Re: chroot and BIND

From: Erek Adams (erek@theadamsfamily.net)
Date: 10/24/01


Date: Wed, 24 Oct 2001 10:46:38 -0700 (PDT)
From: Erek Adams <erek@theadamsfamily.net>
To: Joseph Tam <tam@math.ubc.ca>
Subject: Re: chroot and BIND
Message-ID: <Pine.GSO.4.40.0110241040060.18103-100000@lurch.theadamsfamily.net>

On Tue, 23 Oct 2001, Joseph Tam wrote:

> It doesn't appear you actually need /etc/TIMEZONE in your chroot jail as
> it grabs that information from your environment variable.
>
> How, incidentally, are people constructing their chroot jail to run
> bind 9.1.3?

Joseph, nice work on the three versions! That's some handy info to tuck
away... :)

Well, I've not done BIND 9.1.3, but I do chroot a few things. Something that
I managed to run across was a article with scripts by Carole Fennelly at
Sunworld online. Since it seems that Sunworld Online has become 'something
else', I managed to grab a copy and mirror it. IOW, it's not mine, nor am I
responsible for it. :) Use it at your own risk, etc...

        http://www.theadamsfamily.net/~erek/snort/cell

And the tarball of everything it has...

        http://www.theadamsfamily.net/~erek/snort/cell/cell.tar.gz

Hope this is of some use/help to folks!

Cheers!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net



Relevant Pages

  • Re: Ronning named in chroot env
    ... You can keep the number of libs that you need to put in the chroot down by ... If you are using the ports collection to build bind, ... > In case someone is interested in running named in chrooted environment on ... > FreeBSD, below is my experience how this can be done. ...
    (FreeBSD-Security)
  • Re: FreeBSD Security Advisory: FreeBSD-SA-01:18.bind
    ... >:as user flags it would be trivial to have it the defaultt. ... > not be able to rebind its sockets), you can only restart it, and ... I'm not sure how bind handles restarts, but even if it execs over ... A shell script could copy the required shared libs into the chroot ...
    (FreeBSD-Security)
  • Re: Proper way to run bind9
    ... run if there is no chroot. ... I'll commit a fix for this in a second. ... >> file to run the system's version of bind, ...
    (freebsd-current)
  • Re: bind update keeps messing up write-rights
    ... Whenever I update bind it messes up/resets access rights on my ... You must have bind configured to run in chroot. ... Move your updateable zone files there and update the referenced paths in named.conf accordingly. ...
    (Fedora)
  • Re: RHEL 4 AS
    ... > environment (BIND and chroot'd BIND were installed during the OS ... These servers serving DNS without issue. ... Do you have a duplicate key file in the chroot environment? ...
    (linux.redhat)