Bind in FreeBSD, security advisories

J David j.david.lists at gmail.com
Tue Jul 30 14:52:08 UTC 2013


Half the people will say:

"There should be more stuff in base!"

The other half will say:

"There should be less stuff in base!"

People don't generally change each other's minds about this because
they start from competing definitions of what is good that are 100%
opinion in nature.

(Spoken as a hardcore advocate of "There should be less stuff in base!")

DNS client and DNS server functionality are quite different, and it
would be swell if there were a set of BIND-independent client tools
that were part of the base so that BIND could, at a minimum, be left
out via WITH_BIND=no in src.conf or similar without producing a
crippled system.  And/or people could install the DNS server of their
choice (whether unbound or BIND or whatever) using pkg.

If there isn't one already readily available, I might even volunteer
to help develop that set of client tools at such time as FreeBSD
coding standards allow C++11 in the tree. :)


More information about the freebsd-stable mailing list