From owner-freebsd-security Fri Nov 22 11:38:43 2002 Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9DB1F37B401 for ; Fri, 22 Nov 2002 11:38:41 -0800 (PST) Received: from carbon.berkeley.netdot.net (carbon.berkeley.netdot.net [216.27.190.205]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4CD9D43EBE for ; Fri, 22 Nov 2002 11:38:41 -0800 (PST) (envelope-from nick@netdot.net) Received: by carbon.berkeley.netdot.net (Postfix, from userid 101) id A5201F804; Fri, 22 Nov 2002 11:38:40 -0800 (PST) Date: Fri, 22 Nov 2002 11:38:40 -0800 From: Nicholas Esborn To: Alex Povolotsky Cc: freebsd-security@FreeBSD.ORG Subject: Re: jailed virtual https, anyone? Message-ID: <20021122193840.GA16501@carbon.berkeley.netdot.net> References: <20021122155027.7f694357.tarkhil@webmail.sub.ru> <20021122113328.M48082-100000@lorax.ubergeeks.com> <20021122210409.0061b0c7.tarkhil@webmail.sub.ru> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable In-Reply-To: <20021122210409.0061b0c7.tarkhil@webmail.sub.ru> User-Agent: Mutt/1.5.1i Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Have you considered using a simple TCP-port redirector like pound? It's in the ports tree in www/pound. It would pass the connection in to your lo0 alias with minimal modifications to the packets. -nick On Fri, Nov 22, 2002 at 09:04:09PM +0300, Alex Povolotsky wrote: > YES!!! YES!!! YES!!! I do understand it for quite some time!!! >=20 > But, for instance, transproxy extracts real IP information from /dev/ipl,= which seems to be unavailable from inside the jail. >=20 > I need either proxy with some method of SSL environment variables passing= , or some apache module retrieving information from /dev/ipl or something e= lse, or some way to transfer packets keeping original destination address. >=20 > That is what I'm seeking here.=20 >=20 > --=20 > Alex. --=20 Nicholas Esborn Unix Systems Administrator Berkeley, California To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message