Bug 46586
Summary: | problems in current bind named.conf, rndc.conf | ||
---|---|---|---|
Product: | [Retired] Red Hat Raw Hide | Reporter: | Jonathan Kamens <jik> |
Component: | caching-nameserver | Assignee: | Florian La Roche <laroche> |
Status: | CLOSED RAWHIDE | QA Contact: | David Lawrence <dkl> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 1.0 | CC: | rh-bugzilla |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | i386 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2001-07-03 20:48:38 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Jonathan Kamens
2001-06-29 12:40:10 UTC
I would not protect named.conf with mode 0600 but include protected key-files. E.g: --- /etc/bind.conf --- ... include "/etc/rndc.key"; ... ---- /etc/rndc.key (mode 0640, root.named)--- key "key" { algorithm hmac-md5; ... } It is a little bit pity that rndc.conf is not understanding the `include' syntax. Else the redundant key there could be removed also. Making the files owned by named is not a good idea because user named (possibly gained by an attack) can modify them else. Mode 0640 and owner `root.named' for the files containing keys should be a good choice. rndc.conf is fixed and rndc.key is created in bind-9.1.3-0.rc2.3. Moving to caching-nameserver for named.conf Fixed in caching-nameserver-7.2-1 |