de/index.htm >>>> >>>> >>>> I think this really would add something very unique to DL: >>>> I've been searching for a CD-based Linux with realtime http traffic >>>> virus scanning. None found so far. >>>> >>>> The external boxes from Panda/TrendMicro/etc. are hideously expensiv= e. >>>> A DL box would be more suitable for many organisations. >>>> >>>> >>>> OK. Those expensive boxes do more, but still.. >>>> >>>> >>>> I found this HAVP from http://www.clamav.net/3rdparty.html#webftp >>>> >>>> >>>> The source download is less than 600 KB. >>>> >>>> >>>> This is a Request For Comment :-) >>>> >>>> >>>> >>>> Terveisin/With kind regards/Med h=E4lsningar/Lugupidamisega, >>>> >>>> >>>> Kari Mattsson >>>> >> >> >> >> >> ------------------------------------------------------- >> SF.Net email is Sponsored by the Better Software Conference & EXPO >> September 19-22, 2005 * San Francisco, CA * Development Lifecycle=20 >> Practices >> Agile & Plan-Driven Development * Managing Projects & Teams * Testing=20 >> & QA >> Security * Process Improvement & Measurement * http://www.sqe.com/bsce= 5sf >> _______________________________________________ >> Devil-linux-develop mailing list >> Dev...@li... >> https://lists.sourceforge.net/lists/listinfo/devil-linux-develop >> >=20 >=20 >=20 >=20 > Terveisin/With kind regards/Med h=E4lsningar/Lugupidamisega, >=20 > Kari Mattsson > Trivore Corp. >=20 >=20 > ------------------------------------------------------- > SF.Net email is Sponsored by the Better Software Conference & EXPO > September 19-22, 2005 * San Francisco, CA * Development Lifecycle Pract= ices > Agile & Plan-Driven Development * Managing Projects & Teams * Testing &= QA > Security * Process Improvement & Measurement * http://www.sqe.com/bsce5= sf > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop >=20 Terveisin/With kind regards/Med h=E4lsningar/Lugupidamisega, Kari Mattsson Trivore Corp. |
|
From: Kari M. <kar...@tr...> - 2005-09-08 21:57:35
|
I'll continue myself, see below: Kari Mattsson wrote: > Bruce Smith wrote: >=20 >> Has anyone actually tried the program? >> I'd like to hear how well it really works (or not). >=20 >=20 > Sorry, I cannot help here. >=20 >> Also, I see there are some other AV addons for squid listed on the >> http://www.clamav.net/3rdparty.html#webftp page mentioned. Is this=20 >> one the "best" one for DL? >=20 >=20 > Dunno. Se below.. >=20 >> Also, looking at the docs, it appears that it does not work directly >> with squid, but it's a standalone proxy server and squid can be setup = to >> proxy it's traffic through it. Not the best way to integrate it with >> Squid, IMO. >=20 >=20 > True, but this gives the option not to cache, but just filter/check for= =20 > viruses, and you can get by without Squid. >=20 >> I'm curious why you picked this one over the others listed?=20 >=20 >=20 > Good question :-) >=20 >> (unless you don't plan on using Squid, then I understand) >> As you can probably tell, I use and like Squid. :-) >=20 >=20 > I like Squid too. It is just not required in all installations. >=20 > I go through all the choices on the above mentioned clamav page: >=20 > DansGuardian Anti-Virus Patch - takes the Virus Scanning capabilities o= f=20 > ClamAV and integrates them into the content filtering web proxy=20 > DansGuardian. > Latest: Antivirus plugin stable version 6.4.3 for DansGuardian 2.8.0.6 > I'm not sure if this DansGuardian 2.8.0.6 is a proxy which has to be=20 > installed, too. > OK. This one looks good feature-wise, but that additional requirement..= .=20 > Hmm... >=20 > Frox - Frox is a transparent ftp proxy. > Not for the intended usage? > Otherwise, Frox might be a nice addon, if ftp proxy is required. > ...or does Squid do ftp proxying really well nowadays? >=20 > HAVP - proxy with an antivirus filter. It does not cache or filter=20 > content. At the moment the complete traffic is scanned. A reason for=20 > that is the chance of malicious code in nearly every filetypes e.g. HTM= L=20 > (JavaScript) or Jpeg. >=20 > mod_clamav - Apache virus scanning filter > Not for the intended usage. >=20 > ClamAV module for ProFTPD - This is an add on module for ProFTPD > Not for the intended usage. >=20 > SafeSquid - if I understand right, the free version is a cache only, an= d=20 > does not have ClamAV support. Commercial version has it all. > If I'm wrong, the this might be the best one. >=20 > SquidClamAV Redirector - 404 Not Found ... >=20 > Squidclam - this is really not ready yet >=20 > Viralator - Viralator is a perl script that virus scans http downloads=20 > on a linux server after passing through the squid proxy server. > Future Enhancements: > 1. Remove the use of Wget and use LWP Perl module to download the files > 2. Fix Internet Explorer anonomous FTP problem > 3. Fix websites that use .exe as a web page extension >=20 >=20 > So, >=20 > DansGuradian > HAVP > SafeSquid >=20 > These are the only three options I see. >=20 > If DG requires another proxy to be installed, and SS does not have=20 > ClamAV support in the free version, we only have HAVP left. SafeSquid only allows commercial use with theis $50 commercial version=20 of the software. So, ignore it here. DansGuardian, on the other hand, looks good... but: http://dansguardian.org/?page=3Dcopyright2 So the situation is about the same as with SafeSquid. In the end: go for HAVP. >> - BS >> >> >> >> >>> You got my OK. >>> Anybody wants to submit a patch? >>> >>> Heiko >>> >>> On Thu, September 8, 2005 15:45, Kari Mattsson wrote: >>> >>>> from their web site: >>>> >>>> HAVP (HTTP Antivirus Proxy) is a proxy with a ClamAV anti-virus=20 >>>> scanner. >>>> The main aims are continuous, non-blocking downloads and smooth=20 >>>> scanning >>>> of dynamic and password protected HTTP traffic. Havp antivirus proxy= =20 >>>> has a >>>> parent and transparent proxy mode. It can be used with squid or >>>> standalone. >>>> >>>> # HTTP Antivirus proxy >>>> # Scans complete incomming traffic >>>> # Nonblocking downloads >>>> # Smooth scanning of dynamic and password protected traffic >>>> # Can used with squid or other proxy >>>> # Parent proxy support >>>> # Transparent proxy support >>>> # Logfile >>>> # Process change to defined user and group >>>> # Daemon >>>> # Use Clamav (GPL antivirus) >>>> # Operating System: Linux >>>> # Written in C++ >>>> # Released under GPL >>>> >>>> >>>> http://www.server-side.de/index.htm >>>> >>>> >>>> I think this really would add something very unique to DL: >>>> I've been searching for a CD-based Linux with realtime http traffic >>>> virus scanning. None found so far. >>>> >>>> The external boxes from Panda/TrendMicro/etc. are hideously expensiv= e. >>>> A DL box would be more suitable for many organisations. >>>> >>>> >>>> OK. Those expensive boxes do more, but still.. >>>> >>>> >>>> I found this HAVP from http://www.clamav.net/3rdparty.html#webftp >>>> >>>> >>>> The source download is less than 600 KB. >>>> >>>> >>>> This is a Request For Comment :-) >>>> >>>> >>>> >>>> Terveisin/With kind regards/Med h=E4lsningar/Lugupidamisega, >>>> >>>> >>>> Kari Mattsson >>>> >> >> >> >> >> ------------------------------------------------------- >> SF.Net email is Sponsored by the Better Software Conference & EXPO >> September 19-22, 2005 * San Francisco, CA * Development Lifecycle=20 >> Practices >> Agile & Plan-Driven Development * Managing Projects & Teams * Testing=20 >> & QA >> Security * Process Improvement & Measurement * http://www.sqe.com/bsce= 5sf >> _______________________________________________ >> Devil-linux-develop mailing list >> Dev...@li... >> https://lists.sourceforge.net/lists/listinfo/devil-linux-develop >> >=20 >=20 >=20 >=20 > Terveisin/With kind regards/Med h=E4lsningar/Lugupidamisega, >=20 > Kari Mattsson > Trivore Corp. >=20 >=20 > ------------------------------------------------------- > SF.Net email is Sponsored by the Better Software Conference & EXPO > September 19-22, 2005 * San Francisco, CA * Development Lifecycle Pract= ices > Agile & Plan-Driven Development * Managing Projects & Teams * Testing &= QA > Security * Process Improvement & Measurement * http://www.sqe.com/bsce5= sf > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop >=20 Terveisin/With kind regards/Med h=E4lsningar/Lugupidamisega, Kari Mattsson Trivore Corp. --=20 http://trivore.com/ tel:+358-50-69000 |
|
From: Kari M. <ka...@tr...> - 2005-09-08 21:41:58
|
Bruce Smith wrote: > Has anyone actually tried the program? > I'd like to hear how well it really works (or not). Sorry, I cannot help here. > Also, I see there are some other AV addons for squid listed on the > http://www.clamav.net/3rdparty.html#webftp page mentioned. =20 > Is this one the "best" one for DL? Dunno. Se below.. > Also, looking at the docs, it appears that it does not work directly > with squid, but it's a standalone proxy server and squid can be setup t= o > proxy it's traffic through it. Not the best way to integrate it with > Squid, IMO. True, but this gives the option not to cache, but just filter/check for=20 viruses, and you can get by without Squid. > I'm curious why you picked this one over the others listed?=20 Good question :-) > (unless you don't plan on using Squid, then I understand) > As you can probably tell, I use and like Squid. :-) I like Squid too. It is just not required in all installations. I go through all the choices on the above mentioned clamav page: DansGuardian Anti-Virus Patch - takes the Virus Scanning capabilities of=20 ClamAV and integrates them into the content filtering web proxy=20 DansGuardian. Latest: Antivirus plugin stable version 6.4.3 for DansGuardian 2.8.0.6 I'm not sure if this DansGuardian 2.8.0.6 is a proxy which has to be=20 installed, too. OK. This one looks good feature-wise, but that additional requirement...=20 Hmm... Frox - Frox is a transparent ftp proxy. Not for the intended usage? Otherwise, Frox might be a nice addon, if ftp proxy is required. ...or does Squid do ftp proxying really well nowadays? HAVP - proxy with an antivirus filter. It does not cache or filter=20 content. At the moment the complete traffic is scanned. A reason for=20 that is the chance of malicious code in nearly every filetypes e.g. HTML=20 (JavaScript) or Jpeg. mod_clamav - Apache virus scanning filter Not for the intended usage. ClamAV module for ProFTPD - This is an add on module for ProFTPD Not for the intended usage. SafeSquid - if I understand right, the free version is a cache only, and=20 does not have ClamAV support. Commercial version has it all. If I'm wrong, the this might be the best one. SquidClamAV Redirector - 404 Not Found ... Squidclam - this is really not ready yet Viralator - Viralator is a perl script that virus scans http downloads=20 on a linux server after passing through the squid proxy server. Future Enhancements: 1. Remove the use of Wget and use LWP Perl module to download the files 2. Fix Internet Explorer anonomous FTP problem 3. Fix websites that use .exe as a web page extension So, DansGuradian HAVP SafeSquid These are the only three options I see. If DG requires another proxy to be installed, and SS does not have=20 ClamAV support in the free version, we only have HAVP left. > - BS >=20 >=20 >=20 >=20 >>You got my OK. >>Anybody wants to submit a patch? >> >>Heiko >> >>On Thu, September 8, 2005 15:45, Kari Mattsson wrote: >> >>>from their web site: >>> >>>HAVP (HTTP Antivirus Proxy) is a proxy with a ClamAV anti-virus scanne= r. >>>The main aims are continuous, non-blocking downloads and smooth scanni= ng >>>of dynamic and password protected HTTP traffic. Havp antivirus proxy h= as a >>>parent and transparent proxy mode. It can be used with squid or >>>standalone. >>> >>># HTTP Antivirus proxy >>># Scans complete incomming traffic >>># Nonblocking downloads >>># Smooth scanning of dynamic and password protected traffic >>># Can used with squid or other proxy >>># Parent proxy support >>># Transparent proxy support >>># Logfile >>># Process change to defined user and group >>># Daemon >>># Use Clamav (GPL antivirus) >>># Operating System: Linux >>># Written in C++ >>># Released under GPL >>> >>> >>>http://www.server-side.de/index.htm >>> >>> >>>I think this really would add something very unique to DL: >>>I've been searching for a CD-based Linux with realtime http traffic >>>virus scanning. None found so far. >>> >>>The external boxes from Panda/TrendMicro/etc. are hideously expensive. >>>A DL box would be more suitable for many organisations. >>> >>> >>>OK. Those expensive boxes do more, but still.. >>> >>> >>>I found this HAVP from http://www.clamav.net/3rdparty.html#webftp >>> >>> >>>The source download is less than 600 KB. >>> >>> >>>This is a Request For Comment :-) >>> >>> >>> >>>Terveisin/With kind regards/Med h=E4lsningar/Lugupidamisega, >>> >>> >>>Kari Mattsson >>> >=20 >=20 >=20 >=20 > ------------------------------------------------------- > SF.Net email is Sponsored by the Better Software Conference & EXPO > September 19-22, 2005 * San Francisco, CA * Development Lifecycle Pract= ices > Agile & Plan-Driven Development * Managing Projects & Teams * Testing &= QA > Security * Process Improvement & Measurement * http://www.sqe.com/bsce5= sf > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop >=20 Terveisin/With kind regards/Med h=E4lsningar/Lugupidamisega, Kari Mattsson Trivore Corp. |
|
From: Bruce S. <bw...@ar...> - 2005-09-08 21:01:27
|
Has anyone actually tried the program? I'd like to hear how well it really works (or not). Also, I see there are some other AV addons for squid listed on the http://www.clamav.net/3rdparty.html#webftp page mentioned. Is this one the "best" one for DL? Also, looking at the docs, it appears that it does not work directly with squid, but it's a standalone proxy server and squid can be setup to proxy it's traffic through it. Not the best way to integrate it with Squid, IMO. I'm curious why you picked this one over the others listed? (unless you don't plan on using Squid, then I understand) As you can probably tell, I use and like Squid. :-) - BS > You got my OK. > Anybody wants to submit a patch? > > Heiko > > On Thu, September 8, 2005 15:45, Kari Mattsson wrote: > > > > > from their web site: > > > > HAVP (HTTP Antivirus Proxy) is a proxy with a ClamAV anti-virus scanner. > > The main aims are continuous, non-blocking downloads and smooth scanning > > of dynamic and password protected HTTP traffic. Havp antivirus proxy has a > > parent and transparent proxy mode. It can be used with squid or > > standalone. > > > > # HTTP Antivirus proxy > > # Scans complete incomming traffic > > # Nonblocking downloads > > # Smooth scanning of dynamic and password protected traffic > > # Can used with squid or other proxy > > # Parent proxy support > > # Transparent proxy support > > # Logfile > > # Process change to defined user and group > > # Daemon > > # Use Clamav (GPL antivirus) > > # Operating System: Linux > > # Written in C++ > > # Released under GPL > > > > > > http://www.server-side.de/index.htm > > > > > > I think this really would add something very unique to DL: > > I've been searching for a CD-based Linux with realtime http traffic > > virus scanning. None found so far. > > > > The external boxes from Panda/TrendMicro/etc. are hideously expensive. > > A DL box would be more suitable for many organisations. > > > > > > OK. Those expensive boxes do more, but still.. > > > > > > I found this HAVP from http://www.clamav.net/3rdparty.html#webftp > > > > > > The source download is less than 600 KB. > > > > > > This is a Request For Comment :-) > > > > > > > > Terveisin/With kind regards/Med hälsningar/Lugupidamisega, > > > > > > Kari Mattsson > > |
|
From: Heiko Z. <he...@zu...> - 2005-09-08 20:53:13
|
You got my OK. Anybody wants to submit a patch? Heiko On Thu, September 8, 2005 15:45, Kari Mattsson wrote: > > from their web site: > > HAVP (HTTP Antivirus Proxy) is a proxy with a ClamAV anti-virus scanner. > The main aims are continuous, non-blocking downloads and smooth scanning > of dynamic and password protected HTTP traffic. Havp antivirus proxy has a > parent and transparent proxy mode. It can be used with squid or > standalone. > > # HTTP Antivirus proxy > # Scans complete incomming traffic > # Nonblocking downloads > # Smooth scanning of dynamic and password protected traffic > # Can used with squid or other proxy > # Parent proxy support > # Transparent proxy support > # Logfile > # Process change to defined user and group > # Daemon > # Use Clamav (GPL antivirus) > # Operating System: Linux > # Written in C++ > # Released under GPL > > > http://www.server-side.de/index.htm > > > I think this really would add something very unique to DL: > I've been searching for a CD-based Linux with realtime http traffic > virus scanning. None found so far. > > The external boxes from Panda/TrendMicro/etc. are hideously expensive. > A DL box would be more suitable for many organisations. > > > OK. Those expensive boxes do more, but still.. > > > I found this HAVP from http://www.clamav.net/3rdparty.html#webftp > > > The source download is less than 600 KB. > > > This is a Request For Comment :-) > > > > Terveisin/With kind regards/Med hälsningar/Lugupidamisega, > > > Kari Mattsson > > > > > ------------------------------------------------------- > SF.Net email is Sponsored by the Better Software Conference & EXPO > September 19-22, 2005 * San Francisco, CA * Development Lifecycle > Practices > Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA > Security * Process Improvement & Measurement * > http://www.sqe.com/bsce5sf > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop > > -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Kari M. <ka...@tr...> - 2005-09-08 20:45:15
|
from their web site: HAVP (HTTP Antivirus Proxy) is a proxy with a ClamAV anti-virus scanner.=20 The main aims are continuous, non-blocking downloads and smooth scanning=20 of dynamic and password protected HTTP traffic. Havp antivirus proxy has=20 a parent and transparent proxy mode. It can be used with squid or=20 standalone. # HTTP Antivirus proxy # Scans complete incomming traffic # Nonblocking downloads # Smooth scanning of dynamic and password protected traffic # Can used with squid or other proxy # Parent proxy support # Transparent proxy support # Logfile # Process change to defined user and group # Daemon # Use Clamav (GPL antivirus) # Operating System: Linux # Written in C++ # Released under GPL http://www.server-side.de/index.htm I think this really would add something very unique to DL: I've been searching for a CD-based Linux with realtime http traffic=20 virus scanning. None found so far. The external boxes from Panda/TrendMicro/etc. are hideously expensive. A DL box would be more suitable for many organisations. OK. Those expensive boxes do more, but still.. I found this HAVP from http://www.clamav.net/3rdparty.html#webftp The source download is less than 600 KB. This is a Request For Comment :-) Terveisin/With kind regards/Med h=E4lsningar/Lugupidamisega, Kari Mattsson |
|
From: Thomas E. <di...@yo...> - 2005-09-01 19:49:40
|
hi @ all, could you please add: http://search.cpan.org/CPAN/authors/id/B/BE/BEHROOZI/IO-Socket-SSL-0.97.tar.gz http://search.cpan.org/CPAN/authors/id/M/MS/MSERGEANT/XML-Parser-2.34.tar.gz http://search.cpan.org/CPAN/authors/id/G/GB/GBARR/Convert-ASN1-0.19.tar.gz http://search.cpan.org/CPAN/authors/id/B/BJ/BJKUIT/Crypt-SmbHash-0.12.tar.gz http://search.cpan.org/CPAN/authors/id/G/GB/GBARR/Authen-SASL-2.09.tar.gz samba.patch perl-ext.patch to DL-1.2.7? what it is? * Convert::ASN1 - ASN.1 Encode/Decode library * Crypt::SmbHash - Perl-only implementation of lanman and nt md4 hash functions, for use in Samba style smbpasswd entries * IO::Socket, XML::Parser and Authen::SASL needed for ASN1 and SmbHash where to use? * Smbldap-tools: administration for samba by using openldap (http://www.idealx.org/prj/samba/index.en.html) tested on? * root:/data/build# make build install iso dist works on DL-1.2.7! -- thomas |
|
From: Marcel W. <mw...@ma...> - 2005-08-29 07:03:40
|
Hi, I was in need of freeradius in devl-linux 1.2.x, so I created the required files and attached the patches to this email. The freeradius source file I used and placed into build/src is: ftp://ftp.freeradius.org/pub/radius/freeradius-1.0.4.tar.gz Maybe this is as useful for others as it is to my project with devil- linux (wireless 802.1x authentication server). Best regards, Marcel |
|
From: Jim H. <jim...@gm...> - 2005-08-25 00:44:42
|
Well, with a little more poking around I discover arp_announce and arp_ignore, so I think I see what the direction is. So ignore me! In the morning I think I'll set the former to "2" and the latter to "1" and we'll just see what happens :) Jim On 8/24/05, Jim Hogan <jim...@gm...> wrote: > I'm posting here rather than the general list as I am interested to > know what Devil developers/maintainers think with respect to the > direction some patches are going. >=20 > The story: Greedy souls that we are, we deployed several Devil-based > firewalls in dual-interface configuration (two physical interfaces > connected to same physical network, but on separate logical/IP > subnets) to take maximum advantage of the ports available (two!). It > delivers a privately addressed network riding on the general network. >=20 > It is a hand-rolled Devil with kernel 2.4.27 and all > /proc/sys/net/ipv4/conf/ethx/arp_filter =3D 1 >=20 > This all worked swimmingly for 6 months. >=20 > We do not know what changed, but we've started to see signifcant > number of cases of so-called "arp flux" related to particular > workstations whose public addresses are advertised on the firewall's > public interface. Flux occurs and the router serving the subnet/s > will pick up the MAC of the private (wrong) interface for that PC > instead of the (correct) public interface MAC. In reality, we did have > a few cases of this, but it has gotten worse. We can't see what's > triggering it. But that's not what I'm here to ask really. >=20 > We've read what seems like the authoritative doc on this (including > arp flux) here: http://linux-ip.net/html/ether-arp.html We've also > looked at the "hidden" patches for 2.4 kernels (2.6, too, looks like) > here: http://www.ssi.bg/~ja/#hidden >=20 > I am curious to know a) if people have needed to resort to the hidden > patch, and what their experience was, but also b) what do developers > see as the future of these arp-related patches? If they are what is > needed to make dual-homing-on-single-network work, are they going to > be be integrated/merged at some point? >=20 > One other option in front of us is to just abandon our config and go > back to single interfaces. This would just involve work in the short > term, but we'd like to keep our options open for when we can afford > blazingly faster firewall boxes :) >=20 > Jim >=20 >=20 > -- > -*- Jim Hogan >=20 --=20 -*- Jim Hogan Seattle, WA www.drizzle.com/~jimhogan |
|
From: Jim H. <jim...@gm...> - 2005-08-24 22:53:33
|
I'm posting here rather than the general list as I am interested to know what Devil developers/maintainers think with respect to the direction some patches are going. The story: Greedy souls that we are, we deployed several Devil-based firewalls in dual-interface configuration (two physical interfaces connected to same physical network, but on separate logical/IP subnets) to take maximum advantage of the ports available (two!). It delivers a privately addressed network riding on the general network. It is a hand-rolled Devil with kernel 2.4.27 and all /proc/sys/net/ipv4/conf/ethx/arp_filter =3D 1 This all worked swimmingly for 6 months. =20 We do not know what changed, but we've started to see signifcant number of cases of so-called "arp flux" related to particular workstations whose public addresses are advertised on the firewall's public interface. Flux occurs and the router serving the subnet/s will pick up the MAC of the private (wrong) interface for that PC instead of the (correct) public interface MAC. In reality, we did have a few cases of this, but it has gotten worse. We can't see what's triggering it. But that's not what I'm here to ask really. We've read what seems like the authoritative doc on this (including arp flux) here: http://linux-ip.net/html/ether-arp.html We've also looked at the "hidden" patches for 2.4 kernels (2.6, too, looks like) here: http://www.ssi.bg/~ja/#hidden I am curious to know a) if people have needed to resort to the hidden patch, and what their experience was, but also b) what do developers see as the future of these arp-related patches? If they are what is needed to make dual-homing-on-single-network work, are they going to be be integrated/merged at some point? One other option in front of us is to just abandon our config and go back to single interfaces. This would just involve work in the short term, but we'd like to keep our options open for when we can afford blazingly faster firewall boxes :) Jim=20 --=20 -*- Jim Hogan |
|
From: Heiko Z. <he...@zu...> - 2005-08-24 15:03:02
|
On Wed, August 24, 2005 06:48, Serge Leschinsky wrote: > Dear Heiko, > > > Friday, July 29, 2005, 7:18:38 PM, you wrote: > >>> I'm sorry, but I don't check rtos patches with grsec because I don't >>> use grsec in my servers. I check that pax patch has a several rejects >>> after rtos apply. If it's interesting for anybody I'll try to apply >>> rtos and grsec simultaneously. Theoretically, there is no reason for >>> any incompatibles in these patches. > >> Yes please try if they work together. >> Otherwise you'll have to add some logic into the menuconfig part, so you >> can't select rtos together with grsec (which is very easy). > I'm sorry again for so long term of answer writing. There are some > troubles happened. So, abt grsec. I haven't done it because grsec patch > trys to modify sched.c file which was completely rewritten by rtos patch. > Now, I've got a > little changed grsec patch which produces rejects into 2 files: the first - > in Makefile (in version string) - it's easy the second - 4 rejects in > sched.c file. It's a seriously.... > > If anybody is interested into modified patch I'll send it directly > because of its size... It doesn't make sense to maintain a modified grsec patch just for rtos. I would suggest to make rtos only available on systems, which have grsec disabled. -- Regards Heiko Zuerker http://www.devil-linux.org |