티스토리 뷰

Fedora 18 DNS Server chroot Environment

Configute chroot environment. Simply install "bind-chroot" package to do so. If you edit named.conf or other zone files on chroot environment, edit configuration files under /var/named/chroot/ .


[root@otaec ~]# yum -y install bind-chroot


[root@otaec ~]# /usr/libexec/setup-named-chroot.sh /var/named/chroot on 


[root@otaec ~]# systemctl stop named.service 


[root@otaec ~]# systemctl disable named.service 


[root@otaec ~]# systemctl start named-chroot.service 


[root@otaec ~]# systemctl enable named-chroot.service 

ln -s '/usr/lib/systemd/system/named-chroot.service' '/etc/systemd/system/multi-user.target.wants/named-chroot.service'


[root@otaec ~]# ll /var/named/chroot/etc 

total 32

-rw-r--r-- 1 root root   331 Jan 17 13:01 localtime

drwxr-x--- 2 root named 4096 Dec 20 23:07 named

-rw-r----- 1 root named 1630 Jan 17 12:50 named.conf

-rw-r--r-- 1 root named 2389 Dec 20 23:07 named.iscdlv.key

-rw-r----- 1 root named  931 Jun 21  2007 named.rfc1912.zones

-rw-r--r-- 1 root named  487 Jul 19  2010 named.root.key

drwxr-x--- 3 root named 4096 Jan 17 13:01 pki

-rw-r----- 1 root named   77 Jan 17 12:54 rndc.key


[root@otaec ~]# ll /var/named/chroot/var/named 

total 40

-rw-r--r-- 1 root  root   359 Jan 17 12:54 0.0.10.db

drwxr-x--- 6 root  named 4096 Jan 17 13:01 chroot

drwxrwx--- 2 named named 4096 Jan 17 12:54 data

drwxrwx--- 2 named named 4096 Jan 17 12:56 dynamic

-rw-r----- 1 root  named 1892 Feb 18  2008 named.ca

-rw-r----- 1 root  named  152 Dec 15  2009 named.empty

-rw-r----- 1 root  named  152 Jun 21  2007 named.localhost

-rw-r----- 1 root  named  168 Dec 15  2009 named.loopback

-rw-r--r-- 1 root  root   353 Jan 17 12:53 server.world.lan

drwxrwx--- 2 named named 4096 Dec 20 23:07 slaves

댓글