Re: Wrong ownership of /var/named/master ?

2008-06-16 Thread Andreas Maus
On Sun, Jun 15, 2008 at 09:15:41PM +0200, Dorian B|ttner wrote: propably the file you gave named in the zone-section of named.conf needs to be existing in the first place. give named sufficient permission to read and, for dynamic update, to write in it - no bug here and no need to change

Re: Wrong ownership of /var/named/master ?

2008-06-16 Thread Jamie Gavahan
On Sun, Jun 15, 2008 at 1:42 PM, Andreas Maus [EMAIL PROTECTED] wrote: Hi. While configuring named on my sweet new Soekris 5501 I discovered a little *uhm* misconfiguration (I would not call it a bug). By default the permissions of /var/named/master is set to 0755 and owned by root:wheel.

Re: Wrong ownership of /var/named/master ?

2008-06-16 Thread Andreas Maus
On Mon, Jun 16, 2008 at 03:06:46AM -0500, Jamie Gavahan wrote: Hello, Hi. A quick search of the archives yielded these results* (among others): Someone correct me if I'm wrong. You are wrong :P named supports dynamic updates via allow-update { key ...; }; But the _DHCP_ server does not

Re: Wrong ownership of /var/named/master ?

2008-06-16 Thread Jussi Peltola
On Sun, Jun 15, 2008 at 08:42:38PM +0200, Andreas Maus wrote: Hi. While configuring named on my sweet new Soekris 5501 I discovered a little *uhm* misconfiguration (I would not call it a bug). By default the permissions of /var/named/master is set to 0755 and owned by root:wheel. named

Re: Wrong ownership of /var/named/master ?

2008-06-16 Thread Andreas Maus
On Mon, Jun 16, 2008 at 09:32:39AM +, Jussi Peltola wrote: Hi. It's reasonable to me: named doesn't need to modify master zones, so don't let it do that. Principle of the least privilege. Using static zones ... I totally agree. Simpler fix: put dynamically updated zones in slave, which I

Wrong ownership of /var/named/master ?

2008-06-15 Thread Andreas Maus
Hi. While configuring named on my sweet new Soekris 5501 I discovered a little *uhm* misconfiguration (I would not call it a bug). By default the permissions of /var/named/master is set to 0755 and owned by root:wheel. named runs in the chroot /var/named with the user named, group named. For

Re: Wrong ownership of /var/named/master ?

2008-06-15 Thread Dorian Büttner
Andreas Maus schrieb: Hi. While configuring named on my sweet new Soekris 5501 I discovered a little *uhm* misconfiguration (I would not call it a bug). By default the permissions of /var/named/master is set to 0755 and owned by root:wheel. named runs in the chroot /var/named with the user