1N/A - Copyright (C) 2004-2013 Internet Systems Consortium, Inc. ("ISC") 1N/A - Copyright (C) 2000-2003 Internet Software Consortium. 1N/A - Permission to use, copy, modify, and/or distribute this software for any 1N/A - purpose with or without fee is hereby granted, provided that the above 1N/A - copyright notice and this permission notice appear in all copies. 1N/A - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH 1N/A - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY 1N/A - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT, 1N/A - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM 1N/A - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE 1N/A - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR 1N/A - PERFORMANCE OF THIS SOFTWARE. 1N/A<
meta http-
equiv="Content-Type" content="text/html; charset=ISO-8859-1">
1N/A<
title>Chapter�7.�BIND 9 Security Considerations</
title>
1N/A<
meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
1N/A<
link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
1N/A<
link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
1N/A<
body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
1N/A<
div class="navheader">
1N/A<
table width="100%" summary="Navigation header">
1N/A<
tr><
th colspan="3" align="center">Chapter�7.�<
acronym class="acronym">BIND</
acronym> 9 Security Considerations</
th></
tr>
1N/A<
td width="20%" align="left">
1N/A<
th width="60%" align="center">�</
th>
1N/A<
div class="chapter" lang="en">
1N/A<
div class="titlepage"><
div><
div><
h2 class="title">
1N/A<
a name="Bv9ARM.ch07"></
a>Chapter�7.�<
acronym class="acronym">BIND</
acronym> 9 Security Considerations</
h2></
div></
div></
div>
1N/A<
p><
b>Table of Contents</
b></
p>
1N/A<
dt><
span class="sect1"><
a href="Bv9ARM.ch07.html#Access_Control_Lists">Access Control Lists</
a></
span></
dt>
1N/A<
dt><
span class="sect1"><
a href="Bv9ARM.ch07.html#id2605517"><
span><
strong class="command">Chroot</
strong></
span> and <
span><
strong class="command">Setuid</
strong></
span></
a></
span></
dt>
1N/A<
dt><
span class="sect2"><
a href="Bv9ARM.ch07.html#id2605598">The <
span><
strong class="command">chroot</
strong></
span> Environment</
a></
span></
dt>
1N/A<
dt><
span class="sect2"><
a href="Bv9ARM.ch07.html#id2605658">Using the <
span><
strong class="command">setuid</
strong></
span> Function</
a></
span></
dt>
1N/A<
dt><
span class="sect1"><
a href="Bv9ARM.ch07.html#dynamic_update_security">Dynamic Update Security</
a></
span></
dt>
1N/A<
div class="sect1" lang="en">
1N/A<
div class="titlepage"><
div><
div><
h2 class="title" style="clear: both">
1N/A<
a name="Access_Control_Lists"></
a>Access Control Lists</
h2></
div></
div></
div>
1N/A Access Control Lists (ACLs) are address match lists that
1N/A you can set up and nickname for future use in <
span><
strong class="command">allow-notify</
strong></
span>,
1N/A <
span><
strong class="command">allow-query</
strong></
span>, <
span><
strong class="command">allow-query-on</
strong></
span>,
1N/A <
span><
strong class="command">allow-recursion</
strong></
span>, <
span><
strong class="command">allow-recursion-on</
strong></
span>,
1N/A <
span><
strong class="command">blackhole</
strong></
span>, <
span><
strong class="command">allow-transfer</
strong></
span>,
1N/A Using ACLs allows you to have finer control over who can access
1N/A your name server, without cluttering up your config files with huge
1N/A lists of IP addresses.
1N/A It is a <
span class="emphasis"><
em>good idea</
em></
span> to use ACLs, and to
1N/A control access to your server. Limiting access to your server by
1N/A outside parties can help prevent spoofing and denial of service (DoS) attacks against
1N/A Here is an example of how to properly apply ACLs:
1N/A<
pre class="programlisting">
1N/A// Set up an ACL named "bogusnets" that will block
1N/A// RFC1918 space and some reserved space, which is
1N/A// commonly used in spoofing attacks.
1N/A// Set up an ACL called our-nets. Replace this with the
1N/A allow-query { our-nets; };
1N/A allow-recursion { our-nets; };
1N/A blackhole { bogusnets; };
1N/A allow-query { any; };
1N/A This allows recursive queries of the server from the outside
1N/A unless recursion has been previously disabled.
1N/A<
div class="sect1" lang="en">
1N/A<
div class="titlepage"><
div><
div><
h2 class="title" style="clear: both">
1N/A<
a name="id2605517"></
a><
span><
strong class="command">Chroot</
strong></
span> and <
span><
strong class="command">Setuid</
strong></
span>
1N/A</
h2></
div></
div></
div>
1N/A On UNIX servers, it is possible to run <
acronym class="acronym">BIND</
acronym>
1N/A in a <
span class="emphasis"><
em>chrooted</
em></
span> environment (using
1N/A the <
span><
strong class="command">chroot()</
strong></
span> function) by specifying
1N/A the "<
code class="option">-t</
code>" option for <
span><
strong class="command">named</
strong></
span>.
1N/A This can help improve system security by placing
1N/A <
acronym class="acronym">BIND</
acronym> in a "sandbox", which will limit
1N/A the damage done if a server is compromised.
1N/A Another useful feature in the UNIX version of <
acronym class="acronym">BIND</
acronym> is the
1N/A ability to run the daemon as an unprivileged user ( <
code class="option">-u</
code> <
em class="replaceable"><
code>user</
code></
em> ).
1N/A We suggest running as an unprivileged user when using the <
span><
strong class="command">chroot</
strong></
span> feature.
1N/A Here is an example command line to load <
acronym class="acronym">BIND</
acronym> in a <
span><
strong class="command">chroot</
strong></
span> sandbox,
1N/A <
span><
strong class="command">/
var/
named</
strong></
span>, and to run <
span><
strong class="command">named</
strong></
span> <
span><
strong class="command">setuid</
strong></
span> to
1N/A<
div class="sect2" lang="en">
1N/A<
div class="titlepage"><
div><
div><
h3 class="title">
1N/A<
a name="id2605598"></
a>The <
span><
strong class="command">chroot</
strong></
span> Environment</
h3></
div></
div></
div>
1N/A In order for a <
span><
strong class="command">chroot</
strong></
span> environment
1N/A work properly in a particular directory
1N/A (for example, <
code class="filename">/
var/
named</
code>),
1N/A you will need to set up an environment that includes everything
1N/A <
acronym class="acronym">BIND</
acronym> needs to run.
1N/A From <
acronym class="acronym">BIND</
acronym>'s point of view, <
code class="filename">/
var/
named</
code> is
1N/A the root of the filesystem. You will need to adjust the values of
1N/A like <
span><
strong class="command">directory</
strong></
span> and <
span><
strong class="command">pid-file</
strong></
span> to account
1N/A Unlike with earlier versions of BIND, you typically will
1N/A <
span class="emphasis"><
em>not</
em></
span> need to compile <
span><
strong class="command">named</
strong></
span>
1N/A statically nor install shared libraries under the new root.
1N/A However, depending on your operating system, you may need
1N/A to set up things like
1N/A<
div class="sect2" lang="en">
1N/A<
div class="titlepage"><
div><
div><
h3 class="title">
1N/A<
a name="id2605658"></
a>Using the <
span><
strong class="command">setuid</
strong></
span> Function</
h3></
div></
div></
div>
1N/A Prior to running the <
span><
strong class="command">named</
strong></
span> daemon,
1N/A the <
span><
strong class="command">touch</
strong></
span> utility (to change file
1N/A modification times) or the <
span><
strong class="command">chown</
strong></
span>
1N/A set the user id
and/
or group id) on files
1N/A to which you want <
acronym class="acronym">BIND</
acronym>
1N/A<
div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
1N/A<
h3 class="title">Note</
h3>
1N/A Note that if the <
span><
strong class="command">named</
strong></
span> daemon is running as an
1N/A unprivileged user, it will not be able to bind to new restricted
1N/A ports if the server is reloaded.
1N/A<
div class="sect1" lang="en">
1N/A<
div class="titlepage"><
div><
div><
h2 class="title" style="clear: both">
1N/A<
a name="dynamic_update_security"></
a>Dynamic Update Security</
h2></
div></
div></
div>
1N/A Access to the dynamic
1N/A update facility should be strictly limited. In earlier versions of
1N/A <
acronym class="acronym">BIND</
acronym>, the only way to do this was
1N/A address of the host requesting the update, by listing an IP address
1N/A network prefix in the <
span><
strong class="command">allow-update</
strong></
span>
1N/A This method is insecure since the source address of the update UDP
1N/A is easily forged. Also note that if the IP addresses allowed by the
1N/A <
span><
strong class="command">allow-update</
strong></
span> option include the
1N/A server which performs forwarding of dynamic updates, the master can
1N/A trivially attacked by sending the update to the slave, which will
1N/A forward it to the master with its own source IP address causing the
1N/A master to approve it without question.
1N/A For these reasons, we strongly recommend that updates be
1N/A cryptographically authenticated by means of transaction signatures
1N/A (TSIG). That is, the <
span><
strong class="command">allow-update</
strong></
span>
1N/A list only TSIG key names, not IP addresses or network
1N/A prefixes. Alternatively, the new <
span><
strong class="command">update-policy</
strong></
span>
1N/A Some sites choose to keep all dynamically-updated DNS data
1N/A in a subdomain and delegate that subdomain to a separate zone. This
1N/A way, the top-level zone containing critical data such as the IP
1N/A of public web and mail servers need not allow dynamic update at
1N/A<
div class="navfooter">
1N/A<
table width="100%" summary="Navigation footer">
1N/A<
td width="40%" align="left">
1N/A<
td width="20%" align="center">�</
td>
1N/A<
td width="40%" align="left" valign="top">Chapter�6.�<
acronym class="acronym">BIND</
acronym> 9 Configuration Reference�</
td>
1N/A<
td width="20%" align="center"><
a accesskey="h" href="Bv9ARM.html">Home</
a></
td>
<
td width="40%" align="right" valign="top">�Chapter�8.�Troubleshooting</
td>