From owner-freebsd-security@FreeBSD.ORG Fri Oct 20 14:05:27 2006 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0EF6016A412 for ; Fri, 20 Oct 2006 14:05:27 +0000 (UTC) (envelope-from quetzal@zone3000.net) Received: from mx1.sitevalley.com (sitevalley.com [209.67.60.43]) by mx1.FreeBSD.org (Postfix) with SMTP id 9AAA343D4C for ; Fri, 20 Oct 2006 14:05:26 +0000 (GMT) (envelope-from quetzal@zone3000.net) Received: from unknown (HELO localhost) (217.144.69.37) by 209.67.61.254 with SMTP; 20 Oct 2006 14:05:25 -0000 Date: Fri, 20 Oct 2006 17:04:56 +0300 From: Nikolay Pavlov To: freebsd-security@freebsd.org Message-ID: <20061020140456.GA25717@zone3000.net> Mail-Followup-To: Nikolay Pavlov , freebsd-security@freebsd.org Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.4.2.1i X-Operating-System: FreeBSD 6.1-RELEASE-p10 Subject: mac_portacl X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 20 Oct 2006 14:05:27 -0000 Hi, folks. I am trying to implement reverse proxy using squid with mac_portacl, but i have problem while binding squid to port 80. Am i missed something? Here is my mac_portacl variables: # sysctl security.mac.portacl. security.mac.portacl.enabled: 1 security.mac.portacl.suser_exempt: 1 security.mac.portacl.autoport_exempt: 1 security.mac.portacl.port_high: 1023 security.mac.portacl.rules: uid:100:tcp:80 And squid user info: # grep squid /etc/passwd squid:*:100:100:squid caching-proxy pseudo user:/usr/local/squid:/usr/sbin/nologin Also here is cache.log: 2006/10/20 09:55:59| Starting Squid Cache version 2.5.STABLE14 for i386-portbld-freebsd6.1... 2006/10/20 09:55:59| Process ID 6584 2006/10/20 09:55:59| With 11072 file descriptors available 2006/10/20 09:55:59| DNS Socket created at 0.0.0.0, port 59879, FD 5 2006/10/20 09:55:59| Adding nameserver 206.53.60.10 from /etc/resolv.conf 2006/10/20 09:55:59| User-Agent logging is disabled. 2006/10/20 09:55:59| Unlinkd pipe opened on FD 10 2006/10/20 09:55:59| Swap maxSize 102400000 KB, estimated 7876923 objects 2006/10/20 09:55:59| Target number of buckets: 393846 2006/10/20 09:55:59| Using 524288 Store buckets 2006/10/20 09:55:59| Max Mem size: 1048576 KB 2006/10/20 09:55:59| Max Swap size: 102400000 KB 2006/10/20 09:55:59| Rebuilding storage in /cache (DIRTY) 2006/10/20 09:55:59| Using Least Load store dir selection 2006/10/20 09:55:59| Set Current Directory to /usr/local/squid/cache 2006/10/20 09:55:59| Loaded Icons. 2006/10/20 09:55:59| commBind: Cannot bind socket FD 12 to *:80: (13) Permission denied FATAL: Cannot open HTTP Port Squid Cache (Version 2.5.STABLE14): Terminated abnormally. CPU Usage: 0.035 seconds = 0.000 user + 0.035 sys Maximum Resident Size: 9528 KB Page faults with physical i/o: 0 -- ====================================================================== - Best regards, Nikolay Pavlov. <<<----------------------------------- ======================================================================