MESSAGE
DATE | 2002-08-23 |
FROM | marco
|
SUBJECT | Subject: [hangout] should I chroot my name servers?
|
Well I just finished setting up two name servers for me and Vincenzo.
dlint is not giving me any errors except the usual 2 A records on the machines that are the nameservers. reverse-dns seems to be working also.
I have also set up a good bit of security, including transaction signatures on the zone transfers, I even checked this by changing one character in one of the keys and indeed the transfer did not occur (pretty cool). I am refusing all external queries except for the zone I am authoritative for, and I made sure all config files are not world readable.
But, I did not chroot the servers, it wouldn't be too hard to do, but I wonder if this is really necessary. Chroot'ing is protection against a buffer under/over flow entry to the system, or is there more?
Comments? Ideas?
Thanks,
--Marco
ps if you are feeling overly helpfull I can send you the dig commands to check my set up as the configuration hasn't propagated through the net yet.
____________________________ New Yorker Free Software Users Scene Fair Use - because it's either fair use or useless....
|
|