Date: Mon, 4 Oct 2004 22:17:03 -0400 From: Garance A Drosehn <gad@FreeBSD.org> To: Doug Barton <DougB@FreeBSD.org> Cc: freebsd-current@FreeBSD.org Subject: Re: New BIND 9 chroot directories Message-ID: <p06110406bd87b32f23d7@[128.113.24.47]> In-Reply-To: <20041004181933.H96420@bo.vpnaa.bet> References: <4160259A.3070708@FreeBSD.org> <200410041734.53316.freebsd@redesjm.local> <200410042343.19211.freebsd@redesjm.local> <20041004181933.H96420@bo.vpnaa.bet>
next in thread | previous in thread | raw e-mail | index | archive | help
At 6:25 PM -0700 10/4/04, Doug Barton wrote: >On Mon, 4 Oct 2004, Jose M Rodriguez wrote: > >>El Lunes, 4 de Octubre de 2004 22:10, Doug Barton escribi=F3: > >>Really good work. But, this is really needed? >>I can't see why. > >Because running bind chrooted is considerably safer, and >the defaults should be as safe as possible unless it is an >inconvenience to the majority of our users. =46wiw, I do believe it is better to have the chrooted setup by default. We're already making a significant change in going from bind8 to bind9, so anyone running bind is going to have to check over their machines anyway. No one running bind is going to be able to "blindly update" to 5.3-release. We might as well go with the safer configuration by default, because I would rather do it now than wait for 6.0-release. After all, if this change is "too scary" to do for the first release to be called 5.x-STABLE, then it must be too scary to do for later releases in that STABLE branch. Just my 2 cents. -- Garance Alistair Drosehn =3D gad@gilead.netel.rpi.edu Senior Systems Programmer or gad@FreeBSD.org Rensselaer Polytechnic Institute; Troy, NY; USA
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?p06110406bd87b32f23d7>