Le mardi 23 août 2022 à 07:38 +0200, Daniel Salzman a écrit :
Bastien,
I suspect it's related to systemd service changes (main commit
https://gitlab.nic.cz/knot/knot-dns/-/commit/e152a4c21e0f34bece12eb68af61e5…
).
Especially the TemporaryFileSystem setting. You can try extending it
with some /usr value. I will try to reproduce the issue using
softhsm.
Daniel
Hello,
I can confirm removing the line "TemporaryFileSystem=/run:ro /var:ro"
from unit make knot able to use the HSM key
As /usr is not listed, it should be left untouched in the FS namespace,
I'll try to dig a little bit more
Regards,
--
Bastien