Re: configure bind in chroot jail

stuart--- via bind-users <[email protected]>
Newsgroups gmane.network.dns.bind9.user
Message-ID <6E3958DD-0D88-4616-A02C-7EA0287DF07F__39742.4506883667$1754523380$gmane$org@registry.godaddy>
> From: bind-users <[email protected]> on behalf of Greg Choules via bind-users <[email protected]>
> Reply to: Greg Choules <[email protected]>
> Date: Wednesday 6 August 2025 at 20:06
> To: Renzo Marengo <[email protected]>
> Cc: "[email protected]" <[email protected]>
> Subject: Re: configure bind in chroot jailenzo. The Linux distros package their own versions of BIND, which they obtain from ISC and patch over the years, hence it is almost guaranteed to not be the latest. That may be OK for you. But see here for how to install it directly if you
> ZjQcmQRYFpfptBannerEnd
> 
[snip]
>
> Whether you think that chroot is worth the effort is your decision. I can't tell you not to do it, just advise that many don't use chroot and have no issues. BIND needs to write to certain folders, depending on which features you use. But as it is running as a normal user, if the OS won't let it, it can't.
> Maybe you should ask RedHat and its users (there must be a RH forum) what they recommend and make your decision once you have gathered opinions from various sources.
> 
> Hope that helps.
> Cheers, Greg

As a RH-family user, we use the COPR ISC packages with SELinux in enforcing mode and are more than happy with the level of security provided.

For inline signing, we've had to make some selinux policy modifications so that BIND can create/delete keys (when not using HSM's), but other than that, it works fine out of the box.

Stuart

-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/bind-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.