Re: BIND vs. mac_portacl

2005-07-05 Thread Kövesdán Gábor
David Malone wrote: If you don't actually want to use IPv6, you could give explicit addresses to named using the listen-on and query-source directives. Alternatively, a kernel without IPv6 might work. I don't have IPv6 support in the kernel. Anyway, I tried to set those directives in named.c

Re: BIND vs. mac_portacl

2005-07-04 Thread David Malone
On Tue, Jul 05, 2005 at 12:17:40AM +0200, K?vesd?n G?bor wrote: > The bind user has the uid 55. I've added a rule for it, as You can see, > but it doesn't help. I get this error with the ruleset can be seen > above, and also without any rules. But apache works. It can change to > the www user. P

BIND vs. mac_portacl

2005-07-04 Thread Kövesdán Gábor
Hello, I've loaded the mac_portacl module but BIND doesn't properly work with it. My sysctl values: net.inet.ip.portrange.reservedlow: 0 net.inet.ip.portrange.reservedhigh: 0 security.mac.portacl.rules: uid:55:tcp:53,uid:55:udp:53,uid:55:tcp:953,uid:55:udp:953 security.mac.portacl.port_high: