Fedora 43

BIND : Configure Chroot Environment2025/11/03

 

If you'd like to configure Chroot Environment for named, Set like follows.

[1] After setting Chroot environment, configuration files are placed under [/var/named/chroot].
[named.conf] is placed under [/var/named/chroot/etc/named.conf],
zone files are placed [/var/named/chroot/var/named/***].
When modify settings, Change them under [/var/named/chroot] files.
[root@dlp ~]#
dnf -y install bind-chroot
[root@dlp ~]#
mkdir /var/named/chroot/usr/lib64/named

[root@dlp ~]#
/usr/libexec/setup-named-chroot.sh /var/named/chroot on
[root@dlp ~]#
systemctl disable --now named

[root@dlp ~]#
systemctl enable --now named-chroot

Created symlink /etc/systemd/system/multi-user.target.wants/named-chroot.service → /usr/lib/systemd/system/named-chroot.service.
[root@dlp ~]#
ll /var/named/chroot/etc

total 720
drwxr-x---. 3 root named     23 Nov  3 10:10 crypto-policies
-rw-r--r--. 2 root root     309 Jul 29 09:00 localtime
drwxr-x---. 2 root named      6 Oct 24 09:00 named
-rw-r--r--. 1 root named   3314 Oct 24 09:00 named.ca
-rw-r-----. 1 root named   2392 Nov  3 10:02 named.conf
-rw-r-----. 1 root named   1137 Oct 24 09:00 named.rfc1912.zones
-rw-r--r--. 1 root named   1066 Oct 24 09:00 named.root.key
drwxr-x---. 3 root named     25 Nov  3 10:10 pki
-rw-r--r--. 1 root root    6963 Jul 25 09:00 protocols
-rw-r-----. 1 root named    100 Nov  3 09:58 rndc.key
-rw-r--r--. 1 root root  701707 Jul 25 09:00 services

[root@dlp ~]#
ll /var/named/chroot/var/named

total 8
-rw-r--r--. 1 root  root  384 Nov  3 09:57 0.0.10.db
drwxr-x---. 8 root  named  73 Nov  3 10:10 chroot
drwxrwx---. 2 named named  23 Nov  3 09:58 data
drwxrwx---. 2 named named 108 Nov  3 10:06 dynamic
lrwxrwxrwx. 1 root  named  18 Oct 24 09:00 named.ca -> ../../etc/named.ca
lrwxrwxrwx. 1 root  named  33 Oct 24 09:00 named.empty -> ../../usr/share/named/named.empty
lrwxrwxrwx. 1 root  named  37 Oct 24 09:00 named.localhost -> ../../usr/share/named/named.localhost
lrwxrwxrwx. 1 root  named  36 Oct 24 09:00 named.loopback -> ../../usr/share/named/named.loopback
drwxrwx---. 2 named named   6 Oct 24 09:00 slaves
-rw-r--r--. 1 root  root  683 Nov  3 10:05 srv.world.lan
Matched Content