Univention Bugzilla – Bug 37837
Document DHCP option wpad
Last modified: 2017-10-16 21:35:41 CEST
Right now there is only a vague sentence regarding that proxy settings are distributed via DHCP by default: http://docs.univention.de/ucsschool-handbuch-4.0.html#school:proxy > Die Proxykonfiguration wird in der Grundeinstellung durch DHCP verteilt, diese Einstellung wird jedoch nicht von allen Browsern unterstützt. There is no documentation on how this is done (wpad) nor how to turn it off. In a current case (Ticket#2014112021000242) this feature lead to strange behaviour when accessing a local windows webserver. Disabling: > udm dhcp/service modify --dn cn=<hostname>,cn=dhcp,ou=<schoolname>,<ldap-base> --set option='' > ucr unset dhcpd/options/wpad/252 > /etc/init.d/univention-dhcp restart Enabling again: > udm dhcp/service modify --dn cn=<hostname>,cn=dhcp,ou=<schoolname>,<ldap-base> --append option='wpad "http://<FQDN-of-schoolserver>/proxy.pac";' > ucr set dhcpd/options/wpad/252=text > /etc/init.d/univention-dhcp restart
WPAD is a security disaster and should not be used: <https://www.us-cert.gov/ncas/alerts/TA16-144A>
(In reply to Philipp Hahn from comment #1) > WPAD is a security disaster and should not be used: I second that.
(In reply to Sönke Schwardt-Krummrich from comment #2) > (In reply to Philipp Hahn from comment #1) > > WPAD is a security disaster and should not be used: > > I second that. I don't want to argue with you, but with Bug #31728 we now also provide a wpad.dat next to the proxy.pac, so imho this should really be documented somewhere. Not documenting it doesn't make it any less a security problem. I regularly have to support customers in turning this off, because of different scenarios where clients need to access a web service on the same subnet without proxy authentication. The most common is a local Windows Updates Repository (Windows Server Update Services , WSUS).
Documentation should include information about UCRVs proxy/pac/exclude/*
3e90381f: document DHCP option wpad 8ce291ee: fix spelling 97a76be (doc-common): add abbreviations http://jenkins.knut.univention.de:8080/job/UCSschool%204.2/job/Manual/3/artifact/webroot/ucsschool-handbuch-4.2.html#school:proxy
Did some additions: doc-common: 86e95304e120 | Bug #37837: add new entries to dictionary manual: 1cb7700d5e66 | Bug #37837: Merge branch 'sschwardt/37837/42/wpad-manual' into 4.2 4b9002d87d41 | Bug #37837: add line break in example code / fixed typos
UCS@school 4.2 v4 has been released. http://docs.software-univention.de/changelog-ucsschool-4.2v4-de.html If this error occurs again, please clone this bug.