Re: Using BIND in a chroot enviro?

Jamie Heilman <jamie@audible.transient.net> writes:

> > forget it.
> > 1. non-free
> Certainly, that is something to consider, if your prejudice is that way
> bent. I tend to judge software more on its technical merit than on its
> distribution policies. 

Hmmmm. I dislike the word `prejudice' there, even if it does sum my
approach to non-free up very well. Technical merits are of stuff-all use if
the software can't be redistributed freely in sensible packages.

> At any rate, maradns is of similar design, and it is DFSG compliant, if
> you want yet another alternative.

Yes. (I've been thinking about experimenting with this, but can't atm.)

> > 2. author write like "alle shit then my"
> Uh, sure.

Whatever the quote means, I don't need *another* DJB-war barely a fortnight
after the last one.

> You clearly don't understand what this person was asking for, or what
> dnscache is capable of. There seem to be a lot of people waving the
> 53/tcp flag lately like its some kind of huge bogon that you have to
> watch out for when you're building your firewall rules. 

It's something to consider, as you say, given the assorted criteria. As you
say, if you decide you don't need it, you should probably firewall it off.

>      If your upstream ISP only accepts queries from source port 53, they
> are stupid and you'd be best off finding a better ISP, or just doing all
> the resolving yourself (probably more secure that way anyhow depending on
> how much you trust your upstream's DNS cache configuration).

Correct. query-source-port 53 is evil.

> If, on the other hand, you are serving DNS records to the world at large,
> you already know perfectly well if you have records over 512 bytes that
> will require tcp transport or not, or if you need to allow zone transfers
> to outside parties, so the question of if you need to allow 53/tcp is
> already decided, all you have to do is recognise that fact.


