Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Subgraph Firewall should support a rules.d/ for default policies distributed with packages #47

Open
dma opened this issue Sep 11, 2017 · 1 comment

Comments

@dma
Copy link
Contributor

dma commented Sep 11, 2017

e.g. we plan to built default rules, one easy example is ricochet. Something like:

[ricochet|/usr/bin-oz/ricochet]
ALLOW|.onion:|SYSTEM|-1:-1|

These would be included in a Subgraph package and would allow us to issue updates (which may be rare) in isolation from the user's own custom rules.

@Zerokami
Copy link

Zerokami commented Mar 26, 2018

I hope you use an easy to use format for rules like JSON as you did with OZ or conf.

I hope you don't make a new format unless it is essential for security

Learning different rule systems can get complicated for users

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants