mirror of
https://github.com/NLnetLabs/unbound.git
synced 2025-12-20 23:00:56 -05:00
- Document write permission to directory of trust anchor needed.
git-svn-id: file:///svn/unbound/trunk@3730 be551aaa-1e26-0410-a405-d3ace91eadb9
This commit is contained in:
parent
cffec5e0fe
commit
709d450bd7
2 changed files with 4 additions and 1 deletions
|
|
@ -1,6 +1,7 @@
|
||||||
27 May 2016: Wouter
|
27 May 2016: Wouter
|
||||||
- Fix #770: Small subgroup attack on DH used in unix pipe on localhost
|
- Fix #770: Small subgroup attack on DH used in unix pipe on localhost
|
||||||
if unbound control uses a unix local named pipe.
|
if unbound control uses a unix local named pipe.
|
||||||
|
- Document write permission to directory of trust anchor needed.
|
||||||
|
|
||||||
26 May 2016: Wouter
|
26 May 2016: Wouter
|
||||||
- Updated patch from Charles Walker.
|
- Updated patch from Charles Walker.
|
||||||
|
|
|
||||||
|
|
@ -706,7 +706,9 @@ File with trust anchor for one zone, which is tracked with RFC5011 probes.
|
||||||
The probes are several times per month, thus the machine must be online
|
The probes are several times per month, thus the machine must be online
|
||||||
frequently. The initial file can be one with contents as described in
|
frequently. The initial file can be one with contents as described in
|
||||||
\fBtrust\-anchor\-file\fR. The file is written to when the anchor is updated,
|
\fBtrust\-anchor\-file\fR. The file is written to when the anchor is updated,
|
||||||
so the unbound user must have write permission.
|
so the unbound user must have write permission. Write permission to the file,
|
||||||
|
but also to the directory it is in (to create a temporary file, which is
|
||||||
|
necessary to deal with filesystem full events).
|
||||||
.TP
|
.TP
|
||||||
.B trust\-anchor: \fI<"Resource Record">
|
.B trust\-anchor: \fI<"Resource Record">
|
||||||
A DS or DNSKEY RR for a key to use for validation. Multiple entries can be
|
A DS or DNSKEY RR for a key to use for validation. Multiple entries can be
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue