[Opendnssec-user] bad perms

Randy Bush randy at psg.com
Sat Jul 8 21:00:02 UTC 2023


freebsd 13.1 fully up to date
opendnssec version 2.1.13
bind  "9.16.42"

    rip.psg.com:/usr/home/dns# dig @localhost psg.com. a 

    ; <<>> DiG 9.18.16 <<>> @localhost psg.com. a
    ; (2 servers found)
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 1669
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

    ;; OPT PSEUDOSECTION:
    ; EDNS: version: 0, flags:; udp: 1232
    ; COOKIE: 08a164ab319991760100000064a9cb3269d768b7b43df337 (good)
    ;; QUESTION SECTION:
    ;psg.com.                       IN      A

    ;; Query time: 0 msec
    ;; SERVER: ::1#53(localhost) (UDP)
    ;; WHEN: Sat Jul 08 20:46:42 UTC 2023
    ;; MSG SIZE  rcvd: 64

all signed zones have undestirable perms

    -rw-r--r--  1 bind        staff          865 Jul  3  2011 com.luluvertus
    -rw-r--r--  1 bind        staff         1056 Feb  7  2018 com.pathguy
    -rw-r--r--  1 bind        staff         1055 Jan 30  2018 com.pathguy~
    -rw-------  1 opendnssec  opendnssec   64392 Jul  8 20:16 com.psg
    -rw-r--r--  1 bind        staff          827 Feb 11  2013 com.ruedesvertus
    -rw-r--r--  1 bind        staff          801 Jan  5  2013 com.salmabezzir
    -rw-------  1 opendnssec  opendnssec    7013 Jul  8 20:16 com.ymbk
    -rw-r--r--  1 opendnssec  opendnssec  409523 Jul  8 20:51 gn

whoops.

suggesting on how to fix long term

randy


More information about the Opendnssec-user mailing list