On Tue, Feb 29, 2000 at 04:53:42PM +0000, Jim Reid wrote:

> You misunderstand. Running the name server with a non-root UID is an
> application of one of the basic tenets of security: least privilege.
I agree.

> ie The software only gets enough access rights to do what it has to do
> and no more. For the name server that should mean *reading* zone files
> and named.conf and maybe writing some log files. (Well, with a little
> work, that's possible.) 

It must be able to write it's slave zones, too...

