<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does anyone have DNS working in Fedora in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265260#M11863</link>
    <description>The CHRoot jail could have happened in my GUI config of named; GUI config of my ADSL always breaks the init script for example. No matter what I enter as the password the GUI puts "none" in the password portion of the paps-secrets file. Have to manually change it to the correct password to get ADSL to start.&lt;BR /&gt;&lt;BR /&gt;Like they say; if it was easy it would be no fun !!&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Sun, 02 May 2004 23:10:02 GMT</pubDate>
    <dc:creator>Vernon Brown_4</dc:creator>
    <dc:date>2004-05-02T23:10:02Z</dc:date>
    <item>
      <title>Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265255#M11858</link>
      <description>I was running DNS on my server before I upgraded from RedHat 7.1 to Fedora Core 1. Apache virtual hosts and mail are working but just noticed that DNS does not work. Named is running; starts without complaint; but strange things happen in the /var/named directory. I find there /var/named/chroot in which the /var/named directory is duplicated; and in that yet another /var/named/chroot/var/named/chroot etc. to who knows how far.&lt;BR /&gt;&lt;BR /&gt;Seems broke.&lt;BR /&gt;&lt;BR /&gt;How to revert back to the old DNS that works while waiting for this new chroot scheme to get fixed.&lt;BR /&gt;&lt;BR /&gt;Anyone know ??&lt;BR /&gt;&lt;BR /&gt;Vern</description>
      <pubDate>Sun, 02 May 2004 20:15:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265255#M11858</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-05-02T20:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265256#M11859</link>
      <description>I've made this work with Fedora. I did as follows:&lt;BR /&gt;&lt;BR /&gt;1) Copied my /etc/named.conf file exactly as it was from Red Hat 7.x&lt;BR /&gt;&lt;BR /&gt;2) copied all the entries in /var/named from the old system to the new system.&lt;BR /&gt;&lt;BR /&gt;service named start&lt;BR /&gt;&lt;BR /&gt;There were a few warning messages, but I was able to comment out the lines in /etc/named.conf that were being complained about.&lt;BR /&gt;&lt;BR /&gt;You didn't run Bastile on this system did you?&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Sun, 02 May 2004 20:51:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265256#M11859</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-05-02T20:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265257#M11860</link>
      <description>Hi Steven; I didn't intentionally run Bastille but I did the DNS setup with the Gnome GUI and am not sure what all that setup did.&lt;BR /&gt;&lt;BR /&gt;Searching on the internet I find lots of folks having problems with DNS with Fedora; I'll try your approach and see if I can tweak for my setup.&lt;BR /&gt;&lt;BR /&gt;Thanks !!&lt;BR /&gt;&lt;BR /&gt;Vern</description>
      <pubDate>Sun, 02 May 2004 21:18:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265257#M11860</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-05-02T21:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265258#M11861</link>
      <description>Success !!!&lt;BR /&gt;&lt;BR /&gt;Steven; it worked; had to do a couple of additional steps. In the file /etc/sysconfig/named comment out the entry:&lt;BR /&gt;&lt;BR /&gt;ROOTDIR=/var/named/chroot&lt;BR /&gt;&lt;BR /&gt;so that it looks like:&lt;BR /&gt;&lt;BR /&gt;#ROOTDIR=/var/named/chroot&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Then make the /etc/resolv.conf first entry be:&lt;BR /&gt;&lt;BR /&gt;nameserver 127.0.0.1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 02 May 2004 22:08:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265258#M11861</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-05-02T22:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265259#M11862</link>
      <description>By default, it would appear as if your system was set up to use a CHRoot jail for Named.&lt;BR /&gt;&lt;BR /&gt;Until last night, I'd never purposely done this.  I've since found out it's bloody simple!&lt;BR /&gt;&lt;BR /&gt;The CHRoot jail by it's very nature means that if 'named' does get exploited, there's nothing to do within the exploited filesystem, as there's no shell, no utilities, hell, no libraries!  Very secure.&lt;BR /&gt;&lt;BR /&gt;The requirements are pretty simple too.  I admit to being a bit confused by the zero-byte-length 'named.conf' in the distributed fedora chroot jail however, as the documentation says this is read *after* the chroot creation.  Anyway..&lt;BR /&gt;&lt;BR /&gt;As for the double duplication, I think that was a bugger-up on behalf of the packager.</description>
      <pubDate>Sun, 02 May 2004 22:52:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265259#M11862</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2004-05-02T22:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265260#M11863</link>
      <description>The CHRoot jail could have happened in my GUI config of named; GUI config of my ADSL always breaks the init script for example. No matter what I enter as the password the GUI puts "none" in the password portion of the paps-secrets file. Have to manually change it to the correct password to get ADSL to start.&lt;BR /&gt;&lt;BR /&gt;Like they say; if it was easy it would be no fun !!&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 02 May 2004 23:10:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265260#M11863</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-05-02T23:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265261#M11864</link>
      <description>So you've taken named out of the chroot jail.&lt;BR /&gt;&lt;BR /&gt;Its still reasonably secure. Now I'd like to suggest that you attempt to get it working within the chroot jail.&lt;BR /&gt;&lt;BR /&gt;I've injured myself playing sports(yeah, more itrc time right?) and will attempt to do this very same thing on a non-production BIND server over the next few days.&lt;BR /&gt;&lt;BR /&gt;Of the procedures I've found thus far, this one looks best.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://sxs.thexdershome.com/internet_serving/bind9_chroot.html" target="_blank"&gt;http://sxs.thexdershome.com/internet_serving/bind9_chroot.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I'm going to try it and see how it works.&lt;BR /&gt;&lt;BR /&gt;We'll learn together.&lt;BR /&gt;&lt;BR /&gt;I suggest this only because you have been hacked so many times, its best to secure everything you can.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Sun, 02 May 2004 23:12:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265261#M11864</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-05-02T23:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265262#M11865</link>
      <description>I literally did this last night for a friend of mine who runs a small local ISP.&lt;BR /&gt;&lt;BR /&gt;He mentioned it, I looked, and lo-and-behold, 10 minutes later one CHRoot'd monster!&lt;BR /&gt;&lt;BR /&gt;Looking at how fedora does it by default seems I did too much, but *shrug* it works well!&lt;BR /&gt;&lt;BR /&gt;requirements:&lt;BR /&gt;&lt;BR /&gt;/etc/named.conf&lt;BR /&gt;/etc/localtime&lt;BR /&gt;/var/named/*&lt;BR /&gt;/var/run/named/ (group-write 'named')&lt;BR /&gt;/dev/random (c/1/8)&lt;BR /&gt;/dev/null (c/1/3)&lt;BR /&gt;&lt;BR /&gt;The 'ROOTDIR' entry in '/etc/sysconfig/named' to point to your new chroot structure.&lt;BR /&gt;&lt;BR /&gt;I didn't have to make any syslog changes, it found them all on it's own.</description>
      <pubDate>Sun, 02 May 2004 23:18:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265262#M11865</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2004-05-02T23:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265263#M11866</link>
      <description>Why would you convert it to the older version.The only difference (to someone who configures of course) is that the configuration files are now under /var/named/chroot/.&lt;BR /&gt;If you edit /var/named/chroot/etr/named.conf&lt;BR /&gt;&lt;BR /&gt;and then /var/named/chroot/var/named/zonefile&lt;BR /&gt;correctly and then restart the named service-everything is suppose to work.&lt;BR /&gt;&lt;BR /&gt;However if you still wish to work without the chroot enviroment-try to remove the bind-chroot package:&lt;BR /&gt;rpm -e bind-chroot&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 03 May 2004 00:53:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265263#M11866</guid>
      <dc:creator>Alexander Chuzhoy</dc:creator>
      <dc:date>2004-05-03T00:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265264#M11867</link>
      <description>Okay, progress report.&lt;BR /&gt;&lt;BR /&gt;After much annoyance I had to combine Stuart's and my procedure.  His assumes you know the mknod commands which frankly I don't.  Mine doesn't work due to the syslog changes I think.&lt;BR /&gt;&lt;BR /&gt;One caveat.&lt;BR /&gt;&lt;BR /&gt;I get this error at startup.&lt;BR /&gt;&lt;BR /&gt;/etc/init.d/named: line 7: --: command not found&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;There is nothing on line 7 of /etc/init.d/ so I'm not sure how serious this is.&lt;BR /&gt;&lt;BR /&gt;I do however have named running in a choot jail. I may try it on HP-UX at work. &lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 03 May 2004 01:31:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265264#M11867</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-05-03T01:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265265#M11868</link>
      <description>Err, oops! ;) Sorry Steve.  Did a bit of 'mknod'n last week so it's fresh in my mind ;)&lt;BR /&gt;&lt;BR /&gt;(for the record, the docuemnt SEP posted has the commands, but they are simply 'mknod null c 1 3;mknod random c 1 8').&lt;BR /&gt;&lt;BR /&gt;I did it last night on an ES3 box with copying those files, and mknod'n those device nodes.&lt;BR /&gt;&lt;BR /&gt;I admit it took 3 restarts to get all the permissions right though :)&lt;BR /&gt;&lt;BR /&gt;SEP, I'm looking through RH8, RH9, FC1 and RHES3's '/etc/init.d/named', and line 7 on all of them appear to be part of the commented-out 'chkconfig' Description lines.&lt;BR /&gt;&lt;BR /&gt;Wanna paste the top dozen or so lines of it, or email 'em to me (stuart at promed.com.au), and we'll see what it's thinking.&lt;BR /&gt;&lt;BR /&gt;Oh, and I forgot the '/etc/rndc.key' file earlier.  Apologies.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 03 May 2004 01:56:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265265#M11868</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2004-05-03T01:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265266#M11869</link>
      <description>Ok; I'll try to put DNS back in jail :o)&lt;BR /&gt;&lt;BR /&gt;I managed to get an install of Fedora with chroot'ed named only one level deep; the way I think it should be. It works as a caching only name server. &lt;BR /&gt;&lt;BR /&gt;I'll try adding my local zones later.</description>
      <pubDate>Mon, 03 May 2004 06:42:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265266#M11869</guid>
      <dc:creator>Vernon Brown_4</dc:creator>
      <dc:date>2004-05-03T06:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265267#M11870</link>
      <description>Stuart, my /etc/init.d/named looks just like yours.&lt;BR /&gt;&lt;BR /&gt;Which makes the error rather problematic and hard to diagnose. I have no clue how to proceed but note that DNS is running in the chroot jail, appears to be stable, so I'm not going production yet, but I'm not terribly worried.&lt;BR /&gt;&lt;BR /&gt;Vernon,&lt;BR /&gt;&lt;BR /&gt;Stuart was "spot on" with regards to not having to alter the syslog. My document is out of date where it refers to /etc/rc.d/named that should be /etc/init.d/named  ... At some point, I'll post a version to my own website.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 03 May 2004 10:30:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265267#M11870</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-05-03T10:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have DNS working in Fedora</title>
      <link>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265268#M11871</link>
      <description>Hrm.. Freaky..  Ghost errors.. always fun ;)</description>
      <pubDate>Mon, 03 May 2004 18:14:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/does-anyone-have-dns-working-in-fedora/m-p/3265268#M11871</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2004-05-03T18:14:19Z</dc:date>
    </item>
  </channel>
</rss>

