Subject: Re: proposals for running named in a non-root chroot cage
To: Luke Mewburn <lukem@wasabisystems.com>
From: Andrew Brown <atatat@atatdot.net>
List: tech-security
Date: 03/08/2001 19:10:32
>	- change the build system to populate /var/named/ by default
>	  (with named-xfer, the example etc/namedb, ...)

...named-xfer would be installed in /var/named/usr/libexec/named-xfer
and a symlink would be put at /usr/libexec/named-xfer?

>	- add a migration mechanism to /etc/rc.d/named which detects
>	  if /etc/namedb isn't a symlink, and if it isn't, copies the
>	  contents to /var/namedb and makes it a symlink. This could
>	  be dangerours

...especially if the symlink points to the wrong place.  too bad
there's no useland to spew the contents of a symlink.

>	- alternatively, consider a manual migration tool/process.

might not be so bad.

-- 
|-----< "CODE WARRIOR" >-----|
codewarrior@daemon.org             * "ah!  i see you have the internet
twofsonet@graffiti.com (Andrew Brown)                that goes *ping*!"
andrew@crossbar.com       * "information is power -- share the wealth."