From owner-freebsd-net@FreeBSD.ORG Mon Aug 4 18:50:16 2008 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 594C71065670 for ; Mon, 4 Aug 2008 18:50:16 +0000 (UTC) (envelope-from dougb@FreeBSD.org) Received: from mail2.fluidhosting.com (mx23.fluidhosting.com [204.14.89.6]) by mx1.freebsd.org (Postfix) with ESMTP id AF8768FC0C for ; Mon, 4 Aug 2008 18:50:15 +0000 (UTC) (envelope-from dougb@FreeBSD.org) Received: (qmail 4383 invoked by uid 399); 4 Aug 2008 18:50:15 -0000 Received: from localhost (HELO lap.dougb.net) (dougb@dougbarton.us@127.0.0.1) by localhost with ESMTPAM; 4 Aug 2008 18:50:15 -0000 X-Originating-IP: 127.0.0.1 X-Sender: dougb@dougbarton.us Message-ID: <48974F65.7050301@FreeBSD.org> Date: Mon, 04 Aug 2008 11:50:13 -0700 From: Doug Barton Organization: http://www.FreeBSD.org/ User-Agent: Thunderbird 2.0.0.16 (X11/20080726) MIME-Version: 1.0 To: Eugene Grosbein References: <20080803073803.GA10321@grosbein.pp.ru> <4895EB57.2000801@FreeBSD.org> <20080803183346.GA53252@svzserv.kemerovo.su> <4896997D.8060001@FreeBSD.org> <20080804060658.GA19639@svzserv.kemerovo.su> <4896A416.80602@FreeBSD.org> <20080804075510.GA28531@svzserv.kemerovo.su> In-Reply-To: <20080804075510.GA28531@svzserv.kemerovo.su> X-Enigmail-Version: 0.95.6 OpenPGP: id=D5B2F0FB Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-net@freebsd.org Subject: Re: permissions on /etc/namedb X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 04 Aug 2008 18:50:16 -0000 Eugene Grosbein wrote: > On Sun, Aug 03, 2008 at 11:39:18PM -0700, Doug Barton wrote: > >>>>>>> I need /etc/namedb to be owned by root:bind and have permissions 01775, Fair enough, I misread that bit. Sorry for the confusion. I will (once again) return to my point that while I do not think what you are proposing is an appropriate default, you have the tools to do what you want to do, so good luck with it. -- This .signature sanitized for your protection