From e239821b65691577ed30e8b7c54fd2050f86a487 Mon Sep 17 00:00:00 2001 From: Tommy Date: Mon, 31 Jul 2023 01:24:06 -0700 Subject: [PATCH] Fix trust anchor permission --- GCP-Debian-11.sh | 3 +++ 1 file changed, 3 insertions(+) diff --git a/GCP-Debian-11.sh b/GCP-Debian-11.sh index c6929fe..9728cb1 100644 --- a/GCP-Debian-11.sh +++ b/GCP-Debian-11.sh @@ -18,6 +18,7 @@ sudo ufw allow 22/tcp sudo tuned-adm profile virtual-guest echo 'server: + trust-anchor-file: "/var/lib/unbound/root.key trust-anchor-signaling: yes root-key-sentinel: yes tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt @@ -50,6 +51,8 @@ forward-zone: forward-addr: 2606:4700:4700::1112@853#security.cloudflare-dns.com forward-addr: 2606:4700:4700::1002@853#security.cloudflare-dns.com' | sudo tee /etc/unbound/unbound.conf.d/custom.conf +sudo mv /etc/unbound/unbound.conf.d/root-auto-trust-anchor-file.conf /etc/unbound/unbound.conf.d/root-auto-trust-anchor-file.conf.bk + mkdir -p /etc/systemd/system/unbound.service.d echo $'[Service] CapabilityBoundingSet=CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_SYS_RESOURCE CAP_NET_RAW