On 29/10/2021 16.59, Martin Dosch wrote:
  You're right. Although the certs are readable (and
other services
 successfully read them already) it works after I created a script
 which copys the files into kresd's workdir and chowns them to
 knot-resolver.  
Maybe those other services run as root user or something...