OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Bryan Paxton (evil7deadhorse.net)
Date: Thu Jan 24 2002 - 18:06:42 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

     The last BIND upgrade ( MDKSA-2002:001 ) has seemed to break BIND's
    ability to perform a chroot, and reside in that jail.

    Excerpt from logs:
    <SNIP>
    Jan 25 00:00:40 sQa /usr/sbin/named[18391]: starting BIND 9.1.1 -n 2 -u
    dns -t /var/dns/
    Jan 25 00:00:40 sQa /usr/sbin/named[18391]: using 2 CPUs
    Jan 25 00:00:40 sQa /usr/sbin/named[20932]: loading configuration from
    '/etc/named.conf'
    Jan 24 18:00:40 sQa named: named startup succeeded
    Jan 25 00:00:40 sQa /usr/sbin/named[20932]: no IPv6 interfaces found
    Jan 25 00:00:40 sQa /usr/sbin/named[20932]: listening on IPv4 interface
    lo, 127.0.0.1#53
    Jan 25 00:00:40 sQa /usr/sbin/named[20932]: listening on IPv4 interface
    eth1, 172.16.19.1#53
    Jan 25 00:00:40 sQa /usr/sbin/named[20932]: couldn't open pid file
    '/var/run/named/named.pid': No such file or directory
    Jan 25 00:00:40 sQa /usr/sbin/named[20932]: exiting (due to early fatal
    error)
    </SNIP>

     It appears it's trying to write a PID file before chrooting.
    The lay out of /var/dns:
    |-- dev
    | `-- null
    |-- etc
    | `-- named.conf
    |-- lib
    | |-- ld-linux.so.2
    | `-- libc.so.6
    |-- usr
    | `-- sbin
    | |-- named
    | `-- named-xfer
    `-- var
        |-- named
        | |-- internal.db
        | |-- named.ca
        | `-- named.local
        `-- run

     The only files named needs (needed before).
    Anyway, if some one has insight as to the problem here... : )

    --
    Bryan Paxton
    Public PGP key: http://www.deadhorse.net/bpaxton.gpg

    For help, email discuss-helpmandrakesecure.net; to unsubscribe send a
    message to discuss-unsubscribemandrakesecure.net. To visit MandrakeSecure,
    go to http://www.mandrakesecure.net/.