net-dns/unbound: add var/ dir for auto-trust-anchor by default
authorMarc Schiffbauer <mschiff@gentoo.org>
Mon, 26 Feb 2018 01:07:18 +0000 (02:07 +0100)
committerMarc Schiffbauer <mschiff@gentoo.org>
Mon, 26 Feb 2018 01:07:33 +0000 (02:07 +0100)
Package-Manager: Portage-2.3.24, Repoman-2.3.6

net-dns/unbound/unbound-1.6.8-r2.ebuild [moved from net-dns/unbound/unbound-1.6.8-r1.ebuild with 81% similarity]

similarity index 81%
rename from net-dns/unbound/unbound-1.6.8-r1.ebuild
rename to net-dns/unbound/unbound-1.6.8-r2.ebuild
index 07379f933b5c2abedbcd6587ea4c53486f3bf5ae..8fda5205f2097bc9152ad45ffe58464e5ac66504 100644 (file)
@@ -132,4 +132,25 @@ multilib_src_install_all() {
 
        exeinto /usr/share/${PN}
        doexe contrib/update-anchor.sh
+
+       # create space for auto-trust-anchor-file...
+       keepdir /etc/unbound/var
+       # ... and point example config to it
+       sed -i '/# auto-trust-anchor-file:/s,/etc/dnssec/root-anchors.txt,/etc/unbound/var/root-anchors.txt,' "${ED}/etc/unbound/unbound.conf"
+}
+
+pkg_postinst() {
+       # make var/ writable by unbound
+       if [[ -d "${ROOT}/etc/unbound/var" ]]; then
+               chown --no-dereference --from=root unbound: "${ROOT}/etc/unbound/var"
+       fi
+       einfo ""
+       einfo "If you want unbound to automatically update the root-anchor file for DNSSEC validation"
+       einfo "set 'auto-trust-anchor-file: /etc/unbound/var/root-anchors.txt' in /etc/unbound/unbound.conf"
+       einfo "and run"
+       einfo ""
+       einfo "  su -s /bin/sh -c '/usr/sbin/unbound-anchor -a /etc/unbound/var/root-anchors.txt' unbound"
+       einfo ""
+       einfo "as root to create it initially before starting unbound for the first time after enabling this."
+       einfo ""
 }