Go Back   HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials > ISPConfig 3 > Installation/Configuration

Do you like HowtoForge? Please consider supporting us by becoming a subscriber.
Reply
 
Thread Tools Display Modes
  #1  
Old 12th July 2011, 23:02
user99 user99 is offline
Junior Member
 
Join Date: Jul 2008
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Default Name resolution not working for jailkit chrooted users

I followed the "Perfect Server" installation for Ubuntu 11.04 and ISPConfig 3.
When using shell as generic linux user or sudo, name resolution works perfectly.

Inside a chrooted environment, name resolution fails.

Here's what I did:

I created a client, and a site. (No reseller is used in my case).
I gave the client a chrooted shell.
The client user can login to the shell, but cannot get name resolution from the shell using any of the available tools:

ping www.google.com
ping: unknown host www.google.com

ping with ip address works fine, of course.

More details:
chrooted /etc/resolv.conf contains:
search (my local domain here)
nameserver 8.8.8.8
nameserver 8.8.4.4

The chrooted user can read from resolv.conf
It is identical to the root version.

/bin/ping does have required suid:
ls -la /bin/ping
-rwsr-xr-x 1 0 0 35680 Nov 15 2010 /bin/ping

As far as the settings in ISPConfig's panel for jailkit, these are still set to default values:

Jailkit chroot app sections:
basicshell editors extendedshell netutils ssh sftp scp groups jk_lsh

Jailkit chrooted applications:
/usr/bin/groups /usr/bin/id /usr/bin/dircolors /usr/bin/lesspipe /usr/bin/basename /usr/bin/dirname /usr/bin/nano /usr/bin/pico

I copied dig and nslookup into the chrooted environment, and both work.

Other info:
This server functions as Web and Mail server only. All other services (including DNS server) are disabled. Mail seems to be working perfectly. I haven't tested the web server yet.

Has anyone else run into this issue?
Any ideas on what might be causing the problem?

thx

Last edited by user99; 12th July 2011 at 23:04. Reason: correct error.
Reply With Quote
Sponsored Links
  #2  
Old 13th July 2011, 06:45
user99 user99 is offline
Junior Member
 
Join Date: Jul 2008
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Default never mind

I figured it out. Works fine now.
Reply With Quote
  #3  
Old 13th July 2011, 08:08
Ghostdare Ghostdare is offline
Senior Member
 
Join Date: Aug 2009
Location: Europe - Romania - Bucharest
Posts: 146
Thanks: 10
Thanked 22 Times in 22 Posts
Default

Post your resolution here... if somebody end the same as you, to know how to resolve it.
Reply With Quote
  #4  
Old 11th September 2011, 19:42
ispconfig-user ispconfig-user is offline
Junior Member
 
Join Date: Sep 2011
Posts: 1
Thanks: 0
Thanked 1 Time in 1 Post
 
Default

Here's the fix.

Copy these two libraries into their respective locations for the client sites, as follows:

cp /lib/x86_64-linux-gnu/libnss_files.so.2 /var/www/clients/client#/web#/lib/x86_64-linux-gnu/
cp /lib/x86_64-linux-gnu/libnss_dns.so.2 /var/www/clients/client#/web#/lib/x86_64-linux-gnu/

(NOTE: The location of these files may vary depending upon your distribution, but the names of the libraries will be the same. You can use strace with ping to find out where it's looking for them.)

There are a lot of useful command line tools that are missing from the default client jail, such as ping, wget, dig, nslookup, etc. Not sure why these were left out. Maybe I did something wrong during the installation.

cheers...
Reply With Quote
The Following User Says Thank You to ispconfig-user For This Useful Post:
falko (12th September 2011)
Reply

Bookmarks

Tags
"name resolution", chroot, jailkit, ping, ubuntu 11.04

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Qemu-kVM setup vm using 2 NIC's are not working muzi Technical 1 14th February 2011 22:27
WEB UI FTP not working gimhan90 Installation/Configuration 2 16th March 2006 08:03
Add DNS to a "Virtual Users And Domains" installation, and finish with ISPConfig Nuxeretes Installation/Configuration 4 2nd March 2006 14:02
Ability to add components for users webstergd Feature Requests 1 20th December 2005 10:25


All times are GMT +2. The time now is 11:37.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2014, vBulletin Solutions, Inc.