Bv9ARM.7.html revision 40f53fa8d9c6a4fc38c0014495e7a42b08f52481
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML EXPERIMENTAL 970324//EN">
c18e9c3c6d5039618f1f2c05526ece84c7794ea3Christian Maeder - Copyright (C) 2000 Internet Software Consortium.
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder - Permission to use, copy, modify, and distribute this software for any
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder - purpose with or without fee is hereby granted, provided that the above
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder - copyright notice and this permission notice appear in all copies.
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder - THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM
48c4688439e0aade4faeebf25ca8b16d661e47afChristian Maeder - DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
48c4688439e0aade4faeebf25ca8b16d661e47afChristian Maeder - IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
48c4688439e0aade4faeebf25ca8b16d661e47afChristian Maeder - INTERNET SOFTWARE CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT,
7dec34aee2b609b9535c48d060e0f7baf3536457Christian Maeder - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING
48c4688439e0aade4faeebf25ca8b16d661e47afChristian Maeder - FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT,
48c4688439e0aade4faeebf25ca8b16d661e47afChristian Maeder - NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION
48c4688439e0aade4faeebf25ca8b16d661e47afChristian Maeder - WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
8425adcfd77c8f90e6b76c7b40d39f878ee86d44Christian Maeder<!-- $Id: Bv9ARM.7.html,v 1.10 2000/08/01 01:17:57 tale Exp $ -->
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML EXPERIMENTAL 970324//EN">
7dec34aee2b609b9535c48d060e0f7baf3536457Christian Maeder<META NAME="GENERATOR" CONTENT="Adobe FrameMaker 5.5/HTML Export Filter">
fcec1ffa4a95dbc47cf23f75e6843ceff93a925eChristian Maeder<TITLE> Section 7. BIND 9 Security Considerations</TITLE></HEAD>
34b317241b7401a4b0a90472e73d769d64d69a2aChristian MaederSection 7. BIND 9 Security Considerations</H1>
c6456fd6e9cc28e09be25058d38fd41cc49a87e9Christian MaederAccess Control Lists</H3>
7dec34aee2b609b9535c48d060e0f7baf3536457Christian MaederAccess Control Lists (ACLs), are address match lists that you can set up and nickname for future use in <CODE CLASS="Program-Process">
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maederallow-query</CODE>
7dec34aee2b609b9535c48d060e0f7baf3536457Christian Maederallow-recursion</CODE>
fc7df539e6d41b050161ed8f9ae6e444b1b5ab14Christian Maederblackhole</CODE>
fc7df539e6d41b050161ed8f9ae6e444b1b5ab14Christian Maederallow-transfer</CODE>
702e6988ac0ef3cf2d1840e5d544b092821adc76Christian MaederUsing ACLs allows you to have finer control over who can access your nameserver, without cluttering up your config files with huge lists of IP addresses.</P>
702e6988ac0ef3cf2d1840e5d544b092821adc76Christian Maedergood idea</EM>
702e6988ac0ef3cf2d1840e5d544b092821adc76Christian Maeder to use ACLs, and to control access to your server. Limiting access to your server by outside parties can help prevent spoofing and DoS attacks against your server.</P>
fc7df539e6d41b050161ed8f9ae6e444b1b5ab14Christian MaederHere is an example of how to properly apply ACLs:</P>
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder<CODE><STRONG>// Set up an ACL named "bogusnets" that will block RFC1918 space,
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder// which is commonly used in spoofing attacks.
47a19e4d083d2cecf1fd95f93dcbe04496544a6aChristian Maederacl bogusnets { 0.0.0.0/8; 1.0.0.0/8; 2.0.0.0/8; 192.0.2.0/24; 224.0.0.0/3;
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder10.0.0.0/8; 172.16.0.0/12; 192.168.0.0/16; };
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder// Set up an ACL called our-nets. Replace this with the real IP numbers.
9c5b1136299d9052e4e995614a3a36a051a2682fChristian Maeder allow-query { our-nets; };
9c5b1136299d9052e4e995614a3a36a051a2682fChristian Maeder allow-recursion { our-nets; };
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder blackhole { bogusnets; };
fcec1ffa4a95dbc47cf23f75e6843ceff93a925eChristian Maederzone "example.com" {
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder allow-query { any; };
8425adcfd77c8f90e6b76c7b40d39f878ee86d44Christian MaederThis allows recursive queries of the server from the outside unless recursion has been previously disabled.</P>
9c5b1136299d9052e4e995614a3a36a051a2682fChristian MaederFor more information on how to use ACLs to protect your server, see the <EM CLASS="Emphasis">
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder advisory at<BR>
34b317241b7401a4b0a90472e73d769d64d69a2aChristian Maeder<a href="ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos">
48c4688439e0aade4faeebf25ca8b16d661e47afChristian Maederftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos</a>
715ffaf874309df081d1e1cd8e05073fc1227729Christian Maeder (for UNIX servers)</H3>
fcec1ffa4a95dbc47cf23f75e6843ceff93a925eChristian MaederOn UNIX servers, it is possible to run BIND in a <EM CLASS="Emphasis">
8338fbf3cfb9cf981261d893286f070bd9fa17efChristian Maeder environment (<CODE CLASS="Program-Process">
fcec1ffa4a95dbc47cf23f75e6843ceff93a925eChristian Maederchroot()</CODE>
b789ce4c50283bff24d92a2806b253850395d990Christian Maeder) by specifying the "<CODE CLASS="Program-Process">
715ffaf874309df081d1e1cd8e05073fc1227729Christian Maeder" option. This can help improve system security by placing BIND in a "sandbox," which will limit the damage done if a server is compromised.</P>
715ffaf874309df081d1e1cd8e05073fc1227729Christian MaederAnother useful feature in the UNIX version of BIND is the ability to run the daemon as a nonprivileged user ( <CODE CLASS="Program-Process">
c18e9c3c6d5039618f1f2c05526ece84c7794ea3Christian Maeder ). We suggest running as a nonprivileged user when using the <CODE CLASS="Program-Process">
fc7df539e6d41b050161ed8f9ae6e444b1b5ab14Christian MaederHere is an example command line to load BIND in a <CODE CLASS="Program-Process">
780f981d3c8567cfaebdc8c2d6edb0e2c57aae04Christian Maederchroot()</CODE>
fc7df539e6d41b050161ed8f9ae6e444b1b5ab14Christian Maeder sandbox, <BR>
715ffaf874309df081d1e1cd8e05073fc1227729Christian Maeder to user 202:</P>
47a19e4d083d2cecf1fd95f93dcbe04496544a6aChristian Maeder<CODE><STRONG>/usr/local/bin/named -u 202 -t /var/named
780f981d3c8567cfaebdc8c2d6edb0e2c57aae04Christian Maeder Environment</H4>
5214cf3742dc626a7efc5ec851db09bf0ff1f579Christian MaederIn order for a <CODE CLASS="Program-Process">
9c5b1136299d9052e4e995614a3a36a051a2682fChristian Maederchroot()</CODE>
9c5b1136299d9052e4e995614a3a36a051a2682fChristian Maeder environment to work properly in a particular directory (for example, <EM CLASS="pathname">
41859342472c9349707a4bbd7a05340c639013c0Christian Maeder), you will need to set up an environment that includes everything BIND needs to run. From BIND's point of view, <EM CLASS="pathname">
780f981d3c8567cfaebdc8c2d6edb0e2c57aae04Christian Maeder is the root of the filesystem. You will need <EM CLASS="pathname">
780f981d3c8567cfaebdc8c2d6edb0e2c57aae04Christian Maeder, and any library directories and files that BIND needs to run on your system. Please consult your operating system's instructions if you need help figuring out which library files you need to copy over to the <CODE CLASS="Program-Process">
780f981d3c8567cfaebdc8c2d6edb0e2c57aae04Christian Maederchroot()</CODE>
93ee71ae78c3b7419930a8e4a06977ac7dbae6d0Christian MaederIf you are running an operating system that supports static binaries, you can also compile BIND statically and avoid the need to copy system libraries over to your <CODE CLASS="Program-Process">
93ee71ae78c3b7419930a8e4a06977ac7dbae6d0Christian Maederchroot()</CODE>
7dec34aee2b609b9535c48d060e0f7baf3536457Christian Maeder7.2.2 Using the <CODE CLASS="Program-Process">
7dec34aee2b609b9535c48d060e0f7baf3536457Christian Maeder Function </H4>
7dec34aee2b609b9535c48d060e0f7baf3536457Christian MaederPrior to running the <CODE CLASS="Program-Process">
6cca02cb6a5ae882d887a879f8b7a71941c3715cChristian Maeder daemon, use the <CODE CLASS="Program-Process">
fc7df539e6d41b050161ed8f9ae6e444b1b5ab14Christian Maeder utility (to change file access and modification times) or the <CODE CLASS="Program-Process">
7dec34aee2b609b9535c48d060e0f7baf3536457Christian Maeder utility (to set the user id and/or group id) on files to which you want BIND to write.</P>
702e6988ac0ef3cf2d1840e5d544b092821adc76Christian Maeder7.3 Dynamic Updates</H3>
fc7df539e6d41b050161ed8f9ae6e444b1b5ab14Christian MaederAccess to the dynamic update facility should be strictly limited. In earlier versions of BIND the only way to do this was based on the IP address of the host requesting the update. BIND 9BIND 9 also supports authenticating updates cryptographically by means of transaction signatures (TSIG). The use of TSIG is strongly recommended.</P>
7dec34aee2b609b9535c48d060e0f7baf3536457Christian MaederSome sites choose to keep all dynamically updated DNS data in a subdomain and delegate that subdomain to a separate zone. This way, the top-level zone containing critical data such as the IP addresses of public web and mail servers need not allow dynamic update at all.</P>
702e6988ac0ef3cf2d1840e5d544b092821adc76Christian Maeder<p>Return to <A href="Bv9ARM.html">BIND 9 Administrator Reference Manual</A> table of contents.</p>