Re: /var/unbound/db/root.key not world-readable, unbound fails to start

2023-12-09 Thread Martin Schröder
Am So., 10. Dez. 2023 um 02:48 Uhr schrieb Todd C. Miller : > By default, /etc/login.conf has umask set to 022. Is it more > restrictive on your system? Ah, yes. Mine is set to 077. That would explain me being unable to start it via sudo. And when I rebooted after a failed restart the

Re: /var/unbound/db/root.key not world-readable, unbound fails to start

2023-12-09 Thread Todd C . Miller
The mode on /var/unbound/db/root.key is influenced by the umask. If you restart unbound from a shell with umask set to 077, /var/unbound/db/root.key will be mode 0600. If the the umask is 022, the /var/unbound/db/root.key will be mode 0644. By default, /etc/login.conf has umask set to 022. Is

/var/unbound/db/root.key not world-readable, unbound fails to start

2023-12-09 Thread Martin Schröder
Hi, after the last erratas I rebooted my 7.4 and unbound failed to start because unbound: [65439:0] error: unable to open /db/root.key for reading: Permission denied unbound: [65439:0] error: error reading auto-trust-anchor-file: /var/unbound/db/root.key unbound: [65439:0] error: validator: error