public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] Secure DNS servers
@ 2014-06-16 18:15 James
  2014-06-16 18:49 ` Michael Orlitzky
  2014-06-16 20:10 ` thegeezer
  0 siblings, 2 replies; 12+ messages in thread
From: James @ 2014-06-16 18:15 UTC (permalink / raw
  To: gentoo-user

Hello,

I'm reading up on how to secure DNS primary and secondary servers.
I guess DNSSEC is pretty important. Any other areas I should read
up on?  It's been a few years since I admin'd a dns server....


Also, look for gentoo centric  DNS primary solutions, I see
no mention of hardened, up-mounted or read only partitions, 
etc etc. I wondering if anyone has some general suggestions 
on how to keep a gentoo dns primary only machine secure.

The iptables suggests seem trite and old.  I'll not
be running anything but DNS primary on the machine. When it
is up, I want to test it and see if it can be hacked, by me.
So  a listing of "how to hack-test" your DNS primary server
of ideas would be keen too.


I wonder why the gentoo wiki does not have such information, as 
I'm sure it is commonly needed?

Any other thoughts, suggestions and ideas are most appreciated,
as I have not kept current with all of the latest dns security
issues. I cannot even find a listing of security issues, that
are strictly centric to DNS primary server issues.


James





^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2014-06-17 20:41 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-06-16 18:15 [gentoo-user] Secure DNS servers James
2014-06-16 18:49 ` Michael Orlitzky
2014-06-16 19:57   ` [gentoo-user] " James
2014-06-16 20:26     ` thegeezer
2014-06-16 21:40     ` Michael Orlitzky
2014-06-17 14:48     ` Eray Aslan
2014-06-17 20:40       ` Alan McKinnon
2014-06-16 20:59   ` [gentoo-user] " Rich Freeman
2014-06-16 20:10 ` thegeezer
2014-06-16 21:08   ` [gentoo-user] " James
2014-06-16 22:06     ` thegeezer
2014-06-17  1:29       ` James

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox