From owner-cvs-src-old@FreeBSD.ORG Tue Dec 15 05:15:04 2009 Return-Path: Delivered-To: cvs-src-old@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 6280E10657CB for ; Tue, 15 Dec 2009 05:15:04 +0000 (UTC) (envelope-from dougb@FreeBSD.org) Received: from repoman.freebsd.org (repoman.freebsd.org [IPv6:2001:4f8:fff6::29]) by mx1.freebsd.org (Postfix) with ESMTP id 500348FC08 for ; Tue, 15 Dec 2009 05:15:04 +0000 (UTC) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.14.3/8.14.3) with ESMTP id nBF5F49u031724 for ; Tue, 15 Dec 2009 05:15:04 GMT (envelope-from dougb@repoman.freebsd.org) Received: (from svn2cvs@localhost) by repoman.freebsd.org (8.14.3/8.14.3/Submit) id nBF5F4C7031723 for cvs-src-old@freebsd.org; Tue, 15 Dec 2009 05:15:04 GMT (envelope-from dougb@repoman.freebsd.org) Message-Id: <200912150515.nBF5F4C7031723@repoman.freebsd.org> X-Authentication-Warning: repoman.freebsd.org: svn2cvs set sender to dougb@repoman.freebsd.org using -f From: Doug Barton Date: Tue, 15 Dec 2009 05:14:39 +0000 (UTC) To: cvs-src-old@freebsd.org X-FreeBSD-CVS-Branch: HEAD Subject: cvs commit: src/etc/mtree BIND.chroot.dist src/etc/namedb named.conf X-BeenThere: cvs-src-old@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: **OBSOLETE** CVS commit messages for the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 15 Dec 2009 05:15:04 -0000 dougb 2009-12-15 05:14:39 UTC FreeBSD src repository Modified files: etc/mtree BIND.chroot.dist etc/namedb named.conf Log: SVN rev 200563 on 2009-12-15 05:14:39Z by dougb The named process needs to have a "working directory" that it can write to. This is specified in "options { directory }" in named.conf. So, create /etc/namedb/working with appropriate permissions, and update the entry in named.conf to match. In addition to specifying the working directory, file and path names in named.conf can be specified relative to the directory listed. However, since that directory is now different from /etc/namedb (where the configuration, zone, rndc.*, and other files are located) further update named.conf to specify all file names with fully qualified paths. Also update the comment about file and path names so users know this should be done for all file/path names in the file. This change will eliminate the 'working directory is not writable' messages at boot time without sacrificing security. It will also allow for features in newer versions of BIND (9.7+) to work as designed. Revision Changes Path 1.7 +2 -0 src/etc/mtree/BIND.chroot.dist 1.30 +95 -95 src/etc/namedb/named.conf