Proxy Auto-config

There comes a need for many organizations (or individuals) to establish proxy servers on their network. This is usually done for reasons of security or network topology. While the use of proxy servers simpifies some aspects of networking, it comes at the cost of maintaining the browser configuration of every network device (usually browsers). Netscape provided a mechanism to automate much of this problem by allowing the browser to retrieve the proxy configuration from a centrally managed server.

The proxy autoconfig file is written in JavaScript, it should be a separate file that has the proper filename extension and MIME type when provided from a webserver.

The file must define the function:

function FindProxyForURL(url, host)




4. ApacheHTTP config.

Add the following to the httpd.conf file:

Redirect permanent /wpad.dat {yourdomain}/proxy.pac
AddType application/x-ns-proxy-autoconfig .pac


/* 'proxy.pac' - This is the main function called by any browser */
function FindProxyForURL(url, host)

if (isPlainHostName(host) || // No Proxy for Non FQDN names
shExpMatch(host, “*.localnet”) || // No Proxy for internal network
shExpMatch(host, “”) || // No Proxy for LocalHost
shExpMatch(host, “localhost”) || // No Proxy for LocalHost
shExpMatch(host, “mailhost”) || // No Proxy for MailHost
dnsDomainIs(host, “”) || // No Proxy
return “DIRECT”;

else {

} //End else

} // End function FindProxyForUrl

NOTE: Also see my ‘WPAD’ blog entry.

JavaScript (intro)

JavaScript is one of the foundations of the internet as we currently know it, but is often misunderstood. It is the “J” in AJAX (to be discussed elsewhere), and is typically used for creation of interactive browser applications with client-side (browser) functionalities such as FORM validation and manipulation of onscreen elements via the DOM (to be discussed elsewhere).

JavaScript is more appropriately called ECMAScript, as it is a ‘Standard’ from the ECMA organization. Early incarnations of this specification were called LiveScript (by Netscape). Microsoft, in typical form, created a VisualBASIC like version that they called JScript, though while mostly compatible, has some proprietary differences.

It’s always preferred to add this to your HEAD section (or the equivalent in HTTP Headers):

<meta http-equiv=”Content-Script-Type” content=”text/javascript” />

To include external files containing JavaScript:

<script type=”text/javascript” src=”/filename.js”></script>

To include XHTML compliant blocks of JavaScript in your page:

<script type=”text/javascript”>
<!– <![CDATA[

//]]> — >

DO NOT use the deprecated ‘language’ attribute:

<script language=”JavaScript”>


P3P 1.0 Implementation guide

Standards documentation is available from W3C at:


  1. Version P3P 1.1 is currently in the works.
  2. Throughout the specifications you’ll see references to “Well-Known Location”, this refers to the default path and naming of these files in the /w3c/ folder.
  3. In my examples below, I have left MOST data empty, the “

xxx” indicates a field that must match between these files.

<link type="text/xml" rel="P3Pv1" href="/w3c/p3p.xml" />

HTTP Header:

p3p: policyref="/w3c/p3p.xml", CP="TST"


<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<META xmlns="">
<POLICY-REF about="/w3c/privacy.xml#xxx">
<COOKIE-INCLUDE name="*" value="*" domain="*" path="*" />


<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<POLICIES xmlns="">
<POLICY name="xxx" discuri="/index.html" xml:lang="en">
<DATA ref=""></DATA>
<DATA ref="#business.department"></DATA>
<DATA ref=""></DATA>
<DATA ref=""></DATA>
<DATA ref=""></DATA>
<DATA ref=""></DATA>
<DATA ref=""></DATA>
<DATA ref=""></DATA>
<DATA ref=""></DATA>
<DATA ref=""></DATA>
<DATA ref=""></DATA>
<DATA ref=""></DATA>
<DATA ref=""></DATA>
<DISPUTES resolution-type="service" service="/index.html" short-description="Customer Service">
<CONSEQUENCE>We record some information in order to serve your request and to secure and improve our Web site.</CONSEQUENCE>
<DATA ref="#dynamic.clickstream"/>
<DATA ref="#dynamic.http"/>

