-
Short descriptionPermission denied on starting dnsdist on Rocky 9.2 using letsencrypt
Environment
Steps to reproducePermission denied on starting dnsdist on Rocky 9.2 using letsencrypt
Expected behaviourStart the server Actual behaviour
Other informationMovinf the cert to /tmp dir does not help:
Curious error:
Running: |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
I'm moving this issue to a discussion since in my humble opinion this is in fact a support question. The first issue arises because our systemd unit starts dnsdist under an unprivileged user named
Moving the certificate and key to |
Beta Was this translation helpful? Give feedback.
I'm moving this issue to a discussion since in my humble opinion this is in fact a support question.
The first issue arises because our systemd unit starts dnsdist under an unprivileged user named
dnsdist
, so this user needs to have access to the certificate and key in/etc/letsencrypt/live/somedomain.com/
and clearly it doesn't. This is actually documented in https://dnsdist.org/guides/dns-over-https.html: