Re: question on minimal file permissions

2011-04-18 Thread Chris Thompson
On Apr 18 2011, Tony Finch wrote: Zone files that are managed by bind need to be writable by BIND (mode 644 and owned by BIND). BIND does not overwrite zone file in place! For those that it does manage (type slave/stub, or type master with DNS updates allowed) it is the directory containing t

Re: question on minimal file permissions

2011-04-18 Thread Tony Finch
hostmas...@g-net.be wrote: > > 4 dr--r--r-- 2 bind bind 4096 2011-04-18 14:50 . You should set execute permission on the directory so that bind can traverse it. Tony. -- f.anthony.n.finchhttp://dotat.at/ Rockall, Malin, Hebrides: South 5 to 7, occasionally gale 8 at first in Rockall and Ma

Re: question on minimal file permissions

2011-04-18 Thread John Bond
On 4/18/11 2:17 PM, hostmas...@g-net.be wrote: > > and when I configure my zone like this in named.conf.local : > > zone "zone.be" { > type master; > file "/dnszones/db.zone.be.signed"; > auto-dnssec maintain; > key-directory "/dnskeys/"; > sig-validity-in

Re: question on minimal file permissions

2011-04-18 Thread hostmas...@g-net.be
On Mon, 2011-04-18 at 11:47 +0100, Tony Finch wrote: > hostmas...@g-net.be wrote: > > > > The reason I ask is because I'm setting up a DNS sec server and for easy > > key rollover and manageability I have created several new directories on > > a usb stick for example. Key files and zone files now

Re: question on minimal file permissions

2011-04-18 Thread Tony Finch
hostmas...@g-net.be wrote: > > The reason I ask is because I'm setting up a DNS sec server and for easy > key rollover and manageability I have created several new directories on > a usb stick for example. Key files and zone files now all have 774 > permissions , owned by bind:bind , but I was won

question on minimal file permissions

2011-04-18 Thread hostmas...@g-net.be
Hi all , I'm running bind 9.7 on Ubuntu server 10.04LTS , and I was wondering if there is documentation on minimal file permissions needed for bind-config files/zone files. The reason I ask is because I'm setting up a DNS sec server and for easy key rollover and manageability I have created sev