DNSSEC policy using wrong directory?
Mike
debian at good-with-numbers.com
Sun Aug 24 15:36:16 UTC 2025
I should have mentioned that `managed-keys.bind{,.jnl}` are written
(correctly) to /var/cache/bind. So the `directory` option is doing its job,
just not for the `dnssec-policy` journals.
But `Kgood-with-numbers.com.*` *are* going into /var/cache/bind, so
`dnssec-policy` is getting that part correct.
I just saw
general: error: dumping master file: /etc/bind/tmp-...: open: permission denied
as well. So this seems to go beyond just setting the `journal` option.
> general: error: /etc/bind/good-with-numbers.com.signed.jnl: create: permission denied
> directory "/var/cache/bind";
>
> is set, so that's the working directory, so it should be writing into there.
More information about the bind-users
mailing list