Re: chroot and BIND

From: Devin L. Ganger (devin@thecabal.org)
Date: 10/26/01


Date: Fri, 26 Oct 2001 05:15:19 -0700
From: "Devin L. Ganger" <devin@thecabal.org>
To: focus-sun@securityfocus.com
Subject: Re: chroot and BIND
Message-ID: <20011026051519.A2329@thecabal.org>

On Tue, Oct 23, 2001 at 05:45:42PM -0700, Joseph Tam wrote:
 
> 5) Is there a reason to prefer one method over another? If not, method 1
> is by far the easiest and the one I would implement, all other things being
> equal.

Also, why not just use a read-only lofs mount as your jail, with a writeable
filesystem mounted at the jail's /var/named (or wherever) to handle the
files named expects to write?

Combined with a nice configuration to run named as a non-root user on a
high port, and something like http://www.taronga.com/plugdaemon/ to
provide the access to port 53, and it seems you'd have a nice, simple, easy-to-
maintain (well, as easy to maintain as BIND gets) named setup.

-- 
Devin L. Ganger <devin@thecabal.org>
A man, a miss, a car -- a curve,
He kissed the miss and missed the curve -- Burma Shave (1948)



Relevant Pages

  • Re: How to get acces to tcp portnumbers below 1024?
    ... ability to bind to reserved ports. ... As far as being special for a reason, that reason went away the first time ... He can bind to the ports in question either by ... man 7 IP for which capability needs to be set. ...
    (alt.os.linux.suse)
  • 10/17 MSG setlist - complete
    ... The Ties That Bind ... Gypsy Biker ... Reason To Believe ... Adam Raised A Cain ...
    (rec.music.artists.springsteen)
  • Re: Thread safety of DataTable class - Filling on background thread OK?
    ... That bind to the grid ... clause for a reason:). ... that's why I meant - disconnecting datasource - that will always work. ... BindingSource.DataSource to null or typeof(MyDataSetType) I got ...
    (microsoft.public.dotnet.framework.adonet)
  • Re: [9fans] read/write offset hack
    ... depend on that convention (bind /net/tcp /proc; ... scripts and interactive shell sessions. ... Posts like these are the reason I follow this list, even though I do not have Plan9 installed! ...
    (comp.os.plan9)
  • Firewalling NFS
    ... The reason is that NFS related daemons use RPC, ... don't bind to a deterministic port. ... bind to a specific port or fail with the -p command-line switch. ... Is there any reason other than "no one has needed this yet" why this ...
    (freebsd-net)