Subject: Re: BIND DoS and remote compromise issues
To: Paul Hoffman <phoffman@proper.com>
From: Andrew Brown <atatat@atatdot.net>
List: tech-security
Date: 11/12/2002 15:00:18
>>  >So, once we install BIND 9 from pkgsrc, what is the correct way to
>>>change the system to use it?
>>>
>>>Do I simply change 'command="/usr/sbin/${name}"' in /etc/rc.d/named
>>>to 'command="/usr/pkg/sbin/${name}"'?
>>
>>short answer: yes.
>>
>>long answer: no.
>>
>>long answer justification?
>>
>>try not to change the system supplied rc.d files, as doing so will
>>make upgrades less smooth.
>
>OK, I just noticed that pkg_add added "named9" in /usr/pkg/etc/rc.d. 
>I could copy that to /etc/rc.d, but then how do I get named9 to 
>launch? Do I simply say "named=NO" and "named9=YES" in /etc/rc.conf?

that's another way to do it, yes.  you just have to remember where the
named9 script came from, and to upgrade it if you upgrade the bind9
pkg at some point.

-- 
|-----< "CODE WARRIOR" >-----|
codewarrior@daemon.org             * "ah!  i see you have the internet
twofsonet@graffiti.com (Andrew Brown)                that goes *ping*!"
werdna@squooshy.com       * "information is power -- share the wealth."