October 10th, 2006 | #2 |
Ubuntu Extra Shot Join Date: Jun 2006 Location: Horsham, UK Posts: 394 Thanks: 0 Thanked 1 Time in 1 Post | Re: bind permission denied for jnl file reposted in server thread as i feel that was more approprate. sorry for double post. Twiggy |
April 24th, 2008 | #3 |
First Cup of Ubuntu Join Date: May 2006 Posts: 5 Thanks: 0 Thanked 1 Time in 1 Post | Re: bind permission denied for jnl file After much hair pulling over several months I finally got to the problem. My DNS and DHCP files were OK and always had been. I finally tracked down an kernel audit message kernel: audit(1209076817.081:16): type=1503 operation="inode_create" requested_mask="w::" denied_mask="w::" name="/etc/bind/xxxxx.com.hosts.jnl" pid=16561 profile="/usr/sbin/named" namespace="default" So I had a look in: /etc/apparmor.d/usr.sbin.named and changed this line: /etc/bind/** r, to this: /etc/bind/** rw, End of problems |
April 25th, 2008 | #4 |
Ubuntu Extra Shot Join Date: Jun 2006 Location: Horsham, UK Posts: 394 Thanks: 0 Thanked 1 Time in 1 Post | Re: bind permission denied for jnl file HUH!!! is the a dodgy post???? __________________ Compaq HP Proliant 5500 quad 550MHZ 500MB cache 1.5GB Ram Shes my baby but doesn't she make a Load of noise!!! www.houseofhawkins.com - My development site with bits and bobs on |
May 25th, 2008 | #5 | |
A Carafe of Ubuntu Join Date: Jun 2007 Location: Zimbabwe Posts: 143 Thanks: 3 Thanked 3 Times in 2 Posts | Re: bind permission denied for jnl file Quote:
Since I'm also running this in a fairly "closed" environment, I've just done what you suggested, and yes it solves the problem for me. However, this might not be the correct route to follow on a public server. As stated in usr.sbin.named comments, /etc/bind should be read only to bind and dynamic zones as well as journal files should be stored in /var/lib/bind/, which already has rw permissions set for bind. However, dynamic zones and journal files seem to be stored in /etc/bind/ by default. So ideally, you'd want to change this location to /var/lib/bind. I would assume this has been done for security reasons. __________________ Powered by Linux ~~ and coffee ~~ Promoting Ubuntu in Zimbabwe: http://www.ubuntu-zw.org | |
Nenhum comentário:
Postar um comentário