2 # - REVIEW patches and configuration
4 # For this to work correctly, you will need to patch your linux
5 # kernel with the TOS preserving ZPH patch.
6 # The kernel patch can be downloaded from http://zph.bratcheda.org
9 %bcond_with combined_log # enables apache-like combined log format
11 Summary: SQUID Internet Object Cache
12 Summary(es.UTF-8): proxy/cache para WWW/FTP/gopher
13 Summary(pl.UTF-8): Uniwersalny serwer proxy-cache
14 Summary(pt_BR.UTF-8): Cache Squid de objetos Internet
15 Summary(ru.UTF-8): Squid - кэш объектов Internet
16 Summary(uk.UTF-8): Squid - кеш об'єктів Internet
17 Summary(zh_CN.UTF-8): SQUID 高速缓冲代理服务器
23 Group: Networking/Daemons
24 Source0: http://www.squid-cache.org/Versions/v3/3.2/%{name}-%{version}.tar.bz2
25 # Source0-md5: cdd3612bed27e8d513b713004c78bf5b
27 Source2: %{name}.sysconfig
28 Source3: http://squid-docs.sourceforge.net/latest/zip-files/book-full-html.zip
29 # Source3-md5: 4f3b6dab1de9cbb847df89d8b417378a
30 Source4: %{name}.conf.patch
31 Source5: %{name}.logrotate
33 Source7: %{name}-cachemgr-apache.conf
34 Source8: %{name}.tmpfiles
35 Patch0: %{name}-fhs.patch
36 Patch1: %{name}-location.patch
37 Patch2: %{name}-crash-on-ENOSPC.patch
38 Patch4: %{name}-2.5.STABLE4-apache-like-combined-log.patch
39 Patch5: %{name}-ppc-m32.patch
40 Patch6: %{name}-cachemgr-webapp.patch
41 # http://www.squid-cache.org/mail-archive/squid-dev/201207/0099.html
42 # http://www.squid-cache.org/mail-archive/squid-dev/201207/att-0177/squidv3-vary-cache-1.patch
43 Patch7: squidv3-vary-cache-1.patch
44 # http://www.squid-cache.org/mail-archive/squid-dev/201207/att-0177/squidv3-vary-headers-shm-hack.patch
45 Patch8: squidv3-vary-headers-shm-hack.patch
46 URL: http://www.squid-cache.org/
47 BuildRequires: autoconf
48 BuildRequires: automake
49 BuildRequires: cppunit-devel
50 BuildRequires: cyrus-sasl-devel >= 2.1.0
51 BuildRequires: db-devel
52 BuildRequires: expat-devel
53 BuildRequires: heimdal-devel
54 BuildRequires: libcap-devel >= 1:2.09
55 BuildRequires: libecap-devel >= 0.2.0
56 BuildRequires: libltdl-devel
57 BuildRequires: libnetfilter_conntrack-devel
58 BuildRequires: libstdc++-devel
59 BuildRequires: libtool
60 BuildRequires: libxml2-devel
61 BuildRequires: openldap-devel >= 2.3.0
62 BuildRequires: openssl-devel >= 0.9.7d
63 BuildRequires: pam-devel
64 BuildRequires: perl-base
65 BuildRequires: rpmbuild(macros) >= 1.268
66 BuildRequires: sed >= 4.0
68 Requires(post): /bin/hostname
69 Requires(post): fileutils
70 Requires(post): findutils
72 Requires(post,preun): /sbin/chkconfig
73 Requires(postun): /usr/sbin/groupdel
74 Requires(postun): /usr/sbin/userdel
75 Requires(pre): /usr/bin/getgid
76 Requires(pre): /usr/lib/rpm/user_group.sh
77 Requires(pre): /usr/sbin/groupadd
78 Requires(pre): /usr/sbin/useradd
79 Requires(pre,triggerpostun): /bin/id
80 Requires(pre,triggerpostun): /usr/sbin/usermod
81 Requires: rc-scripts >= 0.2.0
82 Requires: setup >= 2.4.6
83 Provides: group(squid)
84 # epoll enabled by default:
85 Requires: uname(release) >= 2.6
86 # TPROXYv4 (v2 disabled b/c it breaks v4)
87 #Suggests: uname(release) >= 2.6.28.3
89 Conflicts: logrotate < 3.8.0
90 BuildRoot: %{tmpdir}/%{name}-%{version}-root-%(id -u -n)
92 %define _webapps /etc/webapps
93 %define _webapp cachemgr
94 %define _libexecdir %{_libdir}/%{name}
95 %define _sysconfdir /etc/%{name}
96 %define _cgidir %{_prefix}/lib/cgi-bin/%{_webapp}
99 Squid is a high-performance proxy caching server for web clients,
100 supporting FTP, gopher, and HTTP data objects. Unlike traditional
101 caching software, Squid handles all requests in a single,
102 non-blocking, I/O-driven process. Squid keeps meta data and especially
103 hot objects cached in RAM, caches DNS lookups, supports non-blocking
104 DNS lookups, and implements negative caching of failed requests. If
105 you are tight on memory, check out the NOVM version of this package.
106 Squid supports SSL, extensive access controls, and full request
107 logging. By using the lightweight Internet Cache Protocol, Squid
108 caches can be arranged in a hierarchy or mesh for additional bandwidth
109 savings. Squid consists of a main server program squid, a Domain Name
110 System lookup program dnsserver, a program for retrieving FTP data
111 ftpget, and some management and client tools. When squid starts up, it
112 spawns a configurable number of dnsserver processes, each of which can
113 perform a single, blocking Domain Name System (DNS) lookup. This
114 reduces the amount of time the cache waits for DNS lookups. Squid is
115 derived from the ARPA-funded Harvest project.
117 %description -l es.UTF-8
118 Squid es un servidor proxy con caché de alto desempeño para clientes
119 web, soportando FTP, gopher y HTTP. Diferentemente de softwares
120 tradicionales de caché squid manipula todas las requisiciones en un
121 único proceso sin bloqueos, direccionado a E/S. Mantienen metadatos y
122 objetos frecuentemente pedidos en uno caché en memoria RAM. Hace caché
123 de resoluciones DNS, soporta resoluciones DNS sin bloqueo y implementa
124 un caché negativo de requisiciones que fallen. Si tiene poca memoria
125 da un vistazo en la versión NOVM de este paquete. También soporta SSL,
126 controles extensivos de acceso y registro (log) completo de las
127 requisiciones. Usando el ligero Protocolo de Caches Internet (ICP)
128 puede ser usado en una jerarquía de servidores para mayor ahorro de la
129 banda de comunicación. Está compuesto del programa squid (servidor
130 principal), del programa dnsserver (para resolución DNS), del programa
131 ftpget (para transmisiones ftp) y otras herramientas clientes y para
132 administración. Cuando squid se inicia, dispara un número configurable
133 de procesos dnsserver, cada uno pudiendo ejecutar solamente una
134 resolución DNS con poder de bloquear. Esto reduce el tiempo que el
135 caché espera por resoluciones DNS. Fue derivado del proyecto Harvest,
136 financiado por la ARPA.
138 %description -l pl.UTF-8
139 Squid jest wysoce wydajnym serwerem proxy-cache dla przeglądarek WWW,
140 klientów FTP i gopher. Squid przechowuje najczęściej pobierane dane w
141 pamięci RAM i zapamiętuje odwołania do DNS. Squid oferuje wsparcie dla
142 SSL, rozbudowaną kontrolę dostępu oraz pełne rejestrowanie pobieranych
143 danych. Dzięki użyciu protokołu ICP (Internet Cache Protocol), serwer
144 squid można łączyć w hierarchię, zwiększając ich efektywność. Pakiet
145 squid obejmuje: główny program serwera squid, program dostarczający
146 informacji z DNS dnsserver, program odbierający dane FTP ftpget, oraz
147 pomocnicze programy do zarządzania. Squid wywodzi się ze
148 sponsorowanego przez ARPA projektu Harvest.
150 %description -l pt_BR.UTF-8
151 O Squid é um servidor proxy com cache de alta performance para
152 clientes web, suportando FTP, gopher e HTTP. Diferentemente de
153 softwares tradicionais de cache o squid manipula todas as requisições
154 em um único processo sem bloqueios, direcionado a E/S.
156 Mantém meta dados e objetos freqüentemente pedidos num cache em
157 memória RAM. Faz cache de resoluções DNS, suporta resoluções DNS sem
158 bloqueio e implementa um cache negativo de requisições que falharem.
159 Se você tem pouca memória dê uma olhada na versão NOVM deste pacote.
161 Também suporta SSL, controles extensivos de acesso e registro (log)
162 completo das requisições. Usando o leve Protocolo de Caches Internet
163 (ICP) ele pode ser usado em uma hierarquia de servidores para maior
164 economia de banda de comunicação.
166 Ele consiste do programa squid (servidor principal), do programa
167 dnsserver (para resolução DNS), do programa ftpget (para transmissões
168 ftp) e outras ferramentas clientes e para gerenciamento. Quando o
169 squid é inicializado ele dispara um número configurável de processos
170 dnsserver, cada um podendo executar somente uma resolução DNS
171 bloqueante. Isto reduz o tempo que o cache espera por resoluções DNS.
173 Foi derivado do projeto Harvest, financiado pela ARPA.
175 %description -l ru.UTF-8
176 Squid - это высокопроизводительный кэширующий прокси-сервер для
177 клиентов web, поддерживающий объекты данных типа FTP, gopher и HTTP. В
178 отличие от традиционных кэширующих программ, Squid обрабатывает все
179 запросы при помощи одного неблокирующегося, управляемого
180 вводом-выводом процесса.
182 Этот пакет имеет встроенную поддержку базы данных сетевых ICMP-проб
185 %description -l uk.UTF-8
186 Squid - це кешуючий проксі-сервер для web-клієнтів, що підтримує
187 об'єкти даних типу FTP, gopher та HTTP. На відміну від традиційних
188 кешуючих програм, Squid обробляє всі запити за допомогою одного
189 неблокуючого, керованого вводом-виводом процесу.
191 Цей пакет має вбудовану підтримку бази даних мережевих ICMP-проб
195 Summary: CGI script for Squid management
196 Summary(pl.UTF-8): Skrypt CGI do zarządzania Squidem przez WWW
197 Group: Applications/WWW
198 # does not require squid locally
199 Requires: group(http)
202 Requires: webserver(access)
203 Requires: webserver(alias)
204 Requires: webserver(cgi)
206 %description cachemgr
207 Cachemgr.cgi is a CGI script that allows administrator to check
208 various informations about Squid via WWW.
210 %description cachemgr -l pl.UTF-8
211 Cachemgr.cgi jest skryptem CGI, który pozwala administratorowi
212 zapoznać się z informacjami o pracy Squida poprzez WWW.
214 %package kerberos_auth
215 Summary: Authentication via the Negotiate RFC 4559 for proxies
216 Summary(pl.UTF-8): Uwierzytelnianie przez negocjację RFC 4559 dla serwerów proxy
217 Group: Networking/Admin
218 Requires: %{name} = %{epoch}:%{version}-%{release}
219 Provides: squid-kerb_auth = %{epoch}:%{version}-%{release}
220 Obsoletes: squid-kerb_auth < %{epoch}:%{version}-%{release}
222 %description kerberos_auth
223 This squid helper is a reference implementation that supports
224 authentication via the Negotiate RFC 4559 for proxies. It decodes RFC
225 2478 SPNEGO GSS-API tokens from IE7 either through helper functions or
226 via SPNEGO supporting Kerberos libraries and RFC 1964 Kerberos tokens
227 from Firefox on Linux.
229 %description kerberos_auth -l pl.UTF-8
230 Pakiet ten jest implementacją uwierzytelniania przez negocjacji RFC
231 4559 dla serwerów proxy. Dekoduje żetony SPNEGO GSS-API RFC 2478 z IE7
232 poprzez funkcje pomocnicze lub przez biblioteki Kerberos wspierające
233 SPNEGO i żetony Kerberos RFC 1964 z Firefoksa w Linuksie.
236 Summary: LDAP authentication helper for Squid
237 Summary(pl.UTF-8): Obsługa uwierzytelniania LDAP dla squida
238 Group: Networking/Admin
239 Requires: %{name} = %{epoch}:%{version}-%{release}
241 %description ldap_auth
242 This Squid helper allows authentication against LDAP directories using
243 the "simple authentication" (plain-text).
245 %description ldap_auth -l pl.UTF-8
246 Pakiet ten pozwala na uwierzytelnianie przez LDAP za pomocą prostego
247 uwierzytelniania (otwartym tekstem).
250 Summary: PAM authentication helper for Squid
251 Summary(pl.UTF-8): Obsługa uwierzytelniania PAM dla squida
252 Group: Networking/Admin
253 Requires: %{name} = %{epoch}:%{version}-%{release}
254 Requires: pam >= 0.77.3
256 %description pam_auth
257 This program authenticates users against a PAM configured
258 authentication service "squid". This allows you to authenticate Squid
259 users to any authentication source for which you have a PAM module.
261 %description pam_auth -l pl.UTF-8
262 Program ten pozwala na uwierzytelnianie użytkowników squida w dowolnym
263 źródle posiadającym moduł PAM.
266 Summary: SMB authentication helper for Squid
267 Summary(pl.UTF-8): Obsługa uwierzytelniania SMB dla squida
268 Group: Networking/Admin
269 Requires: %{name} = %{epoch}:%{version}-%{release}
271 %description smb_auth
272 This is a proxy authentication module. With smb_auth you can
273 authenticate proxy users against an SMB server like Windows NT or
276 %description smb_auth -l pl.UTF-8
277 To jest moduł uwierzytelniania proxy. Przy pomocy smb_auth można
278 uwierzytelniać użytkowników proxy na serwerach SMB, jak Windows NT czy
282 Summary: MSNT domain authentication helper for Squid
283 Summary(pl.UTF-8): Obsługa uwierzytelniania w domenie MSNT dla squida
284 Group: Networking/Admin
285 Requires: %{name} = %{epoch}:%{version}-%{release}
287 %description msnt_auth
288 This is an authentication module for the Squid proxy server to
289 authenticate users on an NT domain.
291 %description msnt_auth -l pl.UTF-8
292 Jest to moduł uwierzytelniania proxy, który pozwala na
293 uwierzytelnianie użytkowników proxy w domenie NT.
296 Summary: NIS authentication helper for Squid
297 Summary(pl.UTF-8): Obsługa uwierzytelniania NIS dla squida
298 Group: Networking/Admin
299 Requires: %{name} = %{epoch}:%{version}-%{release}
300 Provides: squid-yp_auth = %{epoch}:%{version}-%{release}
301 Obsoletes: squid-yp_auth < %{epoch}:%{version}-%{release}
303 %description nis_auth
304 This is an authentication module for the Squid proxy server to
305 authenticate users on NIS.
307 %description nis_auth -l pl.UTF-8
308 Jest to moduł uwierzytelniania proxy, który pozwala na
309 uwierzytelnianie użytkowników proxy poprzez NIS.
312 Summary: NCSA httpd style authentication helper for Squid
313 Summary(pl.UTF-8): Obsługa uwierzytelniania NCSA httpd dla squida
314 Group: Networking/Admin
315 Requires: %{name} = %{epoch}:%{version}-%{release}
317 %description ncsa_auth
318 This module uses a NCSA httpd style password file for authentication.
320 %description ncsa_auth -l pl.UTF-8
321 Moduł uwierzytelniania proxy używający pliku haseł jak w NCSA httpd.
324 Summary: SASL authentication helper for Squid
325 Summary(pl.UTF-8): Obsługa uwierzytelniania SASL dla squida
326 Group: Networking/Admin
327 Requires: %{name} = %{epoch}:%{version}-%{release}
329 %description sasl_auth
330 This is an authentication module for the Squid proxy server to
331 authenticate users via SASL.
333 %description sasl_auth -l pl.UTF-8
334 Jest to moduł uwierzytelniania proxy, który pozwala na
335 uwierzytelnianie użytkowników proxy poprzez SASL.
337 %package getpwname_auth
338 Summary: getpwname authentication helper for Squid
339 Summary(pl.UTF-8): Obsługa uwierzytelniania getpwname dla squida
340 Group: Networking/Admin
341 Requires: %{name} = %{epoch}:%{version}-%{release}
343 %description getpwname_auth
344 This is an authentication module for the Squid proxy server to
345 authenticate users using getpwname.
347 %description getpwname_auth -l pl.UTF-8
348 Jest to moduł uwierzytelniania proxy, który pozwala na
349 uwierzytelnianie użytkowników proxy poprzez getpwname.
352 Summary: passwd authentication helper for Squid
353 Summary(pl.UTF-8): Obsługa uwierzytelniania passwd dla squida
354 Group: Networking/Admin
355 Requires: %{name} = %{epoch}:%{version}-%{release}
357 %description passwd_auth
358 This is an authentication module for the Squid proxy server to
359 authenticate users with separate passwd file.
361 %description passwd_auth -l pl.UTF-8
362 Jest to moduł uwierzytelniania proxy, który pozwala na
363 uwierzytelnianie użytkowników proxy poprzez oddzielny plik passwd.
366 Summary: NTLM authentication helper for Squid
367 Summary(pl.UTF-8): Obsługa uwierzytelniania NTLM dla squida
368 Group: Networking/Admin
369 Requires: %{name} = %{epoch}:%{version}-%{release}
371 %description ntlm_auth
372 This is an authentication module for the Squid proxy server to
373 authenticate users on NTLM.
375 %description ntlm_auth -l pl.UTF-8
376 Jest to moduł uwierzytelniania proxy, który pozwala na
377 uwierzytelnianie użytkowników proxy poprzez NTLM.
380 Summary: RADIUS authentication helper for Squid
381 Summary(pl.UTF-8): Obsługa uwierzytelniania RADIUS dla squida
382 Group: Networking/Admin
383 Requires: %{name} = %{epoch}:%{version}-%{release}
385 %description radius_auth
386 This helper allows Squid to connect to a RADIUS server to validate the
387 user name and password of Basic HTTP authentication.
389 %description radius_auth -l pl.UTF-8
390 Program ten pozwala na uwierzytelnianie użytkowników squida przez
394 Summary: Database authentication helper for Squid
395 Summary(pl.UTF-8): Obsługa uwierzytelniania przez bazę danych dla squida
396 Group: Networking/Admin
397 Requires: %{name} = %{epoch}:%{version}-%{release}
399 Suggests: perl-DBD-mysql
402 This is an authentication module for the Squid proxy server to
403 authenticate users againsta a database.
405 %description db_auth -l pl.UTF-8
406 Jest to moduł uwierzytelniania proxy, który pozwala na
407 uwierzytelnianie użytkowników proxy poprzez bazę danych.
410 Summary: POP3 authentication helper for Squid
411 Summary(pl.UTF-8): Obsługa uwierzytelniania POP3 dla squida
412 Group: Networking/Admin
413 Requires: %{name} = %{epoch}:%{version}-%{release}
415 %description pop3_auth
416 This is an authentication module for the Squid proxy server to
417 authenticate users on POP3.
419 %description pop3_auth -l pl.UTF-8
420 Jest to moduł uwierzytelniania proxy, który pozwala na
421 uwierzytelnianie użytkowników proxy poprzez POP3.
423 %package negotiate_wrapper_auth
424 Summary: Kerberos authentication helper for Squid
425 Summary(pl.UTF-8): Obsługa uwierzytelniania Kerberos dla squida
426 Group: Networking/Admin
427 Requires: %{name} = %{epoch}:%{version}-%{release}
428 Requires: %{name}-kerberos_auth = %{epoch}:%{version}-%{release}
429 Requires: %{name}-ntlm_auth = %{epoch}:%{version}-%{release}
431 %description negotiate_wrapper_auth
432 This is an authentication module for the Squid proxy server to
433 authenticate users on Kerberos.
435 %description negotiate_wrapper_auth -l pl.UTF-8
436 Jest to moduł uwierzytelniania proxy, który pozwala na
437 uwierzytelnianie użytkowników proxy poprzez Kerberosa.
439 %package digest_edirectory_auth
440 Summary: eDirectory authentication helper for Squid
441 Summary(pl.UTF-8): Obsługa uwierzytelniania eDirectory dla squida
442 Group: Networking/Admin
443 Requires: %{name} = %{epoch}:%{version}-%{release}
445 %description digest_edirectory_auth
446 This is an authentication module for the Squid proxy server to
447 authenticate users on eDirectory.
449 %description digest_edirectory_auth -l pl.UTF-8
450 Jest to moduł uwierzytelniania proxy, który pozwala na
451 uwierzytelnianie użytkowników proxy poprzez eDirectory.
453 %package digest_ldap_auth
454 Summary: LDAP authentication helper for Squid
455 Summary(pl.UTF-8): Obsługa uwierzytelniania LDAP dla squida
456 Group: Networking/Admin
457 Requires: %{name} = %{epoch}:%{version}-%{release}
459 %description digest_ldap_auth
460 This is an authentication module for the Squid proxy server to
461 authenticate users on LDAP.
463 %description digest_ldap_auth -l pl.UTF-8
464 Jest to moduł uwierzytelniania proxy, który pozwala na
465 uwierzytelnianie użytkowników proxy poprzez LDAP.
468 Summary: IP external ACL helper for Squid
469 Summary(pl.UTF-8): Wsparcie kontroli dostępu przez IP dla squida
470 Group: Networking/Admin
471 Requires: %{name} = %{epoch}:%{version}-%{release}
474 This is an external ACL module for the Squid proxy server to limit
475 access for users based on IP address.
477 %description ip_acl -l pl.UTF-8
478 Jest to moduł kontroli dostępu (ACL) do proxy, który pozwala na
479 ograniczenie dostępu użytkowników proxy na podstawie ich adresu IP.
482 Summary: LDAP group external ACL helper for Squid
483 Summary(pl.UTF-8): Wsparcie kontroli dostępu przez grupy LDAP dla squida
484 Group: Networking/Admin
485 Requires: %{name} = %{epoch}:%{version}-%{release}
487 %description ldap_acl
488 This is an external ACL module for the Squid proxy server to limit
489 access for users based on LDAP group membership.
491 %description ldap_acl -l pl.UTF-8
492 Jest to moduł kontroli dostępu (ACL) do proxy, który pozwala na
493 ograniczenie dostępu użytkowników proxy na podstawie ich
494 przynależności do grup LDAP.
497 Summary: UNIX group external ACL helper for Squid
498 Summary(pl.UTF-8): Wsparcie kontroli dostępu przez grupy UNIX dla squida
499 Group: Networking/Admin
500 Requires: %{name} = %{epoch}:%{version}-%{release}
502 %description unix_acl
503 This is an external ACL module for the Squid proxy server to limit
504 access for users based on UNIX group membership.
506 %description unix_acl -l pl.UTF-8
507 Jest to moduł kontroli dostępu (ACL) do proxy, który pozwala na
508 ograniczenie dostępu użytkowników proxy na podstawie ich
509 przynależności do grup UNIX.
512 Summary: NT domain group external ACL helper for Squid
513 Summary(pl.UTF-8): Wsparcie kontroli dostępu przez grupy w domenie NT dla squida
514 Group: Networking/Admin
515 Requires: %{name} = %{epoch}:%{version}-%{release}
517 %description wbinfo_acl
518 This is an external ACL module for the Squid proxy server to limit
519 access for users based on NT domain group membership using wbinfo.
521 %description wbinfo_acl -l pl.UTF-8
522 Jest to moduł kontroli dostępu (ACL) do proxy, który pozwala na
523 ograniczenie dostępu użytkowników proxy na podstawie ich
524 przynależności do grup w domenie NT przy użyciu wbinfo.
527 Summary: Squid session tracking external ACL group helper
528 Summary(pl.UTF-8): Wsparcie kontroli dostępu przez śledzenie sesji
529 Group: Networking/Admin
530 Requires: %{name} = %{epoch}:%{version}-%{release}
532 %description session_acl
533 This helper maintains a concept of sessions by monitoring requests and
534 timing out sessions if no requests have been seen for the idle timeout
537 %description session_acl -l pl.UTF-8
538 Moduł oparty na koncepcji sesji, śledzący zapytania i wygaszający
539 sesje jeśli w określonym czasie nie widziano w ich obrębie kolejnych
542 %package edirectory_userip_acl
543 Summary: Squid eDirectory IP Lookup Helper
544 Summary(pl.UTF-8): Wsparcie kontroli dostępu przez eDirectory
545 Group: Networking/Admin
546 Requires: %{name} = %{epoch}:%{version}-%{release}
548 %description edirectory_userip_acl
549 This is an external ACL module for the Squid proxy server to limit
550 access for users based on IP address lookup in eDirectory.
552 %description edirectory_userip_acl -l pl.UTF-8
553 Jest to moduł kontroli dostępu (ACL) do proxy, który pozwala na
554 ograniczenie dostępu użytkowników proxy na podstawie ich adresu IP
555 popranego z eDirectory.
557 %package kerberos_ldap_group_acl
558 Summary: Squid LDAP external acl group helper for Kerberos or NTLM credentials
559 Summary(pl.UTF-8): Wsparcie kontroli dostępu przez grupy LDAP/Kerberos/NTLM dla squida
560 Group: Networking/Admin
561 Requires: %{name} = %{epoch}:%{version}-%{release}
563 %description kerberos_ldap_group_acl
564 This is an external ACL module for the Squid proxy server to limit
565 access for users based on LDAP Kerberos or NTLM credentials.
567 %description kerberos_ldap_group_acl -l pl.UTF-8
568 Jest to moduł kontroli dostępu (ACL) do proxy, który pozwala na
569 ograniczenie dostępu użytkowników proxy na podstawie ich uprawnień
570 Kerberosowych lub NTLM-owych w LDAP.
573 Summary: Perl scripts for Squid
574 Summary(pl.UTF-8): Skrypty perlowe dla Squida
575 Group: Networking/Admin
576 Requires: %{name} = %{epoch}:%{version}-%{release}
579 This package contains Perl scripts and contributed programs for Squid.
581 %description scripts -l pl.UTF-8
582 Ten pakiet zawiera skrypty perlowe i dodatkowe programy dla Squida.
589 %{?with_combined_log:%patch4 -p1}
597 %{__sed} -i -e '1s#!.*bin/perl#!%{__perl}#' {contrib,scripts}/*.pl
606 --disable-strict-error-checking \
607 --with-default-user=squid \
608 --with-logdir=/var/log/squid \
609 --with-swapdir=/var/cache/squid \
610 --with-pidfile=/var/run/squid.pid \
611 --datadir=%{_datadir}/squid \
614 --enable-basic-auth-helpers \
615 --enable-ntlm-auth-helpers \
616 --enable-negotiate-auth-helpers \
617 --enable-digest-auth-helpers \
618 --enable-external-acl-helpers \
619 --enable-url-rewrite-helpers \
620 --enable-ntlm-fail-open \
621 --enable-cache-digests \
622 --enable-coss-aio-ops \
623 --enable-delay-pools \
624 --enable-err-language=English \
626 --enable-follow-x-forwarded-for \
627 --enable-forward-log \
628 --enable-forw-via-db \
632 --enable-icap-client \
635 --enable-kill-parent-hack \
636 --enable-large-cache-files \
637 --enable-linux-netfilter \
638 --disable-linux-tproxy \
639 --enable-multicast-miss \
640 --enable-referer-log \
641 --enable-removal-policies="heap,lru" \
642 --enable-storeio="aufs,diskd,rock,ufs" \
646 --enable-useragent-log \
647 --enable-x-accelerator-vary \
648 --localstatedir=/var \
649 --sysconfdir=%{_sysconfdir} \
650 --with-auth-on-acceleration \
659 rm -rf $RPM_BUILD_ROOT
660 install -d $RPM_BUILD_ROOT{%{_cgidir},%{_webapps}/%{_webapp}} \
661 $RPM_BUILD_ROOT/etc/{pam.d,rc.d/init.d,security,sysconfig,logrotate.d} \
662 $RPM_BUILD_ROOT{%{_sbindir},%{_bindir},%{_libexecdir}/contrib} \
663 $RPM_BUILD_ROOT%{_mandir}/man8 \
664 $RPM_BUILD_ROOT%{_datadir}/squid \
665 $RPM_BUILD_ROOT/var/{cache,log{,/archive}}/squid \
666 $RPM_BUILD_ROOT%{systemdtmpfilesdir}
669 DESTDIR=$RPM_BUILD_ROOT
671 %{__cp} -a contrib/*.pl $RPM_BUILD_ROOT%{_libexecdir}/contrib
672 install scripts/*.pl $RPM_BUILD_ROOT%{_libexecdir}
674 install %{SOURCE6} $RPM_BUILD_ROOT/etc/pam.d/squid
675 touch $RPM_BUILD_ROOT/etc/security/blacklist.squid
677 install %{SOURCE8} $RPM_BUILD_ROOT%{systemdtmpfilesdir}/squid.conf
679 %{__mv} -f $RPM_BUILD_ROOT%{_libdir}/squid/cachemgr.cgi $RPM_BUILD_ROOT%{_cgidir}
680 %{__cp} -a %{SOURCE7} $RPM_BUILD_ROOT%{_webapps}/%{_webapp}/apache.conf
681 %{__cp} -a %{SOURCE7} $RPM_BUILD_ROOT%{_webapps}/%{_webapp}/httpd.conf
682 %{__rm} $RPM_BUILD_ROOT%{_webapps}/%{_webapp}/cachemgr.conf.default
684 cd $RPM_BUILD_ROOT/etc/squid
685 %{__patch} -p0 < %{SOURCE4}
686 %{__rm} *.default squid.conf.documented
689 install %{SOURCE1} $RPM_BUILD_ROOT/etc/rc.d/init.d/squid
690 install %{SOURCE2} $RPM_BUILD_ROOT/etc/sysconfig/squid
691 install %{SOURCE5} $RPM_BUILD_ROOT/etc/logrotate.d/squid
693 touch $RPM_BUILD_ROOT/var/log/squid/{access,cache,store}.log
695 %{__rm} $RPM_BUILD_ROOT%{_datadir}/squid/errors/{COPYRIGHT,TRANSLATORS}
697 # cp, to have re-entrant install
700 # We don't want Makefiles as docs...
701 %{__rm} docs/Makefile*
703 :> $RPM_BUILD_ROOT/var/cache/squid/netdb_state
704 :> $RPM_BUILD_ROOT/var/cache/squid/swap.state
705 :> $RPM_BUILD_ROOT/var/cache/squid/swap.state.clean
706 :> $RPM_BUILD_ROOT/var/cache/squid/swap.state.last-clean
709 rm -rf $RPM_BUILD_ROOT
712 %groupadd -g 91 squid
713 %useradd -o -u 91 -s /bin/false -g squid -c "SQUID http caching daemon" -d /var/cache/squid squid
714 %addusertogroup stats squid
716 [ -L %{_datadir}/squid/errors ] && rm -f %{_datadir}/squid/errors || :
719 if ! grep -q "^visible_hostname" /etc/squid/squid.conf; then
720 hostname=`/bin/hostname -f 2>/dev/null` || hostname='localhost'
721 echo visible_hostname $hostname >> /etc/squid/squid.conf
724 /sbin/chkconfig --add squid
725 if [ "$1" = "1" ]; then
726 /sbin/service squid init >&2
728 %service squid restart
731 if [ "$1" = "0" ]; then
732 /sbin/chkconfig --del squid
735 # nuke squid cache if uninstalling
736 rm -rf /var/cache/squid/??
740 if [ "$1" = "0" ]; then
745 %triggerpostun -- squid < 7:2.5.STABLE7-5
746 %addusertogroup stats squid
748 %triggerin cachemgr -- apache1 < 1.3.37-3, apache1-base
749 %webapp_register apache %{_webapp}
751 %triggerun cachemgr -- apache1 < 1.3.37-3, apache1-base
752 %webapp_unregister apache %{_webapp}
754 %triggerin cachemgr -- apache < 2.2.0, apache-base
755 %webapp_register httpd %{_webapp}
757 %triggerun cachemgr -- apache < 2.2.0, apache-base
758 %webapp_unregister httpd %{_webapp}
760 %triggerpostun -- cachemgr < 7:3.0.STABLE10-0.2
761 if [ -f %{_sysconfdir}/cachemgr.conf.rpmsave ]; then
762 cp -f %{_webapps}/%{_webapp}/cachemgr.conf{,.rpmsave}
763 mv -f %{_sysconfdir}/cachemgr.conf.rpmsave %{_webapps}/%{_webapp}/cachemgr.conf
767 %defattr(644,root,root,755)
768 %doc CONTRIBUTORS COPYRIGHT CREDITS README ChangeLog QUICKSTART
769 %doc RELEASENOTES.html SPONSORS docs/* src/mib.txt book-full.html
770 %doc src/squid.conf.default src/squid.conf.documented src/mime.conf.default
771 %doc errors/TRANSLATORS
772 %attr(755,root,root) %{_bindir}/purge
773 %attr(755,root,root) %{_bindir}/squidclient
776 %attr(755,root,root) %{_libexecdir}/diskd
777 # YES, it has to be suid root, it sends ICMP packets.
778 %attr(4754,root,squid) %{_libexecdir}/pinger
779 %attr(755,root,root) %{_libexecdir}/unlinkd
780 %attr(755,root,root) %{_libexecdir}/ntlm_fake_auth
781 %attr(755,root,root) %{_libexecdir}/basic_fake_auth
782 %attr(755,root,root) %{_libexecdir}/url_fake_rewrite
783 %attr(755,root,root) %{_libexecdir}/url_fake_rewrite.sh
784 %attr(755,root,root) %{_libexecdir}/log_file_daemon
785 %attr(755,root,root) %{_sbindir}/squid
787 %attr(754,root,root) /etc/rc.d/init.d/squid
788 %attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) /etc/logrotate.d/squid
789 %attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) /etc/sysconfig/squid
792 %attr(640,root,squid) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/squid.conf
793 %attr(640,root,squid) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/mime.conf
794 %attr(640,root,squid) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/errorpage.css
796 %dir %{_datadir}/squid
797 %dir %{_datadir}/squid/errors
798 %{_datadir}/squid/icons
799 %{_datadir}/squid/mib.txt
800 %{_datadir}/squid/errors/templates
801 %lang(af) %{_datadir}/squid/errors/af
802 %lang(ar) %{_datadir}/squid/errors/ar
803 %lang(ar) %{_datadir}/squid/errors/ar-*
804 %lang(az) %{_datadir}/squid/errors/az
805 %lang(az) %{_datadir}/squid/errors/az-*
806 %lang(bg) %{_datadir}/squid/errors/bg
807 %lang(bg) %{_datadir}/squid/errors/bg-*
808 %lang(ca) %{_datadir}/squid/errors/ca
809 %lang(cs) %{_datadir}/squid/errors/cs
810 %lang(cs) %{_datadir}/squid/errors/cs-*
811 %lang(da) %{_datadir}/squid/errors/da
812 %lang(da) %{_datadir}/squid/errors/da-*
813 %lang(de) %{_datadir}/squid/errors/de
814 %lang(de) %{_datadir}/squid/errors/de-*
815 %lang(el) %{_datadir}/squid/errors/el
816 %lang(el) %{_datadir}/squid/errors/el-*
817 %{_datadir}/squid/errors/en
818 %{_datadir}/squid/errors/en-*
819 %lang(es) %{_datadir}/squid/errors/es
820 %lang(es) %{_datadir}/squid/errors/es-*
821 %lang(et) %{_datadir}/squid/errors/et
822 %lang(et) %{_datadir}/squid/errors/et-*
823 %lang(fa) %{_datadir}/squid/errors/fa
824 %lang(fa) %{_datadir}/squid/errors/fa-*
825 %lang(fi) %{_datadir}/squid/errors/fi
826 %lang(fi) %{_datadir}/squid/errors/fi-*
827 %lang(fr) %{_datadir}/squid/errors/fr
828 %lang(fr) %{_datadir}/squid/errors/fr-*
829 %lang(he) %{_datadir}/squid/errors/he
830 %lang(he) %{_datadir}/squid/errors/he-*
831 %lang(hu) %{_datadir}/squid/errors/hu
832 %lang(hu) %{_datadir}/squid/errors/hu-*
833 %lang(hy) %{_datadir}/squid/errors/hy
834 %lang(hy) %{_datadir}/squid/errors/hy-*
835 %lang(id) %{_datadir}/squid/errors/id
836 %lang(id) %{_datadir}/squid/errors/id-*
837 %lang(it) %{_datadir}/squid/errors/it
838 %lang(it) %{_datadir}/squid/errors/it-*
839 %lang(ja) %{_datadir}/squid/errors/ja
840 %lang(ja) %{_datadir}/squid/errors/ja-*
841 %lang(ko) %{_datadir}/squid/errors/ko
842 %lang(ko) %{_datadir}/squid/errors/ko-*
843 %lang(lt) %{_datadir}/squid/errors/lt
844 %lang(lt) %{_datadir}/squid/errors/lt-*
845 %lang(lv) %{_datadir}/squid/errors/lv
846 %lang(lv) %{_datadir}/squid/errors/lv-*
847 %lang(ms) %{_datadir}/squid/errors/ms
848 %lang(ms) %{_datadir}/squid/errors/ms-*
849 %lang(nl) %{_datadir}/squid/errors/nl
850 %lang(nl) %{_datadir}/squid/errors/nl-*
851 %lang(oc) %{_datadir}/squid/errors/oc
852 %lang(pl) %{_datadir}/squid/errors/pl
853 %lang(pl) %{_datadir}/squid/errors/pl-*
854 %lang(pt) %{_datadir}/squid/errors/pt
855 %lang(pt) %{_datadir}/squid/errors/pt-pt
856 %lang(pt_BR) %{_datadir}/squid/errors/pt-br
857 %lang(ro) %{_datadir}/squid/errors/ro
858 %lang(ro) %{_datadir}/squid/errors/ro-*
859 %lang(ru) %{_datadir}/squid/errors/ru
860 %lang(ru) %{_datadir}/squid/errors/ru-*
861 %lang(sk) %{_datadir}/squid/errors/sk
862 %lang(sk) %{_datadir}/squid/errors/sk-*
863 %lang(sk) %{_datadir}/squid/errors/sl
864 %lang(sk) %{_datadir}/squid/errors/sl-*
865 %lang(sr) %{_datadir}/squid/errors/sr
866 %lang(sr) %{_datadir}/squid/errors/sr-*
867 %lang(sv) %{_datadir}/squid/errors/sv
868 %lang(sv) %{_datadir}/squid/errors/sv-*
869 %lang(th) %{_datadir}/squid/errors/th
870 %lang(th) %{_datadir}/squid/errors/th-*
871 %lang(tr) %{_datadir}/squid/errors/tr
872 %lang(tr) %{_datadir}/squid/errors/tr-*
873 %lang(uk) %{_datadir}/squid/errors/uk
874 %lang(uk) %{_datadir}/squid/errors/uk-*
875 %lang(uz) %{_datadir}/squid/errors/uz
876 %lang(vi) %{_datadir}/squid/errors/vi
877 %lang(vi) %{_datadir}/squid/errors/vi-*
878 %lang(zh_CN) %{_datadir}/squid/errors/zh-cn
879 %lang(zh_CN) %{_datadir}/squid/errors/zh-sg
880 %lang(zh_CN) %{_datadir}/squid/errors/zh-tw
881 %lang(zh_TW) %{_datadir}/squid/errors/zh-hk
882 %lang(zh_TW) %{_datadir}/squid/errors/zh-mo
884 %{systemdtmpfilesdir}/squid.conf
885 %attr(770,root,squid) %dir /var/run/squid
887 %attr(770,root,squid) %dir /var/log/archive/squid
888 %attr(770,root,squid) %dir /var/log/squid
889 %attr(660,root,squid) %ghost /var/log/squid/*
891 %attr(770,root,squid) %dir /var/cache/squid
892 %ghost /var/cache/squid/netdb_state
893 %ghost /var/cache/squid/swap.state
894 %ghost /var/cache/squid/swap.state.clean
895 %ghost /var/cache/squid/swap.state.last-clean
896 %{_mandir}/man1/squidclient.1*
897 %{_mandir}/man8/squid.8*
900 %defattr(644,root,root,755)
901 %dir %attr(750,root,http) %{_webapps}/%{_webapp}
902 %attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{_webapps}/%{_webapp}/apache.conf
903 %attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{_webapps}/%{_webapp}/httpd.conf
904 %attr(640,root,http) %config(noreplace) %verify(not md5 mtime size) %{_webapps}/%{_webapp}/cachemgr.conf
906 %attr(755,root,root) %{_cgidir}/cachemgr.cgi
907 %{_mandir}/man8/cachemgr.cgi.8*
910 %defattr(644,root,root,755)
911 %doc helpers/basic_auth/LDAP/README
912 %attr(755,root,root) %{_libexecdir}/basic_ldap_auth
913 %{_mandir}/man8/basic_ldap_auth.*
916 %defattr(644,root,root,755)
917 %config(noreplace) /etc/pam.d/squid
918 %config(noreplace) /etc/security/blacklist.squid
919 # it has to be suid root to access /etc/shadow
920 %attr(4755,root,root) %{_libexecdir}/basic_pam_auth
921 %{_mandir}/man8/basic_pam_auth.8*
924 %defattr(644,root,root,755)
925 %doc helpers/basic_auth/SMB/ChangeLog
926 %attr(755,root,root) %{_libexecdir}/basic_smb_auth*
929 %defattr(644,root,root,755)
930 %doc helpers/basic_auth/MSNT/README*
931 %doc helpers/basic_auth/MSNT-multi-domain/README*
932 %attr(755,root,root) %{_libexecdir}/basic_msnt_auth
933 %attr(755,root,root) %{_libexecdir}/basic_msnt_multi_domain_auth
934 %attr(640,root,squid) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/msntauth.conf
937 %defattr(644,root,root,755)
938 %attr(755,root,root) %{_libexecdir}/basic_nis_auth
941 %defattr(644,root,root,755)
942 %attr(755,root,root) %{_libexecdir}/basic_ncsa_auth
943 %{_mandir}/man8/basic_ncsa_auth.8*
946 %defattr(644,root,root,755)
947 %doc helpers/basic_auth/SASL/basic_sasl_auth.{conf,pam}
948 %attr(755,root,root) %{_libexecdir}/basic_sasl_auth
949 %{_mandir}/man8/basic_sasl_auth.8*
951 %files getpwname_auth
952 %defattr(644,root,root,755)
953 %attr(755,root,root) %{_libexecdir}/basic_getpwnam_auth
954 %{_mandir}/man8/basic_getpwnam_auth.8*
957 %defattr(644,root,root,755)
958 %attr(755,root,root) %{_libexecdir}/digest_file_auth
959 %{_mandir}/man8/digest_file_auth.8*
962 %defattr(644,root,root,755)
963 %doc helpers/negotiate_auth/kerberos/README
964 %attr(755,root,root) %{_libexecdir}/negotiate_kerberos_auth
965 %attr(755,root,root) %{_libexecdir}/negotiate_kerberos_auth_test
966 %{_mandir}/man8/negotiate_kerberos_auth.8*
969 %defattr(644,root,root,755)
970 %attr(755,root,root) %{_libexecdir}/ntlm_smb_lm_auth
973 %defattr(644,root,root,755)
974 %doc helpers/basic_auth/RADIUS/README
975 %attr(755,root,root) %{_libexecdir}/basic_radius_auth
976 %{_mandir}/man8/basic_radius_auth.8*
978 %files digest_ldap_auth
979 %defattr(644,root,root,755)
980 %attr(755,root,root) %{_libexecdir}/digest_ldap_auth
983 %defattr(644,root,root,755)
984 %attr(755,root,root) %{_libexecdir}/basic_db_auth
985 %{_mandir}/man8/basic_db_auth.8*
988 %defattr(644,root,root,755)
989 %{_libexecdir}/basic_pop3_auth
991 %files digest_edirectory_auth
992 %defattr(644,root,root,755)
993 %{_libexecdir}/digest_edirectory_auth
995 %files negotiate_wrapper_auth
996 %defattr(644,root,root,755)
997 %{_libexecdir}/negotiate_wrapper_auth
1000 %defattr(644,root,root,755)
1001 %doc helpers/external_acl/file_userip/example*
1002 %attr(755,root,root) %{_libexecdir}/ext_file_userip_acl
1003 %{_mandir}/man8/ext_file_userip_acl.*
1006 %defattr(644,root,root,755)
1007 %attr(755,root,root) %{_libexecdir}/ext_ldap_group_acl
1008 %{_mandir}/man8/ext_ldap_group_acl.*
1011 %defattr(644,root,root,755)
1012 %attr(755,root,root) %{_libexecdir}/ext_unix_group_acl
1013 %{_mandir}/man8/ext_unix_group_acl.*
1016 %defattr(644,root,root,755)
1017 %attr(755,root,root) %{_libexecdir}/ext_wbinfo_group_acl
1018 %{_mandir}/man8/ext_wbinfo_group_acl.8*
1021 %defattr(644,root,root,755)
1022 %attr(755,root,root) %{_libexecdir}/ext_session_acl
1023 %{_mandir}/man8/ext_session_acl.8*
1025 %files edirectory_userip_acl
1026 %defattr(644,root,root,755)
1027 %{_libexecdir}/ext_edirectory_userip_acl
1028 %{_mandir}/man8/ext_edirectory_userip_acl.8*
1030 %files kerberos_ldap_group_acl
1031 %defattr(644,root,root,755)
1032 %{_libexecdir}/ext_kerberos_ldap_group_acl
1035 %defattr(644,root,root,755)
1036 %attr(755,root,root) %{_libexecdir}/contrib
1037 %attr(755,root,root) %{_libexecdir}/AnnounceCache.pl
1038 %attr(755,root,root) %{_libexecdir}/access-log-matrix.pl
1039 %attr(755,root,root) %{_libexecdir}/cache-compare.pl
1040 %attr(755,root,root) %{_libexecdir}/cachetrace.pl
1041 %attr(755,root,root) %{_libexecdir}/calc-must-ids.pl
1042 %attr(755,root,root) %{_libexecdir}/cert_tool
1043 %attr(755,root,root) %{_libexecdir}/check_cache.pl
1044 %attr(755,root,root) %{_libexecdir}/fileno-to-pathname.pl
1045 %attr(755,root,root) %{_libexecdir}/find-alive.pl
1046 %attr(755,root,root) %{_libexecdir}/flag_truncs.pl
1047 %attr(755,root,root) %{_libexecdir}/helper-mux.pl
1048 %attr(755,root,root) %{_libexecdir}/icpserver.pl
1049 %attr(755,root,root) %{_libexecdir}/icp-test.pl
1050 %attr(755,root,root) %{_libexecdir}/tcp-banger.pl
1051 %attr(755,root,root) %{_libexecdir}/trace-job.pl
1052 %attr(755,root,root) %{_libexecdir}/trace-master.pl
1053 %attr(755,root,root) %{_libexecdir}/udp-banger.pl
1054 %attr(755,root,root) %{_libexecdir}/upgrade-1.0-store.pl