Bug#1125111: apache2: Apache2 won't start, error "Read-only file system: AH10082: Can't change owner of /etc/apache2/md/challenges"

Bastien Roucaries <[email protected]>
Newsgroups gmane.linux.debian.devel.apache
Message-ID <2543105.S38r39SQy0__10052.2111215227$1786629206$gmane$org@debian-ei>
Le jeudi 13 août 2026, 15:22:13 heure d’été d’Europe centrale Hector Cao a écrit :
> Package: apache2
> Followup-For: Bug #1125111
> User: [email protected]
> Usertags: origin-ubuntu stonking ubuntu-patch
> Control: tags -1 patch
> 
> Dear Maintainer,
> 
>     The systemd hardening in debian/apache2.service and
>     debian/[email protected] sets ProtectSystem=full, which makes /etc
>     read-only at runtime. mod_md's default MDStoreDir is a directory named
>     "md" resolved relative to the server root (ServerRoot), i.e.
>     /etc/apache2/md for a normal install, or /etc/apache2-<instance>/md for
>     an [email protected] instance. That path was never added to
>     ReadWritePaths=, so any vhost using an "MDomain" directive fails to
>     start.
>     
>     Add an optional (dash-prefixed, so it is silently skipped if the
>     directory does not exist) ReadWritePaths= entry for /etc/apache2/md
>     (and its %i-instance equivalent).
> 
>   * d/apache2.service: allow mod_md to write its certificate store
No this should be moved to /var/cache/md

Upstream have done some work could you get a glimpse at ti ?

rouca


> 
> 
> Thanks for considering the patch.
> 
> 
> -- System Information:
> Debian Release: trixie/sid
>   APT prefers noble-updates
>   APT policy: (500, 'noble-updates'), (500, 'noble-security'), (500, 'noble'), (100, 'noble-backports')
> Architecture: amd64 (x86_64)
> 
> Kernel: Linux 7.0.0-28-generic (SMP w/16 CPU threads; PREEMPT)
> Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE
> Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
> Shell: /bin/sh linked to /usr/bin/dash
> Init: systemd (via /run/systemd/system)
> LSM: AppArmor: enabled
>
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmp9y9cACgkQADoaLapB
CF+jnA/+KmIELGh8xlZVurcmDa99KSn5ZygKxMB4upyIagfnqKcsNSmTYxUZ8MTq
GY4u907kEoIFhflxP+TqLrc8dJgCPjM5OMMpYRPwCwJh5+xyYFXf93J1sFs4R1V2
+LQ9R48SjV25tJ1zuoQUll8TsBtBFMFfkZQS9o+Cb57BWn1UR8IWi4JJ5zEW7V8o
zetyE02QR7k8mDxRYGcKWVppgHHot+Ex6nqgs43vnR5NWM/+YiDToyhn4wxoaiep
IdlLzLgXWy/gkAtqZqnYpvraVchiKzh4cdh4n12oDk94EnUWr9Vd5t9KwuI6pr3Y
JgmHkNg0irrLaodnwbl5I711tiUOKMHHF+nELyDQIfZHUzevbWT1TtkrEUXA/0//
f08P903Kp7j9r1b2fDtzuCTAyDlvDCmxG+KvZKCFaYS64qNs447n7kZjdyjWMnb/
uCLLlw+6IzOksJcmBstfYsNl9s0gM22baX9E3cBNtlS+XyuSNSCR1ZXDgk2u7Kwk
I1dtjUOVEOm1gJi4VJd0Li1qFrP7YLVpkNOye8PnFGlyrE2B+XCGzgoV/n/Bt+Gy
t821eqe/hdSS3++DRfJfSdfDGXwTbxYo7dY7o0icPy6NF3OeGxxVZ1s5MTKVImGT
vOoON6M/RwD/7bb9luD1gFJzveBV4ut5Wg5ugBfJlasOUE1a1jY=
=hmPw
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.