From owner-freebsd-security@FreeBSD.ORG Mon Jul 9 13:36:42 2012 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 2754B10656EA for ; Mon, 9 Jul 2012 13:36:40 +0000 (UTC) (envelope-from des@des.no) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id CBD598FC18 for ; Mon, 9 Jul 2012 13:36:39 +0000 (UTC) Received: from ds4.des.no (smtp.des.no [194.63.250.102]) by smtp.des.no (Postfix) with ESMTP id D2BD66706; Mon, 9 Jul 2012 13:36:32 +0000 (UTC) Received: by ds4.des.no (Postfix, from userid 1001) id 98BE28768; Mon, 9 Jul 2012 15:36:32 +0200 (CEST) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: Matt Dawson References: <4FF2E00E.2030502@FreeBSD.org> <86bojxow6x.fsf@ds4.des.no> <89AB703D-E075-4AAC-AC1B-B358CC4E4E7F@lists.zabbadoz.net> <4FF8C3A1.9080805@FreeBSD.org> <0AFE3C4A-22DB-4134-949F-4D05BBFC4C6C@lists.zabbadoz.net> <4FF8CA35.7040209@FreeBSD.org> <4FF8D89B.1030308@bluerosetech.com> <4FF95365.7010605@FreeBSD.org> <20473.50867.199081.295841@hergotha.csail.mit.edu> <201207090449.q694nW9C094754@chronos.org.uk> Date: Mon, 09 Jul 2012 15:36:32 +0200 In-Reply-To: <201207090449.q694nW9C094754@chronos.org.uk> (Matt Dawson's message of "Mon, 9 Jul 2012 05:49:32 +0100") Message-ID: <86y5mtm4yn.fsf@ds4.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org Subject: Re: Replacing BIND with unbound X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 09 Jul 2012 13:36:42 -0000 Matt Dawson writes: > TBH, even having the root zone in base is a bit daft. The root zone we ship is a hint used to bootstrap named. Without it, named is a brick, unless all you want is an authoritative-only nameserver. All named does with that hint file is use it to locate a root server from which it can obtain a fresh copy of the root zone. Feel free to replace it with a fresh copy from InterNIC. Since the root zone is signed, you could even set up a cron job to do automatically update the hint file at regular intervals. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no