Re: Re: NTS Server Setup with Let's Encrypt

James Cloos <cloos-GRsvFm/Gh/[email protected]> Sun, 20 Apr 2025 09:43:24 -0400
Newsgroups gmane.comp.time.chrony.user
Message-ID <[email protected]>
> What would be the correct way of giving chrony permissions to read the
> certificate files created by certbot, without breaking the web server?

i would have expected that setfacl(1) call to work, but you could try
adding _chrony to the ssl-cert group.  if you are using debian's
packaging of certbot the certs should be in group ssl-cert and should
be group readable.

-JimC
-- 
James Cloos <cloos-GRsvFm/Gh/[email protected]>
            OpenPGP: https://jhcloos.com/0x997A9F17ED7DAEA6.asc

-- 
To unsubscribe email chrony-users-request-kWFZVVI9zxvPqho9SqqRMmD2FQJk+8+b@public.gmane.org 
with "unsubscribe" in the subject.
For help email chrony-users-request-kWFZVVI9zxvPqho9SqqRMmD2FQJk+8+b@public.gmane.org 
with "help" in the subject.
Trouble?  Email [email protected]