Bv9ARM.ch07.html revision c92c50783e4e93699f2a42643b8f200b9b719c87
45e9809aff7304721fddb95654901b32195c9c7avboxsync - Copyright (C) 2004-2012 Internet Systems Consortium, Inc. ("ISC")
45e9809aff7304721fddb95654901b32195c9c7avboxsync - Copyright (C) 2000-2003 Internet Software Consortium.
45e9809aff7304721fddb95654901b32195c9c7avboxsync - Permission to use, copy, modify, and/or distribute this software for any
45e9809aff7304721fddb95654901b32195c9c7avboxsync - purpose with or without fee is hereby granted, provided that the above
45e9809aff7304721fddb95654901b32195c9c7avboxsync - copyright notice and this permission notice appear in all copies.
45e9809aff7304721fddb95654901b32195c9c7avboxsync - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
45e9809aff7304721fddb95654901b32195c9c7avboxsync - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
45e9809aff7304721fddb95654901b32195c9c7avboxsync - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
45e9809aff7304721fddb95654901b32195c9c7avboxsync - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
45e9809aff7304721fddb95654901b32195c9c7avboxsync - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
45e9809aff7304721fddb95654901b32195c9c7avboxsync - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
45e9809aff7304721fddb95654901b32195c9c7avboxsync - PERFORMANCE OF THIS SOFTWARE.
45e9809aff7304721fddb95654901b32195c9c7avboxsync<!-- $Id: Bv9ARM.ch07.html,v 1.265 2012/01/07 01:14:56 tbox Exp $ -->
45e9809aff7304721fddb95654901b32195c9c7avboxsync<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
45e9809aff7304721fddb95654901b32195c9c7avboxsync<title>Chapter�7.�BIND 9 Security Considerations</title>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
45e9809aff7304721fddb95654901b32195c9c7avboxsync<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
45e9809aff7304721fddb95654901b32195c9c7avboxsync<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
45e9809aff7304721fddb95654901b32195c9c7avboxsync<link rel="prev" href="Bv9ARM.ch06.html" title="Chapter�6.�BIND 9 Configuration Reference">
45e9809aff7304721fddb95654901b32195c9c7avboxsync<link rel="next" href="Bv9ARM.ch08.html" title="Chapter�8.�Troubleshooting">
45e9809aff7304721fddb95654901b32195c9c7avboxsync<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
45e9809aff7304721fddb95654901b32195c9c7avboxsync<tr><th colspan="3" align="center">Chapter�7.�<acronym class="acronym">BIND</acronym> 9 Security Considerations</th></tr>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<a accesskey="p" href="Bv9ARM.ch06.html">Prev</a>�</td>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<td width="20%" align="right">�<a accesskey="n" href="Bv9ARM.ch08.html">Next</a>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<a name="Bv9ARM.ch07"></a>Chapter�7.�<acronym class="acronym">BIND</acronym> 9 Security Considerations</h2></div></div></div>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<dt><span class="sect1"><a href="Bv9ARM.ch07.html#Access_Control_Lists">Access Control Lists</a></span></dt>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<dt><span class="sect1"><a href="Bv9ARM.ch07.html#id2603755"><span><strong class="command">Chroot</strong></span> and <span><strong class="command">Setuid</strong></span></a></span></dt>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<dt><span class="sect2"><a href="Bv9ARM.ch07.html#id2603905">The <span><strong class="command">chroot</strong></span> Environment</a></span></dt>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<dt><span class="sect2"><a href="Bv9ARM.ch07.html#id2603964">Using the <span><strong class="command">setuid</strong></span> Function</a></span></dt>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<dt><span class="sect1"><a href="Bv9ARM.ch07.html#dynamic_update_security">Dynamic Update Security</a></span></dt>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<div class="titlepage"><div><div><h2 class="title" style="clear: both">
45e9809aff7304721fddb95654901b32195c9c7avboxsync<a name="Access_Control_Lists"></a>Access Control Lists</h2></div></div></div>
45e9809aff7304721fddb95654901b32195c9c7avboxsync Access Control Lists (ACLs) are address match lists that
45e9809aff7304721fddb95654901b32195c9c7avboxsync you can set up and nickname for future use in <span><strong class="command">allow-notify</strong></span>,
45e9809aff7304721fddb95654901b32195c9c7avboxsync <span><strong class="command">allow-query</strong></span>, <span><strong class="command">allow-query-on</strong></span>,
45e9809aff7304721fddb95654901b32195c9c7avboxsync <span><strong class="command">allow-recursion</strong></span>, <span><strong class="command">allow-recursion-on</strong></span>,
45e9809aff7304721fddb95654901b32195c9c7avboxsync <span><strong class="command">blackhole</strong></span>, <span><strong class="command">allow-transfer</strong></span>,
45e9809aff7304721fddb95654901b32195c9c7avboxsync Using ACLs allows you to have finer control over who can access
45e9809aff7304721fddb95654901b32195c9c7avboxsync your name server, without cluttering up your config files with huge
45e9809aff7304721fddb95654901b32195c9c7avboxsync lists of IP addresses.
45e9809aff7304721fddb95654901b32195c9c7avboxsync It is a <span class="emphasis"><em>good idea</em></span> to use ACLs, and to
45e9809aff7304721fddb95654901b32195c9c7avboxsync control access to your server. Limiting access to your server by
45e9809aff7304721fddb95654901b32195c9c7avboxsync outside parties can help prevent spoofing and denial of service (DoS) attacks against
45e9809aff7304721fddb95654901b32195c9c7avboxsync your server.
45e9809aff7304721fddb95654901b32195c9c7avboxsync Here is an example of how to properly apply ACLs:
45e9809aff7304721fddb95654901b32195c9c7avboxsync// Set up an ACL named "bogusnets" that will block
45e9809aff7304721fddb95654901b32195c9c7avboxsync// RFC1918 space and some reserved space, which is
45e9809aff7304721fddb95654901b32195c9c7avboxsync// commonly used in spoofing attacks.
45e9809aff7304721fddb95654901b32195c9c7avboxsyncacl bogusnets {
45e9809aff7304721fddb95654901b32195c9c7avboxsync// Set up an ACL called our-nets. Replace this with the
45e9809aff7304721fddb95654901b32195c9c7avboxsync// real IP numbers.
45e9809aff7304721fddb95654901b32195c9c7avboxsync allow-query { our-nets; };
45e9809aff7304721fddb95654901b32195c9c7avboxsync allow-recursion { our-nets; };
45e9809aff7304721fddb95654901b32195c9c7avboxsync blackhole { bogusnets; };
45e9809aff7304721fddb95654901b32195c9c7avboxsync type master;
45e9809aff7304721fddb95654901b32195c9c7avboxsync allow-query { any; };
45e9809aff7304721fddb95654901b32195c9c7avboxsync This allows recursive queries of the server from the outside
45e9809aff7304721fddb95654901b32195c9c7avboxsync unless recursion has been previously disabled.
45e9809aff7304721fddb95654901b32195c9c7avboxsync For more information on how to use ACLs to protect your server,
45e9809aff7304721fddb95654901b32195c9c7avboxsync see the <span class="emphasis"><em>AUSCERT</em></span> advisory at:
45e9809aff7304721fddb95654901b32195c9c7avboxsync <a href="ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos" target="_top">ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos</a>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<div class="titlepage"><div><div><h2 class="title" style="clear: both">
45e9809aff7304721fddb95654901b32195c9c7avboxsync<a name="id2603755"></a><span><strong class="command">Chroot</strong></span> and <span><strong class="command">Setuid</strong></span>
45e9809aff7304721fddb95654901b32195c9c7avboxsync On UNIX servers, it is possible to run <acronym class="acronym">BIND</acronym>
45e9809aff7304721fddb95654901b32195c9c7avboxsync in a <span class="emphasis"><em>chrooted</em></span> environment (using
45e9809aff7304721fddb95654901b32195c9c7avboxsync the <span><strong class="command">chroot()</strong></span> function) by specifying
45e9809aff7304721fddb95654901b32195c9c7avboxsync the "<code class="option">-t</code>" option for <span><strong class="command">named</strong></span>.
45e9809aff7304721fddb95654901b32195c9c7avboxsync This can help improve system security by placing
45e9809aff7304721fddb95654901b32195c9c7avboxsync <acronym class="acronym">BIND</acronym> in a "sandbox", which will limit
45e9809aff7304721fddb95654901b32195c9c7avboxsync the damage done if a server is compromised.
45e9809aff7304721fddb95654901b32195c9c7avboxsync Another useful feature in the UNIX version of <acronym class="acronym">BIND</acronym> is the
45e9809aff7304721fddb95654901b32195c9c7avboxsync ability to run the daemon as an unprivileged user ( <code class="option">-u</code> <em class="replaceable"><code>user</code></em> ).
45e9809aff7304721fddb95654901b32195c9c7avboxsync We suggest running as an unprivileged user when using the <span><strong class="command">chroot</strong></span> feature.
45e9809aff7304721fddb95654901b32195c9c7avboxsync Here is an example command line to load <acronym class="acronym">BIND</acronym> in a <span><strong class="command">chroot</strong></span> sandbox,
45e9809aff7304721fddb95654901b32195c9c7avboxsync <span><strong class="command">/var/named</strong></span>, and to run <span><strong class="command">named</strong></span> <span><strong class="command">setuid</strong></span> to
45e9809aff7304721fddb95654901b32195c9c7avboxsync <strong class="userinput"><code>/usr/local/sbin/named -u 202 -t /var/named</code></strong>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<a name="id2603905"></a>The <span><strong class="command">chroot</strong></span> Environment</h3></div></div></div>
45e9809aff7304721fddb95654901b32195c9c7avboxsync In order for a <span><strong class="command">chroot</strong></span> environment
45e9809aff7304721fddb95654901b32195c9c7avboxsync work properly in a particular directory
45e9809aff7304721fddb95654901b32195c9c7avboxsync (for example, <code class="filename">/var/named</code>),
45e9809aff7304721fddb95654901b32195c9c7avboxsync you will need to set up an environment that includes everything
45e9809aff7304721fddb95654901b32195c9c7avboxsync <acronym class="acronym">BIND</acronym> needs to run.
45e9809aff7304721fddb95654901b32195c9c7avboxsync From <acronym class="acronym">BIND</acronym>'s point of view, <code class="filename">/var/named</code> is
45e9809aff7304721fddb95654901b32195c9c7avboxsync the root of the filesystem. You will need to adjust the values of
45e9809aff7304721fddb95654901b32195c9c7avboxsync options like
45e9809aff7304721fddb95654901b32195c9c7avboxsync like <span><strong class="command">directory</strong></span> and <span><strong class="command">pid-file</strong></span> to account
45e9809aff7304721fddb95654901b32195c9c7avboxsync Unlike with earlier versions of BIND, you typically will
45e9809aff7304721fddb95654901b32195c9c7avboxsync <span class="emphasis"><em>not</em></span> need to compile <span><strong class="command">named</strong></span>
45e9809aff7304721fddb95654901b32195c9c7avboxsync statically nor install shared libraries under the new root.
45e9809aff7304721fddb95654901b32195c9c7avboxsync However, depending on your operating system, you may need
45e9809aff7304721fddb95654901b32195c9c7avboxsync to set up things like
45e9809aff7304721fddb95654901b32195c9c7avboxsync<a name="id2603964"></a>Using the <span><strong class="command">setuid</strong></span> Function</h3></div></div></div>
45e9809aff7304721fddb95654901b32195c9c7avboxsync Prior to running the <span><strong class="command">named</strong></span> daemon,
45e9809aff7304721fddb95654901b32195c9c7avboxsync the <span><strong class="command">touch</strong></span> utility (to change file
45e9809aff7304721fddb95654901b32195c9c7avboxsync modification times) or the <span><strong class="command">chown</strong></span>
45e9809aff7304721fddb95654901b32195c9c7avboxsync utility (to
45e9809aff7304721fddb95654901b32195c9c7avboxsync to which you want <acronym class="acronym">BIND</acronym>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
45e9809aff7304721fddb95654901b32195c9c7avboxsync Note that if the <span><strong class="command">named</strong></span> daemon is running as an
45e9809aff7304721fddb95654901b32195c9c7avboxsync unprivileged user, it will not be able to bind to new restricted
45e9809aff7304721fddb95654901b32195c9c7avboxsync ports if the server is reloaded.
45e9809aff7304721fddb95654901b32195c9c7avboxsync<div class="titlepage"><div><div><h2 class="title" style="clear: both">
45e9809aff7304721fddb95654901b32195c9c7avboxsync<a name="dynamic_update_security"></a>Dynamic Update Security</h2></div></div></div>
45e9809aff7304721fddb95654901b32195c9c7avboxsync Access to the dynamic
45e9809aff7304721fddb95654901b32195c9c7avboxsync update facility should be strictly limited. In earlier versions of
45e9809aff7304721fddb95654901b32195c9c7avboxsync <acronym class="acronym">BIND</acronym>, the only way to do this was
45e9809aff7304721fddb95654901b32195c9c7avboxsync based on the IP
45e9809aff7304721fddb95654901b32195c9c7avboxsync address of the host requesting the update, by listing an IP address
45e9809aff7304721fddb95654901b32195c9c7avboxsync network prefix in the <span><strong class="command">allow-update</strong></span>
45e9809aff7304721fddb95654901b32195c9c7avboxsync zone option.
45e9809aff7304721fddb95654901b32195c9c7avboxsync This method is insecure since the source address of the update UDP
45e9809aff7304721fddb95654901b32195c9c7avboxsync is easily forged. Also note that if the IP addresses allowed by the
45e9809aff7304721fddb95654901b32195c9c7avboxsync <span><strong class="command">allow-update</strong></span> option include the
45e9809aff7304721fddb95654901b32195c9c7avboxsync address of a slave
45e9809aff7304721fddb95654901b32195c9c7avboxsync server which performs forwarding of dynamic updates, the master can
45e9809aff7304721fddb95654901b32195c9c7avboxsync trivially attacked by sending the update to the slave, which will
45e9809aff7304721fddb95654901b32195c9c7avboxsync forward it to the master with its own source IP address causing the
45e9809aff7304721fddb95654901b32195c9c7avboxsync master to approve it without question.
45e9809aff7304721fddb95654901b32195c9c7avboxsync For these reasons, we strongly recommend that updates be
45e9809aff7304721fddb95654901b32195c9c7avboxsync cryptographically authenticated by means of transaction signatures
45e9809aff7304721fddb95654901b32195c9c7avboxsync (TSIG). That is, the <span><strong class="command">allow-update</strong></span>
45e9809aff7304721fddb95654901b32195c9c7avboxsync option should
45e9809aff7304721fddb95654901b32195c9c7avboxsync list only TSIG key names, not IP addresses or network
45e9809aff7304721fddb95654901b32195c9c7avboxsync prefixes. Alternatively, the new <span><strong class="command">update-policy</strong></span>
45e9809aff7304721fddb95654901b32195c9c7avboxsync option can be used.
45e9809aff7304721fddb95654901b32195c9c7avboxsync Some sites choose to keep all dynamically-updated DNS data
45e9809aff7304721fddb95654901b32195c9c7avboxsync in a subdomain and delegate that subdomain to a separate zone. This
45e9809aff7304721fddb95654901b32195c9c7avboxsync way, the top-level zone containing critical data such as the IP
45e9809aff7304721fddb95654901b32195c9c7avboxsync of public web and mail servers need not allow dynamic update at
45e9809aff7304721fddb95654901b32195c9c7avboxsync<a accesskey="p" href="Bv9ARM.ch06.html">Prev</a>�</td>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<td width="40%" align="right">�<a accesskey="n" href="Bv9ARM.ch08.html">Next</a>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<td width="40%" align="left" valign="top">Chapter�6.�<acronym class="acronym">BIND</acronym> 9 Configuration Reference�</td>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
45e9809aff7304721fddb95654901b32195c9c7avboxsync<td width="40%" align="right" valign="top">�Chapter�8.�Troubleshooting</td>