Can someone give me some pointers or help?
I'm trying to get Bind9 to run in a chrooted environment.
The service runs fine as is, but when I move it to a chroot jail, I can't start it anymore.
Error messages during starting.
Config changes to get chroot working1 gauloises kernel: [180942.452046] audit(1217451274.744:5): type=1503 operation="inode_permission" requested_mask="::r" denied_mask="::r" name="/var/chroot/named/etc/localtime" pid=14130 profile="/usr/sbin/named" namespace="default"
1 gauloises kernel: [180942.453222] audit(1217451274.748:6): type=1503 operation="inode_permission" requested_mask="::r" denied_mask="::r" name="/var/chroot/named/etc/localtime" pid=14130 profile="/usr/sbin/named" namespace="default"
1 gauloises named: none:0: open: /etc/bind/named.conf: permission denied
1 gauloises named: loading configuration: permission denied
1 gauloises kernel: [180942.460655] audit(1217451274.756:7): type=1503 operation="inode_permission" requested_mask="::r" denied_mask="::r" name="/var/chroot/named/etc/localtime" pid=14131 profile="/usr/sbin/named" namespace="default"
1 gauloises kernel: [180942.460761] audit(1217451274.756:8): type=1503 operation="inode_permission" requested_mask="r::" denied_mask="r::" name="/var/chroot/named/etc/bind/named.conf" pid=14131 profile="/usr/sbin/named" namespace="default"
1 gauloises kernel: [180942.460812] audit(1217451274.756:9): type=1503 operation="inode_permission" requested_mask="::r" denied_mask="::r" name="/var/chroot/named/etc/localtime" pid=14131 profile="/usr/sbin/named" namespace="default"
1 gauloises kernel: [180942.461179] audit(1217451274.756:10): type=1503 operation="inode_permission" requested_mask="::r" denied_mask="::r" name="/var/chroot/named/etc/localtime" pid=14131 profile="/usr/sbin/named" namespace="default"
1 gauloises kernel: [180942.461221] audit(1217451274.756:11): type=1503 operation="inode_permission" requested_mask="::r" denied_mask="::r" name="/var/chroot/named/etc/localtime" pid=14131 profile="/usr/sbin/named" namespace="default"
sudo mkdir -p /var/chroot/named
sudo cd /var/chroot/named/
sudo mkdir -p /var/chroot/named/etc
sudo mkdir /var/chroot/named/dev
sudo mkdir -p /var/chroot/named/var/cache/bind
sudo mkdir -p /var/chroot/named/var/run/bind/run
sudo mv /etc/bind /var/chroot/named/etc
sudo ln -s /var/chroot/named/etc/bind /etc/bind
sudo mknod /var/chroot/named/dev/null c 1 3
sudo mknod /var/chroot/named/dev/random c 1 8
sudo chmod 666 /var/chroot/named/dev/null /var/chroot/named/dev/random
sudo chown -R bind:bind /var/chroot/named/var/*
sudo chown -R bind:bind /var/chroot/named/etc/bind
sudo vi /etc/default/bind9
# changed "OPTIONS="-u bind" to
OPTIONS="-u bind -t /var/chroot/named"
Bookmarks