Bv9ARM.ch07.html revision f39512a917cdd06c611d366603374f6ef570c80e
a4544a5a0e622ef69e38641f87ab1b5685e05911Phill Cunnington<!--
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Copyright (C) 2004-2014 Internet Systems Consortium, Inc. ("ISC")
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Copyright (C) 2000-2003 Internet Software Consortium.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster -
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Permission to use, copy, modify, and/or distribute this software for any
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - purpose with or without fee is hereby granted, provided that the above
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - copyright notice and this permission notice appear in all copies.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster -
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - PERFORMANCE OF THIS SOFTWARE.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster-->
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<!-- $Id$ -->
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<html>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<head>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<title>Chapter�7.�BIND 9 Security Considerations</title>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="prev" href="Bv9ARM.ch06.html" title="Chapter�6.�BIND 9 Configuration Reference">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="next" href="Bv9ARM.ch08.html" title="Chapter�8.�Troubleshooting">
a4544a5a0e622ef69e38641f87ab1b5685e05911Phill Cunnington</head>
2ae2afec49bee3701557e9761a0a03bc7cab3bb3Kohei Tamura<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
2ae2afec49bee3701557e9761a0a03bc7cab3bb3Kohei Tamura<div class="navheader">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<table width="100%" summary="Navigation header">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr><th colspan="3" align="center">Chapter�7.�<acronym class="acronym">BIND</acronym> 9 Security Considerations</th></tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr>
92813213f3a80b0a65195e59993b49b66d160f69Peter Major<td width="20%" align="left">
92813213f3a80b0a65195e59993b49b66d160f69Peter Major<a accesskey="p" href="Bv9ARM.ch06.html">Prev</a>�</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<th width="60%" align="center">�</th>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="right">�<a accesskey="n" href="Bv9ARM.ch08.html">Next</a>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</table>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<hr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="chapter" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="titlepage"><div><div><h2 class="title">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="Bv9ARM.ch07"></a>Chapter�7.�<acronym class="acronym">BIND</acronym> 9 Security Considerations</h2></div></div></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="toc">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><b>Table of Contents</b></p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dl>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="sect1"><a href="Bv9ARM.ch07.html#Access_Control_Lists">Access Control Lists</a></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="sect1"><a href="Bv9ARM.ch07.html#id2606360"><span><strong class="command">Chroot</strong></span> and <span><strong class="command">Setuid</strong></span></a></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><dl>
8d3140b524c0e28c0a49dc7c7d481123ef3cfe11Chris Lee<dt><span class="sect2"><a href="Bv9ARM.ch07.html#id2606509">The <span><strong class="command">chroot</strong></span> Environment</a></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="sect2"><a href="Bv9ARM.ch07.html#id2606569">Using the <span><strong class="command">setuid</strong></span> Function</a></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dl></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="sect1"><a href="Bv9ARM.ch07.html#dynamic_update_security">Dynamic Update Security</a></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dl>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="sect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="titlepage"><div><div><h2 class="title" style="clear: both">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="Access_Control_Lists"></a>Access Control Lists</h2></div></div></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Access Control Lists (ACLs) are address match lists that
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster you can set up and nickname for future use in <span><strong class="command">allow-notify</strong></span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">allow-query</strong></span>, <span><strong class="command">allow-query-on</strong></span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">allow-recursion</strong></span>, <span><strong class="command">allow-recursion-on</strong></span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">blackhole</strong></span>, <span><strong class="command">allow-transfer</strong></span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster etc.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Using ACLs allows you to have finer control over who can access
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster your name server, without cluttering up your config files with huge
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster lists of IP addresses.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster It is a <span class="emphasis"><em>good idea</em></span> to use ACLs, and to
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster control access to your server. Limiting access to your server by
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster outside parties can help prevent spoofing and denial of service (DoS) attacks against
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster your server.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Here is an example of how to properly apply ACLs:
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<pre class="programlisting">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster// Set up an ACL named "bogusnets" that will block
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster// RFC1918 space and some reserved space, which is
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster// commonly used in spoofing attacks.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosteracl bogusnets {
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster 0.0.0.0/8; 192.0.2.0/24; 224.0.0.0/3;
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster 10.0.0.0/8; 172.16.0.0/12; 192.168.0.0/16;
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster};
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster// Set up an ACL called our-nets. Replace this with the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster// real IP numbers.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosteracl our-nets { x.x.x.x/24; x.x.x.x/21; };
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosteroptions {
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ...
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ...
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster allow-query { our-nets; };
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster allow-recursion { our-nets; };
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ...
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster blackhole { bogusnets; };
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ...
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster};
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterzone "example.com" {
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster type master;
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster file "m/example.com";
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster allow-query { any; };
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster};
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</pre>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster This allows recursive queries of the server from the outside
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster unless recursion has been previously disabled.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="sect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="titlepage"><div><div><h2 class="title" style="clear: both">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2606360"></a><span><strong class="command">Chroot</strong></span> and <span><strong class="command">Setuid</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</h2></div></div></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster On UNIX servers, it is possible to run <acronym class="acronym">BIND</acronym>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster in a <span class="emphasis"><em>chrooted</em></span> environment (using
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster the <span><strong class="command">chroot()</strong></span> function) by specifying
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster the "<code class="option">-t</code>" option for <span><strong class="command">named</strong></span>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster This can help improve system security by placing
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <acronym class="acronym">BIND</acronym> in a "sandbox", which will limit
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster the damage done if a server is compromised.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Another useful feature in the UNIX version of <acronym class="acronym">BIND</acronym> is the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ability to run the daemon as an unprivileged user ( <code class="option">-u</code> <em class="replaceable"><code>user</code></em> ).
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster We suggest running as an unprivileged user when using the <span><strong class="command">chroot</strong></span> feature.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Here is an example command line to load <acronym class="acronym">BIND</acronym> in a <span><strong class="command">chroot</strong></span> sandbox,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">/var/named</strong></span>, and to run <span><strong class="command">named</strong></span> <span><strong class="command">setuid</strong></span> to
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster user 202:
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <strong class="userinput"><code>/usr/local/sbin/named -u 202 -t /var/named</code></strong>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="sect2" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="titlepage"><div><div><h3 class="title">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2606509"></a>The <span><strong class="command">chroot</strong></span> Environment</h3></div></div></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster In order for a <span><strong class="command">chroot</strong></span> environment
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster work properly in a particular directory
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster (for example, <code class="filename">/var/named</code>),
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster you will need to set up an environment that includes everything
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <acronym class="acronym">BIND</acronym> needs to run.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster From <acronym class="acronym">BIND</acronym>'s point of view, <code class="filename">/var/named</code> is
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster the root of the filesystem. You will need to adjust the values of
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster options like
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster like <span><strong class="command">directory</strong></span> and <span><strong class="command">pid-file</strong></span> to account
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster for this.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Unlike with earlier versions of BIND, you typically will
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span class="emphasis"><em>not</em></span> need to compile <span><strong class="command">named</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster statically nor install shared libraries under the new root.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster However, depending on your operating system, you may need
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to set up things like
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="filename">/dev/zero</code>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="filename">/dev/random</code>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="filename">/dev/log</code>, and
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="filename">/etc/localtime</code>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="sect2" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="titlepage"><div><div><h3 class="title">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2606569"></a>Using the <span><strong class="command">setuid</strong></span> Function</h3></div></div></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Prior to running the <span><strong class="command">named</strong></span> daemon,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster use
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster the <span><strong class="command">touch</strong></span> utility (to change file
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster access and
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster modification times) or the <span><strong class="command">chown</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster utility (to
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster set the user id and/or group id) on files
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to which you want <acronym class="acronym">BIND</acronym>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to write.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<h3 class="title">Note</h3>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Note that if the <span><strong class="command">named</strong></span> daemon is running as an
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster unprivileged user, it will not be able to bind to new restricted
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ports if the server is reloaded.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="sect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="titlepage"><div><div><h2 class="title" style="clear: both">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="dynamic_update_security"></a>Dynamic Update Security</h2></div></div></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Access to the dynamic
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster update facility should be strictly limited. In earlier versions of
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <acronym class="acronym">BIND</acronym>, the only way to do this was
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster based on the IP
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster address of the host requesting the update, by listing an IP address
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster or
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster network prefix in the <span><strong class="command">allow-update</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster zone option.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster This method is insecure since the source address of the update UDP
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster packet
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster is easily forged. Also note that if the IP addresses allowed by the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">allow-update</strong></span> option include the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster address of a slave
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster server which performs forwarding of dynamic updates, the master can
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster be
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster trivially attacked by sending the update to the slave, which will
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster forward it to the master with its own source IP address causing the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster master to approve it without question.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster For these reasons, we strongly recommend that updates be
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster cryptographically authenticated by means of transaction signatures
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster (TSIG). That is, the <span><strong class="command">allow-update</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster option should
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster list only TSIG key names, not IP addresses or network
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster prefixes. Alternatively, the new <span><strong class="command">update-policy</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster option can be used.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Some sites choose to keep all dynamically-updated DNS data
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster in a subdomain and delegate that subdomain to a separate zone. This
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster way, the top-level zone containing critical data such as the IP
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster addresses
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster of public web and mail servers need not allow dynamic update at
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster all.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="navfooter">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<hr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<table width="100%" summary="Navigation footer">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="left">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a accesskey="p" href="Bv9ARM.ch06.html">Prev</a>�</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="center">�</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="right">�<a accesskey="n" href="Bv9ARM.ch08.html">Next</a>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="left" valign="top">Chapter�6.�<acronym class="acronym">BIND</acronym> 9 Configuration Reference�</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="right" valign="top">�Chapter�8.�Troubleshooting</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</table>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</body>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</html>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster