Skip to content

Permission denied on starting dnsdist on Rocky 9.2 #13377

Answered by rgacogne
b1tw0rker asked this question in Q&A
Discussion options

You must be logged in to vote

I'm moving this issue to a discussion since in my humble opinion this is in fact a support question.

The first issue arises because our systemd unit starts dnsdist under an unprivileged user named dnsdist, so this user needs to have access to the certificate and key in /etc/letsencrypt/live/somedomain.com/ and clearly it doesn't. This is actually documented in https://dnsdist.org/guides/dns-over-https.html:

A particular attention should be taken to the permissions of the certificate and key files. Many ACME clients used to get and renew certificates, like CertBot, set permissions assuming that services are started as root, which is no longer true for dnsdist as of 1.5.0. For that particu…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@b1tw0rker
Comment options

Answer selected by Habbie
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
2 participants
Converted from issue

This discussion was converted from issue #13375 on October 17, 2023 07:00.