[chrony-users] Chronyd NTS under Ubuntu 24 - group permissions |
[ Thread Index |
Date Index
| More chrony.tuxfamily.org/chrony-users Archives
]
- To: <chrony-users@xxxxxxxxxxxxxxxxxxxx>
- Subject: [chrony-users] Chronyd NTS under Ubuntu 24 - group permissions
- From: "Mikhail" <mikhail@xxxxxxxxxxxxx>
- Date: Tue, 16 Sep 2025 02:03:31 +0200
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zeptobars.com; s=dkim; t=1757981015; h=from:subject:date:message-id:to:mime-version:content-type: content-transfer-encoding:content-language:in-reply-to:references; bh=gwCsumbXAjnNwmJOfJMb1+w3/2eZWr3x1ixrxw1OU2o=; b=AqIWYavH+XIrvf3M2OjwBptNWSfw1YWi3r9qhwLz112g/O2LX9o9lZIiH/JPnldOjGW6T2 e83P8w4i/lsG5DlqhKeGjqREwNULAYEw2FdTyzOs8o6+Ixups/RLH+VN8/Q8DjtyPyv3yK btKDbbRGeNOtntzCy4KcYWo86kWeAIfy7zQki6Y8i3mI92pnTQyb0xtmgxwguaJ0aKf7n6 VIzh0B+CDAHIgoEiZw3xCot5WhX/cmP5q8KmmXa1+ulVchl2dEIed6LCvKixPDSXk0i/Lh Bel7+2vzsaGAF9x5L8pj0WNnT3GQ+uAlSEZAr8WXTALaY1VdbZkp8UpLJ6UQnQ==
- Thread-index: AdwmnS0J4A1K3zYmTPi372gfEG6c2g==
1) NTS keys are generated by letsencrypt/certbot and in Ubuntu are accessible to group ssl-certs.
I can add Chrony user _chrony to group ssl-certs, and verify that user can access the certificates.
Also, I added AppArmor exception to allow Chorny to access the keys.
Still Chrony won't be able to access the keys as Chrony seems to be stripping group permission from itself.
What is the valid path to making NTS work without actually copying/chown-ing keys on schedule? I would prefer to keep private keys in single place.
2) Will chrony see that keys are updated, or he will need to have keys reloaded in a script?
--
To unsubscribe email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "unsubscribe" in the subject.
For help email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "help" in the subject.
Trouble? Email listmaster@xxxxxxxxxxxxxxxxxxxx.