Re: [squid-users] chrooting: why and how?

From: Rick G. Kilgore <rgk@dont-contact.us>
Date: Tue, 31 Aug 2004 15:44:50 -0600

        Works just as if it was not chroot jailed at all. Actually with the
conf file in the chroot I had more problems accessing external ACL and
other oddities.

Joe Cooper wrote:
> Henrik Nordstrom wrote:
>
>> On Tue, 31 Aug 2004, Joe Cooper wrote:
>>
>>> resolve.conf) that Squid relies on (it could be that shared libraries
>>> are pulled in before Squid chroots, and so they might not be
>>> needed--Henrik wrote the chroot code I think, or at least maintains
>>> it now, maybe he'll chime in with clarification).
>>
>>
>>
>> If you use the chroot directive in squid.conf then only logs, cache
>> and a dev/null node is minimally required within the chroot directory
>> structure. It is also a good idea to set up a syslog socket within the
>> chroot (man syslogd).
>>
>> The squid configuration file and any data referenced from there should
>> be outside of the chroot directory, and unless you use any helpers no
>> libraries is required either.
>
>
> Out of curiosity: without squid.conf in the chroot, how does a -k
> reconfigure work?
>

-- 
Hoy es: viernes julio veintedos  des miles y cuatro
fase del dia ----> coma esta usted --- how are you
This message is for the designated recipient only and may contain
privileged, proprietary, or otherwise private information.  If you have
received it in error, please notify the sender immediately and delete 
the original.
Any other use of the email by you is prohibited.
Este mensaje esta' para el recipiente sen~alado solamente y puede contener 
la informacio'n privilegiada, propietaria, o de otra manera privada. Si 
usted lo ha recibido en error, notifique por favor el remitente 
inmediatamente y suprima la original. Cualquier otro uso del email de 
usted se prohi'be.
Rick G. Kilgore
State of Colorado Department of Revenue IT/CSTARS (DDP/CCR/RWOC)
E-Mail: rgk@valhall4.dor.state.co.us
Phone: (303) 205-5659
Fax: (303) 205-5715
Received on Tue Aug 31 2004 - 15:45:04 MDT

This archive was generated by hypermail pre-2.1.9 : Wed Sep 01 2004 - 12:00:03 MDT