stunnel4:stunnel4 owns the directory and has all permissions.
May 11 07:27:19 Riddermark-Linux stunnel4[4198]: Starting TLS tunnels: /etc/stunnel/stunnel.conf:
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Clients allowed=500
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [.] stunnel 5.56 on x86_64-pc-linux-gnu platform
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [.] Compiled with OpenSSL 1.1.1k 25 Mar 2021
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [.] Running with OpenSSL 1.1.1n 15 Mar 2022
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [.] Threading:PTHREAD Sockets:POLL,IPv6,SYSTEMD TLS:ENGINE,FIPS,OCSP,PSK,SNI Auth:LIBWRAP
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] errno: (*__errno_location ())
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [.] Reading configuration from file /etc/stunnel/stunnel.conf
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [.] UTF-8 byte order mark not detected
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [.] FIPS mode disabled
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Compression disabled
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] No PRNG seeding was required
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [:] Insecure file permissions on /var/lib/stunnel4/psk.txt
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] PSKsecrets line 1: 32-byte ASCII key configured for identity "test1"
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Initializing service [**redacted**]
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] PSK identities: 1 retrieved
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Ciphers: PSK
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] TLSv1.3 ciphersuites: TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] TLS options: 0x02100004 (+0x00000000, -0x00000000)
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] No certificate or private key specified
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] DH initialization needed for DHE-PSK-AES256-GCM-SHA384
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] DH initialization
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] No certificate available to load DH parameters
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Using dynamic DH parameters
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] ECDH initialization
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] ECDH initialized with curves X25519:P-256:X448:P-521:P-384
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [.] Configuration successful
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Binding service [**redacted**]
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Listening file descriptor created (FD=9)
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Setting accept socket options (FD=9)
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Option SO_REUSEADDR set on accept socket
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Service [**redacted**] (FD=9) bound to
0.0.0.0:12307May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [.] Switched to chroot directory: /var/lib/stunnel4/
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [!] Cannot open log file: /var/lib/stunnel4/stunnel.logMay 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Deallocating section defaults
May 11 07:27:19 Riddermark-Linux stunnel4[4212]: [ ] Unbinding service [**redacted**]