Re: [CentOS] Vulnerabilities to bind-libs bind-utils - possible to remove these on webservers

2019-06-24 Thread Peda, Allan (NYC-GIS)
I just tried out removal of bind-utils on a soon to be retired machine. It seems fine with the caveat that we lose /bin/host and /bin/dig Perhaps a perl script might suffice to emulate 'host' on machines that might need the occasional networking debug session. Just typed this up, so FWIW:

Re: [CentOS] Vulnerabilities to bind-libs bind-utils - possible to remove these on webservers

2019-06-24 Thread mark
Peda, Allan (NYC-GIS) wrote: > I think the subject says it all. We don't run named. It seems there are > chronic issues with bind. Can these packages be removed? > > We locally authenticate. I see this: > > Removing for dependencies: > bind-utils ipa-client sssd sssd-ad sssd-ipa > > We

Re: [CentOS] Vulnerabilities to bind-libs bind-utils - possible to remove these on webservers

2019-06-24 Thread Mauricio Tavares
On Mon, Jun 24, 2019 at 9:07 AM Peda, Allan (NYC-GIS) wrote: > > I think the subject says it all. We don't run named. It seems there are > chronic issues with bind. Can these packages be removed? > > We locally authenticate. I see this: > > Removing for dependencies: > bind-utils >

[CentOS] Vulnerabilities to bind-libs bind-utils - possible to remove these on webservers

2019-06-24 Thread Peda, Allan (NYC-GIS)
I think the subject says it all. We don't run named. It seems there are chronic issues with bind. Can these packages be removed? We locally authenticate. I see this: Removing for dependencies: bind-utils ipa-client sssd sssd-ad sssd-ipa We shouldn't need any of that with local