Re: [systemd-devel] Securing bind with systemd methods (was: bind-mount of /run/systemd for chrooted bind9/named)

2023-07-17 Thread Mantas Mikulėnas
On Mon, Jul 17, 2023, 15:44 Marc Haber wrote: > > # /lib is necessary here, or execve will fail without indication for > # reason - that was a surprise and hard to debug because even strace > # didnt hint me towards the real issue > ExecPaths=/usr/sbin/named /usr/sbin/rndc /lib > This one in

[systemd-devel] Securing bind with systemd methods (was: bind-mount of /run/systemd for chrooted bind9/named)

2023-07-17 Thread Marc Haber
Hi, I'm back. This is my first try at doing a decent systemd unit for bind 9 / named chrooted with named's own features, making the chroot minimal and code-free. Here we go (this has been merged from various plug-in/overrides files, I don't guarantee correct syntax). I have interspersed my

Re: [systemd-devel] IPv6AcceptRA: RDNSS Lifetime is not expiring

2023-07-17 Thread Petr Menšík
I would suggest creating issue at github.com/systemd/systemd repository. I have not tested it, but sounds like it should be fixed. On 12. 07. 23 0:39, Muggeridge, Matt wrote: Hello there! In our IPv6 network, the address of a Recursive DNS Server (RDNSS) is supplied in a Router