|
From: Heiko Z. <he...@zu...> - 2003-10-11 01:15:19
|
Bruce Smith wrote: >>>>Not necessary. All the squid authorization modules are completely stand >>>>alone binaries. They only take up a little space on the CD. They are >>>>not run unless you add a line in /etc/squid.conf something like: >>>> >>>> auth_param basic program /usr/sbin/yp_auth ... >>>> >>>> >>>Ok, good, but for a real firewall can we offer a configure option so >>>those modules can be selected on an per module basis or just "auth >>>modules yes or no"? So the security consious people can create their >>>own stripped down firewall only version. Just a thought. >>> >>> >>> >>He got a point again.... >> >>Bruce already added the option to (de-)select the nis and port mapper stuff. >>I would suggest that you (Bruce) add some more intelligence to the squid >>script. This should make everybody happy. >> >> > >I'm sorry, but this is crazy. These are small stand alone programs >which are part the squid package, and should be included. All they do >is check a password crypt and send "OK" or "ERR" to stdout. > >There are tons of other non-optional programs that are just as much of a >security risk (none) as these are. We could go crazy making every >binary optional. > > I'm trying to find a solution which makes everybody ( a kind of ) happy. But there's probably a bug anyway: when you don't select the yp stuff, the squid compile should actually fail since it's specified as a required module. Heiko |