BIND less restrictive modes and policy

Enrico Scholz enrico.scholz at informatik.tu-chemnitz.de
Tue Jan 22 00:18:51 UTC 2008


Adam Tkac <atkac at redhat.com> writes:

> Also complete /var/named/* subtree will be writable by named

This is bad. Only the slaves/ and data/ (for DDNS) dirs must be writable.
pz/ and the other parts of the chroot filesystem must be read-only for
named.


Enrico




More information about the devel mailing list