[fw-wiz] i-cap proposals

From: ArkanoiD (ark_at_eltex.net)
Date: 02/11/05

  • Next message: Paul D. Robertson: "Re: [fw-wiz] VPNmadness gets more support;"
    To: firewall-wizards@honor.icsalabs.com
    Date: Fri, 11 Feb 2005 19:32:59 +0300
    
    

    Shame on me, though i joined i-cap mailing list quite early looking for
    universal content inspection protocol, i found it too http-bound for general
    use and seeing no live code for a long period of time somehow lost
    interest. I underestimated the project's future and thus made no contributions.
    It is late now, but there are some major design problems:

    1) response content entities icap deals with defining inspection policy are..
    surprise, "filenames with given extensions". (Transfer-* headers)
    Wait, there is no such thing when we are not dealing with local storage!
    There are content types! And those may be multipart of various types
    (real pain for inspection proxies to deal) and so on.

    2) It is still HTTP-bound. There should be recommendations on how to deal
    with SMTP, POP3, IMAP, FTP and other - we should standardize how those
    requests are being presented to ICAP.

    Any ideas what to do now? ;-)

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul D. Robertson: "Re: [fw-wiz] VPNmadness gets more support;"