Subject: Re: bin/30479
To: None <gnats-admin@netbsd.org, netbsd-bugs@netbsd.org,>
From: Paul Shupak <paul@Plectere.com>
List: netbsd-bugs
Date: 08/22/2005 15:42:08
>...
>Synopsis: named does not use the available libwrap/hosts_access functions
>
>State-Changed-From-To: open->closed
>State-Changed-By: perry@netbsd.org
>State-Changed-When: Mon, 22 Aug 2005 22:05:37 +0000
>State-Changed-Why:
>bind9 has its own internal ACLs, which are generally superior to what
>libwrap could bring.
>

	The internal ACL capability is limited to static lists only
and does not allow the functionality of the RBL capabilties of the
libwrap library to operated of effectively dynamic ACLs.  Also
missing is the ability to use the various extensions in hosts_options;
Particularly "twist"'s abiliy to run a completely different binary in
response to certain hosts.  Further, the ACLs do not allow control over
the syslog severity levels.

	Admittedly, the existing ACL mechanism does quite well for
many of the common uses of libwrap, but is equivolent to limiting
some functionality to what existed in libwrap many, many years ago.
Your statement of "generally superior" is conceded as correct, but
for the specific cases mentioned above and other, please reopen, or
at least reconsider this PR.

	Thank you,

	Paul Shupak