Allow only temporary zone updates without making them permanent

Grant Taylor gtaylor at tnetconsulting.net
Wed Jun 26 19:56:08 UTC 2019


On 6/26/19 1:17 PM, Lefteris Tsintjelis via bind-users wrote:
> If I set it though, and named no longer has access to modify and rewrite 
> other files but its own, will it break things? What will happen in case 
> of a dynamic update like ACME in this case? Will the update go through?

I think that would be HIGHLY dependent on /how/ named updates files.

Does it try to move (rename) existing files and create /new/ files?  Or 
does it rewrite contents of /exiting/ files.

I don't know these particulars.  I've never had a problem allowing named 
to have write access to the directory and do what it wants with the 
files therein.



-- 
Grant. . . .
unix || die

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4008 bytes
Desc: S/MIME Cryptographic Signature
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20190626/a6d0c5fd/attachment.bin>


More information about the bind-users mailing list