give certbot access to /etc/nginx/ocsp-cache

This commit is contained in:
Daniel Micay 2022-08-27 17:22:23 -04:00
parent 2cf0966847
commit 8482ac5144

View File

@ -18,7 +18,7 @@ ProtectKernelModules=true
ProtectKernelTunables=true
ProtectProc=invisible
ProtectSystem=strict
ReadWritePaths=/etc/letsencrypt /var/lib/letsencrypt /var/log/letsencrypt -/srv/certbot
ReadWritePaths=/etc/letsencrypt /var/lib/letsencrypt /var/log/letsencrypt -/srv/certbot /etc/nginx/ocsp-cache
RemoveIPC=true
RestrictAddressFamilies=AF_INET AF_INET6
RestrictNamespaces=true