From owner-freebsd-net@FreeBSD.ORG Sun Aug 3 15:20:41 2008 Return-Path: Delivered-To: net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 510C41065686 for ; Sun, 3 Aug 2008 15:20:41 +0000 (UTC) (envelope-from eugen@kuzbass.ru) Received: from www.svzserv.kemerovo.su (www.svzserv.kemerovo.su [213.184.65.80]) by mx1.freebsd.org (Postfix) with ESMTP id A58128FC17 for ; Sun, 3 Aug 2008 15:20:40 +0000 (UTC) (envelope-from eugen@kuzbass.ru) Received: from www.svzserv.kemerovo.su (eugen@localhost [127.0.0.1]) by www.svzserv.kemerovo.su (8.13.8/8.13.8) with ESMTP id m73ElKYa034411; Sun, 3 Aug 2008 22:47:20 +0800 (KRAST) (envelope-from eugen@www.svzserv.kemerovo.su) Received: (from eugen@localhost) by www.svzserv.kemerovo.su (8.13.8/8.13.8/Submit) id m73ElJi7034409; Sun, 3 Aug 2008 22:47:19 +0800 (KRAST) (envelope-from eugen) Date: Sun, 3 Aug 2008 22:47:19 +0800 From: Eugene Grosbein To: Ian Smith Message-ID: <20080803144719.GA33577@svzserv.kemerovo.su> References: <20080803073803.GA10321@grosbein.pp.ru> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.4.2.3i Cc: net@freebsd.org Subject: Re: permissions on /etc/namedb X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 03 Aug 2008 15:20:41 -0000 On Sun, Aug 03, 2008 at 10:32:22PM +1000, Ian Smith wrote: > > I need /etc/namedb to be owned by root:bind and have permissions 01775, > > so bind may write to it but may not overwrite files that belong to root > > here, and I made it so. Suprise! > > > > # /etc/rc.d/named restart > > Stopping named. > > Waiting for PIDS: 1892. > > etc/namedb changed > > gid expected 0 found 53 modified > > permissions expected 0755 found 01775 modified > > Starting named. > > Are you running /etc/namedb linked to chroot'd /var/named/etc/namedb? > If so, that'd be mtree restoring perms from /etc/mtree/BIND.chroot.dist I just have 'named_enable="YES"' in /etc/rc.conf, it's 6.3-STABLE and stock bind9. I could set named_chroot_autoupdate="NO", but I see now it won't mount devfs into chroot are in that case. Eugene Grosbein