chroot: any security benefits from a full chroot?

Javier Sanchez sjllera at ya.com
Mon Sep 20 10:54:15 UTC 2004


And your colleage has exposed any benefits of running the server in a
complete environment ??? Im running 3 name server, all under chroot
environments and theys are working great, why would you want to expose
your system to any bind9 security bug ???

During the chroot setup, i only found problems searching the strace
output to discover all the libs bind9 needed.

Cheers

?A
> Hi,
> we are setting up a bind9 server (on linux 2.4.26) and want to
> run it chroot'ed. A colleague insists on using a full
> environment, i.e. will all libs etc. included and not using
> bind9's mechanism for chrooting it.
> 
> Is there any security benefit from this?
> 
> Best regards
>         Martin
-- 
GPG Key id: 0x0EF8926E
GPG: Server - gpg.rediris.es




More information about the bind-users mailing list