# Can't use Android App

**URL:** <https://community.passbolt.com/t/cant-use-android-app/4582>\
**Category:** Installation Issues\
**Created:** [December 7, 2021, 9:46pm UTC](https://community.passbolt.com/t/cant-use-android-app/4582 "2021-12-07T21:46:27Z")\
**Posts on this page:** 9\
**Page:** 2

<div class="post-metadata">

**Author:** ![max](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/max/32/1528_2.png) [@max](https://community.passbolt.com/u/max)\
**Post date:** [December 28, 2021, 12:47pm UTC](https://community.passbolt.com/t/cant-use-android-app/4582/21 "2021-12-28T12:47:16Z")

</div>

@1voud I unlocked @johndi89 in a call it was an issue with the jwt keys permissions.  
So first you need to check the ownership of the jwt folder:

```auto
sudo chown -Rf root:www-data /etc/passbolt/jwt
sudo chmod 750 /etc/passbolt/jwt
sudo chmod 640 /etc/passbolt/jwt/jwt.key
sudo chmod 640 /etc/passbolt/jwt/jwt.pem

```

Then logout from your account  
Login again  
Try to transfert the key again on mobile  
If there is still an issue we can try:

```auto
sudo /usr/share/php/passbolt/bin/cake passbolt create_jwt_keys -v -f

```

Then like before, logout, login, transfert on mobile

Let me know

---

<div class="post-metadata">

**Author:** ![1voud](https://avatars.discourse-cdn.com/v4/letter/1/f1d935/32.png) [@1voud](https://community.passbolt.com/u/1voud)\
**Post date:** [December 28, 2021, 4:20pm UTC](https://community.passbolt.com/t/cant-use-android-app/4582/22 "2021-12-28T16:20:51Z")

</div>

Thanks for your reply.

I followed the instructions, the ownership was correct (www-data www-data).

```auto
/etc/passbolt/jwt had 750 --> changed to 755
/etc/passbolt/jwt/jwt.key had 640 --> changed to 600
/etc/passbolt/jwt/jwt.pem had 644

```

Logged in, transferred keys, no change.

```auto
runuser -u www-data -- /usr/share/php/passbolt/bin/cake passbolt create_jwt_keys -v -f

```

Logged out, logged in, transferred keys, no change.

---

<div class="post-metadata">

**Author:** ![Termindiego25](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/termindiego25/32/5517_2.png) [@Termindiego25](https://community.passbolt.com/u/Termindiego25)\
**Post date:** [December 28, 2021, 5:46pm UTC](https://community.passbolt.com/t/cant-use-android-app/4582/23 "2021-12-28T17:46:43Z")

</div>

Have you apache web server or nginx?  
You may check [this post](https://community.passbolt.com/t/cannot-get-passwords-on-the-android-app/4552), I could solve that problem with Apache and there are some users trying to do the same on Nginx

---

<div class="post-metadata">

**Author:** ![1voud](https://avatars.discourse-cdn.com/v4/letter/1/f1d935/32.png) [@1voud](https://community.passbolt.com/u/1voud)\
**Post date:** [December 29, 2021, 2:06pm UTC](https://community.passbolt.com/t/cant-use-android-app/4582/24 "2021-12-29T14:06:22Z")

</div>

A short summary as the information is bit scattered through the thread.

The mobile App throws an exception in the com.passbolt.mobile.android.feature.authentication.auth.challenge.ChallengeProvider.kt when calling:

```
val encryptedChallenge = openPgp.encryptSignMessageArmored(
    publicKey = serverPublicKey,
    privateKey = privateKey,
    passphrase = passphraseCopy,
    message = challengeJson
)

```

When I inspect the the serverPublicKey variable it holds the public GPG key from the server.

The Exception is:  
com.passbolt.mobile.android.gopenpgp.exception.OpenPgpException: gopenpgp: unable to parse public key: gopenpgp: the key contains too many entities.

Please let me know if I need to collect some more info.

---

<div class="post-metadata">

**Author:** ![max](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/max/32/1528_2.png) [@max](https://community.passbolt.com/u/max)\
**Post date:** [December 29, 2021, 2:51pm UTC](https://community.passbolt.com/t/cant-use-android-app/4582/25 "2021-12-29T14:51:19Z")

</div>

@1voud  
The fact that you have 2 entry for uid [passbolt@yourdomain.com](mailto:passbolt@yourdomain.com) is an issue indeed.

You need to identify which key is used on your server  
if you have a passbolt.php (/var/www/passbolt/config/passbolt.php or /etc/passbolt/passbolt.php)

exec the following command to identify your public key fingerprint  
`cat passbolt.php | grep fingerprint`  
you should get  
`'fingerprint' => '2FC8945833C51946E937F9FED47B0811573EE67E',`

Then looks for the location of your gpg keyring  
`sudo su -s /bin/bash -c "/usr/share/php/passbolt/bin/cake passbolt healthcheck --gpg" www-data`  
or  
`sudo su -s /bin/bash -c "/var/www/passbolt/bin/cake passbolt healthcheck --gpg" www-data`  
you will see this line  
`[PASS] The directory /home/www-data/.gnupg containing the keyring is writable by the webserver user.`

Then you need to list list the keys associated with [passbolt@yourdomain.com](mailto:passbolt@yourdomain.com)  
`sudo su -s /bin/bash -c "gpg --home /home/www-data/.gnupg --list-keys | grep -i -B 2 'passbolt@yourdomain.com'" www-data`  
You should see two keys identify the one (let say 1183899100E52F0047BBBDF617AE53A5D9F11253 for ex) that is not related listed in your passbolt.php file and do  
`sudo su -s /bin/bash -c "gpg --home /home/www-data/.gnupg --delete-keys 1183899100E52F0047BBBDF617AE53A5D9F11253" www-data`

Then tell us the result

Best,  
Max

---

<div class="post-metadata">

**Author:** ![1voud](https://avatars.discourse-cdn.com/v4/letter/1/f1d935/32.png) [@1voud](https://community.passbolt.com/u/1voud)\
**Post date:** [December 29, 2021, 6:07pm UTC](https://community.passbolt.com/t/cant-use-android-app/4582/27 "2021-12-29T18:07:02Z")

</div>

I had some issues running the gpg commands in the docker container, the list-keys worked fine. The keyring being writable check PASS-ed.  
The GPG keys are being imported during container startup each time, but I was not able to remove the public key from the keyring since there was a private key. The deletion of the private key failed (no permission).

That’s why I took a different route. I exported both keypairs and replaced the GPG files which get imported at container startup so that only one would be imported at a time on container startup.  
The first key(pair) got me one step further while the second key(pair) made the Android App work!!

Thanks so much for all the support !!

Passbolt Rocks!

---

<div class="post-metadata">

**Author:** ![max](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/max/32/1528_2.png) [@max](https://community.passbolt.com/u/max)\
**Post date:** [December 29, 2021, 8:09pm UTC](https://community.passbolt.com/t/cant-use-android-app/4582/28 "2021-12-29T20:09:51Z")

</div>

Superb @1voud

Enjoy the app and thanks for choosing passbolt 😉

Best,  
Max

P.S: @johndi89 Since your started the thread, could it be possible to close it?

---

<div class="post-metadata">

**Author:** ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)\
**Post date:** [December 30, 2021, 3:02am UTC](https://community.passbolt.com/t/cant-use-android-app/4582/29 "2021-12-30T03:02:47Z")

</div>

(am closing thread after solution has been reached)

---

<div class="post-metadata">

**Author:** ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)\
**Post date:** [December 30, 2021, 3:02am UTC](https://community.passbolt.com/t/cant-use-android-app/4582/30 "2021-12-30T03:02:54Z")

</div>



[Previous page](https://community.passbolt.com/t/cant-use-android-app/4582.md?page=1)
