76074cd
From 3a161af91bffcd457586ab466e32ac8484028763 Mon Sep 17 00:00:00 2001
b8ccda0
From: Petr Mensik <pemensik@redhat.com>
b8ccda0
Date: Wed, 17 Jun 2020 23:17:13 +0200
b8ccda0
Subject: [PATCH] Update man named with Red Hat specifics
b8ccda0
b8ccda0
This is almost unmodified text and requires revalidation. Some of those
b8ccda0
statements are no longer correct.
b8ccda0
---
76074cd
 bin/named/named.rst | 35 +++++++++++++++++++++++++++++++++++
76074cd
 1 file changed, 35 insertions(+)
b8ccda0
b8ccda0
diff --git a/bin/named/named.rst b/bin/named/named.rst
76074cd
index 6fd8f87..3cd6350 100644
b8ccda0
--- a/bin/named/named.rst
b8ccda0
+++ b/bin/named/named.rst
76074cd
@@ -228,6 +228,41 @@ Files
b8ccda0
 ``/var/run/named/named.pid``
b8ccda0
    The default process-id file.
b8ccda0
 
b8ccda0
+Notes
b8ccda0
+~~~~~
b8ccda0
+
b8ccda0
+**Red Hat SELinux BIND Security Profile:**
b8ccda0
+
b8ccda0
+By default, Red Hat ships BIND with the most secure SELinux policy
b8ccda0
+that will not prevent normal BIND operation and will prevent exploitation
76074cd
+of all known BIND security vulnerabilities. See the selinux(8) man page
b8ccda0
+for information about SElinux.
b8ccda0
+
b8ccda0
+It is not necessary to run named in a chroot environment if the Red Hat
b8ccda0
+SELinux policy for named is enabled. When enabled, this policy is far
b8ccda0
+more secure than a chroot environment. Users are recommended to enable
b8ccda0
+SELinux and remove the bind-chroot package.
b8ccda0
+
b8ccda0
+*With this extra security comes some restrictions:*
b8ccda0
+
76074cd
+By default, the SELinux policy does not allow named to write outside directory
76074cd
+/var/named. That directory used to be read-only for named, but write access is
76074cd
+enabled by default now.
b8ccda0
+
b8ccda0
+The "named" group must be granted read privelege to
b8ccda0
+these files in order for named to be enabled to read them.
76074cd
+Any file updated by named must be writeable by named user or named group.
b8ccda0
+
b8ccda0
+Any file created in the zone database file directory is automatically assigned
b8ccda0
+the SELinux file context *named_zone_t* .
b8ccda0
+
b8ccda0
+The Red Hat BIND distribution and SELinux policy creates three directories where
76074cd
+named were allowed to create and modify files: */var/named/slaves*, */var/named/dynamic*
76074cd
+*/var/named/data*. The service is able to write and file under */var/named* with appropriate
76074cd
+permissions. They are used for better organisation of zones and backward compatibility.
76074cd
+Files in these directories are automatically assigned the '*named_cache_t*'
76074cd
+file context, which SELinux always allows named to write.
b8ccda0
+
b8ccda0
 See Also
b8ccda0
 ~~~~~~~~
b8ccda0
 
b8ccda0
-- 
b8ccda0
2.26.2
b8ccda0