Project

General

Profile

Actions

Bug #16937

open
PD JP

Unbound cannot reload due to SSL/TLS certificate file permissions

Bug #16937: Unbound cannot reload due to SSL/TLS certificate file permissions

Added by P Davis 2 months ago. Updated 12 days ago.

Status:
Feedback
Priority:
Normal
Assignee:
Category:
DNS Resolver
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
26.10
Release Notes:
Default
Affected Version:
Affected Architecture:
All

Description

Please refer to following forum post: https://forum.netgate.com/topic/200922/unbound-dns-resolver-periodically-non-responsive

When Unbound is restarted (by pfBlockerNG for example), and this option is selected, Unbound starts to produce the following error and DNS stops resolving:

unbound 1669 [1669:4] error: Error in SSL_CTX use_PrivateKey_file crypto error:8000000D:system library::Permission denied

I have unchecked the option for now. See attached screenshots/log entries


Files

Screenshot 2026-07-07 052506.png (196 KB) Screenshot 2026-07-07 052506.png P Davis, 07/08/2026 09:01 AM
Screenshot 2026-07-07 191320.png (373 KB) Screenshot 2026-07-07 191320.png P Davis, 07/08/2026 09:01 AM
DNSBL.png (163 KB) DNSBL.png P Davis, 08/01/2026 07:49 AM
Unbound.png (175 KB) Unbound.png P Davis, 08/01/2026 07:49 AM
Certificates.png (260 KB) Certificates.png P Davis, 08/01/2026 07:49 AM
16937.patch (1010 Bytes) 16937.patch Jim Pingle, 09/02/2026 05:56 PM

Related issues 1 (0 open1 closed)

Has duplicate Bug #17069: DNS Resolver TLS key is written 0600 owned by root, unbound cannot read it after startupDuplicate

Actions
Actions

Also available in: Atom