4 Commits

Author SHA1 Message Date
Natanael Copa
6bf81f56e8 main/*: replace all sbin/runscript with sbin/openrc-run 2015-04-28 14:34:51 +00:00
Hugo Landau
10f550c471 bind: Modify default config to be more secure
By default BIND will happily serve as both an authoritative nameserver
and recursive resolver, but this is no longer a recommended or desirable
configuration. The previous default configuration did not draw attention
to this fact and the issues involved.

Users are now made to rename one of two sample configuration files,
named.conf.authoritative or named.conf.recursive. Comments inside either
file advise DNS administrators of the most prevalent security issues.

This ensures that users setting up an authoritative nameserver do not
unwittingly also operate a resolver. In the previous default
configuration, BIND would happily perform recursive resolution for
localhost, which means that the local machine may receive
non-authoritative data from what is supposed to be an authoritative
nameserver.

Both default configurations disable zone transfers by default, as BIND
defaults to enabling them for any host (!).
2014-10-16 19:05:10 +00:00
Natanael Copa
6f89add111 main/bind: remove duplicate depend function 2014-06-19 08:30:19 +00:00
Natanael Copa
0c2a46ee5c main/bind: cleanup and fix named.initd stop 2012-03-14 21:23:57 +00:00