
[[BIND9 20121215]]
*OS同梱のbindをportsのものに入れ替える [#a598d102]
2013-03-14 08:19:57


 root@ns1:/root # named -v
 BIND 9.8.3-P4
ports から最新のBIND をインストールする。このとき、make のオプションに "WITH_REPLACE_BASE=yes" を加えると、BASE の BIND を ports のものと完全に置き換えることが出来るが、これはお勧めしない。~
なぜなら、freebsd-update を実行する度に BASE の BIND に戻そうとするから。BASE と ports と両方インストールしておき、rc.conf で named のパスを指定することで使い分ける方法を採る。

 root@ns1:/root # portinstall dns/bind99

 *           _  _____ _____ _____ _   _ _____ ___ ___  _   _             *
 *          / \|_   _|_   _| ____| \ | |_   _|_ _/ _ \| \ | |            *
 *         / _ \ | |   | | |  _| |  \| | | |  | | | | |  \| |            *
 *        / ___ \| |   | | | |___| |\  | | |  | | |_| | |\  |            *
 *       /_/   \_\_|   |_| |_____|_| \_| |_| |___\___/|_| \_|            *
 *                                                                       *
 *       If you are running BIND 9 in a chroot environment, make         *
 *       sure that there is a /dev/random device in the chroot.          *
 *                                                                       *
 *       BIND 9 also requires configuration of rndc, including a         *
 *       "secret" key.  The easiest, and most secure way to configure    *
 *       rndc is to run 'rndc-confgen -a' to generate the proper conf    *
 *       file, with a new random key, and appropriate file permissions.  *
 *                                                                       *
 *       The /etc/rc.d/named script in the base will do both for you.    *
 *                                                                       *
 ===>   Compressing manual pages for bind99-
 ===>   Registering installation for bind99-
       This port has installed the following files which may act as network
       servers and may therefore pose a remote security risk to the system.
       If there are vulnerabilities in these programs there may be a security
       risk to the system. FreeBSD makes no guarantee about the security of
       ports included in the Ports Collection. Please type 'make deinstall'
       to deinstall the port if this is a concern.
       For more information, and contact details about the security
       status of this software, see the following webpage:
 ===>  Cleaning for bind99-
rndc.key を再生成する。
 # /usr/local/sbin/rndc-confgen -a -b 512 -k rndckey 

上記コマンドを実行したら、/etc/namedb/rndc.key というファイルが作成(上書き)されている.~
このとき、/usr/local/etc/rndc.key が /etc/namedb/rndc.key のシンボリックリンクとして作成される。~

続いて、/etc/rc.conf に以下の一文を追加。

しかる後に、BIND を再起動。明示的に停止した上で起動させる。

 # ps ax | grep named
   877  ??  Ss     0:02.21 /usr/sbin/syslogd -l /var/run/log -l /var/named/var/run/log -
  2033  ??  Is     1:54.54 /usr/sbin/named -t /var/named -u bind
 98231   0  S+     0:00.00 grep named
 # kill 2033
 # /usr/local/sbin/named -t /var/named -u bind
 # ps ax | grep named
   877  ??  Ss     0:02.38 /usr/sbin/syslogd -l /var/run/log -l /var/named/var/run/log -
 98235  ??  Ss     0:10.87 /usr/local/sbin/named -t /var/named -u bind
  6680   0  S+     0:00.00 grep named

 Nov 19 20:57:07 atom named[98235]: Warning: view local-zone: 'empty-zones-ena
 ble/disable-empty-zone' not set: disabling RFC 1918 empty zones
 Nov 19 20:57:07 atom named[98235]: command channel listening on
 Nov 19 20:57:07 atom named[98235]: managed-keys-zone ./IN/local-zone: loading 
 from master file 77705e291908193a368e1a63ec464c83c5519736a0faa4bc753d76fc79750
 a68.mkeys failed: file not found
 Nov 19 20:57:07 atom named[98235]: managed-keys-zone ./IN/external: loading fr
 om master file 3c4623849a49a53911c4a3e48d8cead8a1858960bccdea7a1b978d73ec2f06d
 7.mkeys failed: file not found

実用上は特に影響はないが、これを回避するには managed-keys.bind という名の空ファイルを作ってやればよい。
 # touch /etc/namedb/working/managed-keys.bind

 # named -v
 BIND 9.8.1-P1

トップ   新規 一覧 検索 最終更新   ヘルプ   最終更新のRSS