Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 4 Oct 2004 22:17:03 -0400
From:      Garance A Drosehn <gad@FreeBSD.org>
To:        Doug Barton <DougB@FreeBSD.org>
Cc:        freebsd-current@FreeBSD.org
Subject:   Re: New BIND 9 chroot directories
Message-ID:  <p06110406bd87b32f23d7@[128.113.24.47]>
In-Reply-To: <20041004181933.H96420@bo.vpnaa.bet>
References:  <4160259A.3070708@FreeBSD.org> <200410041734.53316.freebsd@redesjm.local> <200410042343.19211.freebsd@redesjm.local> <20041004181933.H96420@bo.vpnaa.bet>

next in thread | previous in thread | raw e-mail | index | archive | help
At 6:25 PM -0700 10/4/04, Doug Barton wrote:
>On Mon, 4 Oct 2004, Jose M Rodriguez wrote:
>
>>El Lunes, 4 de Octubre de 2004 22:10, Doug Barton escribi=F3:
>
>>Really good work.  But, this is really needed?
>>I can't see why.
>
>Because running bind chrooted is considerably safer, and
>the defaults should be as safe as possible unless it is an
>inconvenience to the majority of our users.

=46wiw, I do believe it is better to have the chrooted setup
by default.  We're already making a significant change in
going from bind8 to bind9, so anyone running bind is going
to have to check over their machines anyway.  No one running
bind is going to be able to "blindly update" to 5.3-release.

We might as well go with the safer configuration by default,
because I would rather do it now than wait for 6.0-release.
After all, if this change is "too scary" to do for the first
release to be called 5.x-STABLE, then it must be too scary to
do for later releases in that STABLE branch.

Just my 2 cents.

-- 
Garance Alistair Drosehn     =3D      gad@gilead.netel.rpi.edu
Senior Systems Programmer               or   gad@FreeBSD.org
Rensselaer Polytechnic Institute;             Troy, NY;  USA



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?p06110406bd87b32f23d7>