# 502 error after upgrade to v3.3.0

**URL:** <https://community.passbolt.com/t/502-error-after-upgrade-to-v3-3-0/4376>\
**Category:** Installation Issues\
**Created:** [October 31, 2021, 10:56pm UTC](https://community.passbolt.com/t/502-error-after-upgrade-to-v3-3-0/4376 "2021-10-31T22:56:55Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![krosseyed](https://avatars.discourse-cdn.com/v4/letter/k/ebca7d/32.png) [@krosseyed](https://community.passbolt.com/u/krosseyed)\
**Post date:** [October 31, 2021, 10:56pm UTC](https://community.passbolt.com/t/502-error-after-upgrade-to-v3-3-0/4376/1 "2021-10-31T22:56:55Z")

</div>

**Checklist**  
[\*] I have read intro post: [https://community.passbolt.com/t/about-the-installation-issues-category/12](https://community.passbolt.com/t/about-the-installation-issues-category/12)  
[\*] I have read the tutorials, help and searched for similar issues  
[\*] I provide relevant information about my server (component names and versions, etc.)  
[\*] I provide a copy of my logs and healthcheck  
[\*] I describe the steps I have taken to trouble shoot the problem  
[\*] I describe the steps on how to reproduce the issue

I am trying to upgrade my passbolt VM to v3.3.0 from ~v2.3 and I am getting a 502 error after doing a migration.

I am running Ubuntu 20.04 with PHP 7.4 and MySQL 8 on another device on the network. I am also using an Apache server as a web proxy as I have multiple sites that are served through it.

Please let me know what logs I need to pull from my system so I can troubleshoot this.

## Below is what I get when I run a healthcheck:

## PASSBOLT Open source password manager for teams

Healthcheck shell…Warning Error: file\_get\_contents(/var/www/passbolt/config/jwt/jwt.pem): failed to open stream: No such file or directory  
In [/var/www/passbolt/plugins/Passbolt/JwtAuthentication/src/Service/AccessToken/JwtKeyPairService.php, line 110]

2021-10-31 22:41:59 Warning: Warning (2): file\_get\_contents(/var/www/passbolt/config/jwt/jwt.pem): failed to open stream: No such file or directory in [/var/www/passbolt/plugins/Passbolt/JwtAuthentication/src/Service/AccessToken/JwtKeyPairService.php, line 110]

* * *

Environment

[PASS] PHP version 7.4.3.  
[PASS] PCRE compiled with unicode support.  
[PASS] The temporary directory and its content are writable and not executable.  
[PASS] The logs directory and its content are writable.  
[PASS] GD or Imagick extension is installed.  
[PASS] Intl extension is installed.  
[PASS] Mbstring extension is installed.

Config files

[PASS] The application config file is present  
[PASS] The passbolt config file is present

Core config

[PASS] Debug mode is off.  
[PASS] Cache is working.  
[PASS] Unique value set for security.salt  
[PASS] Full base url is set to [https://passbolt.XXXXXXX.com](https://passbolt.XXXXXXX.com)  
[PASS] App.fullBaseUrl validation OK.  
[FAIL] Could not reach the /healthcheck/status with the url specified in App.fullBaseUrl  
[HELP] Check that the domain name is correct in config/passbolt.php  
[HELP] Check the network settings

SSL Certificate

[FAIL] SSL peer certificate does not validate  
[FAIL] Hostname does not match when validating certificates.  
[WARN] Using a self-signed certificate

Database

[PASS] The application is able to connect to the database  
[PASS] 26 tables found  
[PASS] Some default content is present  
[PASS] The database schema up to date.

GPG Configuration

[PASS] PHP GPG Module is installed and loaded.  
[PASS] The environment variable GNUPGHOME is set to /home/www-data/.gnupg.  
[PASS] The directory /home/www-data/.gnupg containing the keyring is writable by the webserver user.  
[PASS] The server OpenPGP key is not the default one  
[PASS] The public key file is defined in config/passbolt.php and readable.  
[PASS] The private key file is defined in config/passbolt.php and readable.  
[PASS] The server key fingerprint matches the one defined in config/passbolt.php.  
[PASS] The server public key defined in the config/passbolt.php (or environment variables) is in the keyring.  
[PASS] There is a valid email id defined for the server key.  
[PASS] The public key can be used to encrypt a message.  
[PASS] The private key can be used to sign a message.  
[PASS] The public and private keys can be used to encrypt and sign a message.  
[PASS] The private key can be used to decrypt a message.  
[PASS] The private key can be used to decrypt and verify a message.  
[PASS] The public key can be used to verify a signature.

Application configuration

[PASS] Using latest passbolt version (3.3.0).  
[PASS] Passbolt is configured to force SSL use.  
[PASS] App.fullBaseUrl is set to HTTPS.  
[PASS] Selenium API endpoints are disabled.  
[PASS] Search engine robots are told not to index content.  
[PASS] Registration is closed, only administrators can add users.  
[PASS] Serving the compiled version of the javascript app  
[PASS] All email notifications will be sent.

JWT Authentication

[WARN] The JWT Authentication plugin is disabled  
[HELP] Set the environment variable PASSBOLT\_PLUGINS\_JWT\_AUTHENTICATION\_ENABLED to true

[FAIL] 3 error(s) found. Hang in there!

The last two Nginx errors that I captured showing me trying to connect:

2021/10/31 22:48:14 [error] 3885#3885: \*64 connect() failed (111: Connection refused) while connecting to upstream, client: 10.208.41.233, server: [passbolt.XXXXXXX.com](http://passbolt.XXXXXXX.com), request: “GET /install/system\_check HTTP/1.1”, upstream: “fastcgi://127.0.0.1:9000”, host: “[passbolt.XXXXXXX.com](http://passbolt.XXXXXXX.com)”

2021/10/31 22:53:45 [error] 3885#3885: \*69 connect() failed (111: Connection refused) while connecting to upstream, client: 10.208.41.233, server: [passbolt.XXXXXXX.com](http://passbolt.XXXXXXX.com), request: “GET / HTTP/1.1”, upstream: “fastcgi://127.0.0.1:9000”, host: “[passbolt.XXXXXXX.com](http://passbolt.XXXXXXX.com)”

---

<div class="post-metadata">

**Author:** ![remy](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/remy/32/17_2.png) [@remy](https://community.passbolt.com/u/remy)\
**Post date:** [November 2, 2021, 8:06am UTC](https://community.passbolt.com/t/502-error-after-upgrade-to-v3-3-0/4376/2 "2021-11-02T08:06:23Z")

</div>

@krosseyed your post should now be visible.

---

<div class="post-metadata">

**Author:** ![krosseyed](https://avatars.discourse-cdn.com/v4/letter/k/ebca7d/32.png) [@krosseyed](https://community.passbolt.com/u/krosseyed)\
**Post date:** [November 2, 2021, 1:03pm UTC](https://community.passbolt.com/t/502-error-after-upgrade-to-v3-3-0/4376/3 "2021-11-02T13:03:11Z")

</div>

Thank you @remy for opening this back up, as I have been able to resolve my issue.

Turns out it was an Nginx error and I had followed all the steps in the following guide to resolve it:

> **[NGINX 502 Bad Gateway: PHP FPM](https://www.datadoghq.com/blog/nginx-502-bad-gateway-errors-php-fpm/)**
>
> Learn to troubleshoot 502 errors that can occur when you combine NGINX and the PHP-FPM application server.

The solution from this guide that worked for me was the following:

```auto
nano www.conf

listen = 127.0.0.1:9000

```

After that change, nginx started to work again. So if you are updating from 18.04 → 20.04 on ubuntu, please check that your nginx config hasn’t been modified, as it may prevent passbolt access via nginx.

---

<div class="post-metadata">

**Author:** ![AnatomicJC](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/anatomicjc/32/962_2.png) [@AnatomicJC](https://community.passbolt.com/u/AnatomicJC)\
**Post date:** [November 2, 2021, 3:34pm UTC](https://community.passbolt.com/t/502-error-after-upgrade-to-v3-3-0/4376/4 "2021-11-02T15:34:37Z")

</div>

Thanks for your feedback about your installation issue. I think it can help other users.

By the way, the default with Ubuntu 20.04 is now to use a socket (/run/php/php7.4-fpm.sock) instead of a TCP connection (127.0.0.1:9000).

Another solution is to edit your nginx configuration file and use this socket:

```auto
    fastcgi_pass unix:/run/php/php7.4-fpm.sock;

```

Instead of the TCP connection:

```auto
    fastcgi_pass 127.0.0.1:9000;

```

---

<div class="post-metadata">

**Author:** ![krosseyed](https://avatars.discourse-cdn.com/v4/letter/k/ebca7d/32.png) [@krosseyed](https://community.passbolt.com/u/krosseyed)\
**Post date:** [November 18, 2021, 3:24am UTC](https://community.passbolt.com/t/502-error-after-upgrade-to-v3-3-0/4376/5 "2021-11-18T03:24:11Z")

</div>

I appreciate the followup on this. I did have to change the fastcgi\_pass value to the following before it would work.

> fastcgi\_pass unix:php7.4-fpm.pid;

After that, we are good to go!

---

<div class="post-metadata">

**Author:** ![anli](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@anli](https://community.passbolt.com/u/anli)\
**Post date:** [July 9, 2023, 11:23am UTC](https://community.passbolt.com/t/502-error-after-upgrade-to-v3-3-0/4376/6 "2023-07-09T11:23:26Z")

</div>

For anybody coming here via google - I had a 502 gateway timeout after dist-upgrade on debian 10 to debian 11 (buster to bullseye). The reason was the line

```auto
    fastcgi_pass unix:/run/php/php7.3-fpm.sock;

```

in /etc/nginx/sites-enabled/nginx-passbolt.conf which had to be changed to

```auto
    fastcgi_pass unix:/run/php/php7.4-fpm.sock;

```

---

<div class="post-metadata">

**Author:** ![AnatomicJC](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/anatomicjc/32/962_2.png) [@AnatomicJC](https://community.passbolt.com/u/AnatomicJC)\
**Post date:** [July 9, 2023, 8:32pm UTC](https://community.passbolt.com/t/502-error-after-upgrade-to-v3-3-0/4376/7 "2023-07-09T20:32:05Z")

</div>

I got the same from Debian 11 to Debian 12, I had to update the socket path accordingly to php 8.2 version.

---

<div class="post-metadata">

**Author:** ![lbusse](https://avatars.discourse-cdn.com/v4/letter/l/4af34b/32.png) [@lbusse](https://community.passbolt.com/u/lbusse)\
**Post date:** [August 1, 2023, 10:19am UTC](https://community.passbolt.com/t/502-error-after-upgrade-to-v3-3-0/4376/8 "2023-08-01T10:19:11Z")

</div>

I got the same error after I upgraded to ubuntu 22.04  
I had to change  
`fastcgi_pass unix:/run/php/php7.4-fpm.sock;`  
to  
`fastcgi_pass unix:/run/php/php8.1-fpm.sock;`  
in /etc/nginx/sites-enabled/nginx-passbolt.conf to get it to work again

I found the necessary php-fpm.sock version through checking which one was listed in /run/php/
