# Could not verify server key. The OpenPGP server key defined in the config could not be found in the GnuPG keyring

**URL:** https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855
**Category:** Installation Issues
**Created:** [July 18, 2018, 1:24pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855 "2018-07-18T13:24:36Z")
**Posts on this page:** 11
**Page:** 2

<div class="post-metadata">

### Author: ![mzanetti](https://avatars.discourse-cdn.com/v4/letter/m/b3f665/32.png) [@mzanetti](https://community.passbolt.com/u/mzanetti)
#### Post date: [July 23, 2018, 1:33pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/21 "2018-07-23T13:33:11Z")

</div>

Hello Kevin,  
thank you for your reply! 🙂

This is the output of the first command

```
/var/www/.gnupg/pubring.gpg
---------------------------
pub 2048R/08750EFE 2018-07-17
uid Marco Zanetti (Chissà a cosa serve) <marco.zanetti@company.com>
sub 2048R/88638305 2018-07-17

pub 2048R/5335C8B5 2018-07-18
uid Company Testing (Company Testing key) <company.testing@gmail.com>
sub 2048R/F23A5957 2018-07-18

```

and this is the output of the second one

```
/var/www/.gnupg/secring.gpg
---------------------------
sec 2048R/08750EFE 2018-07-17
uid Marco Zanetti (Chissà a cosa serve) <marco.zanetti@company.com>
ssb 2048R/88638305 2018-07-17

sec 2048R/5335C8B5 2018-07-18
uid Company Testing (Company Testing key) <company.testing@gmail.com>
ssb 2048R/F23A5957 2018-07-18

```

I don’t really know what I should see. The only thing I can tell you is that the key generated with [marco.zanetti@company.com](mailto:marco.zanetti@company.com) was the first one I generated. Then, since I got errors, I created a new one with the [company.testing@gmail.com](mailto:company.testing@gmail.com) address. That does not work either.

the output of gpg --version is the following

```
gpg (GnuPG) 1.4.20
Copyright (C) 2015 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

Home: ~/.gnupg
Supported algorithms:
Pubkey: RSA, RSA-E, RSA-S, ELG-E, DSA
Cipher: IDEA, 3DES, CAST5, BLOWFISH, AES, AES192, AES256, TWOFISH,
        CAMELLIA128, CAMELLIA192, CAMELLIA256
Hash: MD5, SHA1, RIPEMD160, SHA256, SHA384, SHA512, SHA224
Compression: Uncompressed, ZIP, ZLIB, BZIP2
```

---

<div class="post-metadata">

### Author: ![kevin](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/kevin/32/128_2.png) [@kevin](https://community.passbolt.com/u/kevin)
#### Post date: [July 23, 2018, 1:39pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/22 "2018-07-23T13:39:54Z")

</div>

Alright.

The fact that you are using GPG V1.x could be the cause of your issue, but it’s not certain. If possible, try to upgrade to GPG V2, delete your keyring completely (rm -fr /var/www/.gnupg) , and import your keys again.

Otherwise, could you add the `--fingerprint` parameter to the 2 commands and update the output given in your previous post? What I am trying to figure is whether the fingerprint provided in your configuration file is also in your keyring for both the public and private server key.

---

<div class="post-metadata">

### Author: ![mzanetti](https://avatars.discourse-cdn.com/v4/letter/m/b3f665/32.png) [@mzanetti](https://community.passbolt.com/u/mzanetti)
#### Post date: [July 23, 2018, 1:55pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/23 "2018-07-23T13:55:48Z")

</div>

In Ubuntu gpg and gpg2 are two separate commands. Should I perform everything with gpg2 and not gpg?

If so, please notice that the first command output would be

```
/var/www/.gnupg/pubring.gpg
---------------------------
pub rsa2048/08750EFE 2018-07-17 [SC]
uid [unknown] Marco Zanetti (Chissà a cosa serve) <marco.zanetti@company.com>
sub rsa2048/88638305 2018-07-17 [E]

pub rsa2048/5335C8B5 2018-07-18 [SC]
uid [unknown] Company Testing (Company Testing key) <company.testing@gmail.com>
sub rsa2048/F23A5957 2018-07-18 [E]

```

and the second

```
/var/www/.gnupg/pubring.gpg
---------------------------
sec rsa2048/08750EFE 2018-07-17 [SC]
uid [unknown] Marco Zanetti (Chissà a cosa serve) <marco.zanetti@company.com>
ssb rsa2048/88638305 2018-07-17 [E]

```

I can’t help but noticing that the second key is absent from the “secrets” keyring

---

<div class="post-metadata">

### Author: ![mzanetti](https://avatars.discourse-cdn.com/v4/letter/m/b3f665/32.png) [@mzanetti](https://community.passbolt.com/u/mzanetti)
#### Post date: [July 23, 2018, 1:57pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/24 "2018-07-23T13:57:37Z")

</div>

Also, this is the output of the plain gpg commands (not gpg2) with the --fingerprint flag

```
/var/www/.gnupg/pubring.gpg
---------------------------
pub 2048R/08750EFE 2018-07-17
      Key fingerprint = 879D 5094 6E51 18B3 E675 682F 6F7F 2E33 0875 0EFE
uid Marco Zanetti (Chissà a cosa serve) <marco.zanetti@company.com>
sub 2048R/88638305 2018-07-17

pub 2048R/5335C8B5 2018-07-18
      Key fingerprint = EB8D CF29 1ED1 E680 91E3 8F69 A6DA 4E2D 5335 C8B5
uid company Testing (company Testing key) <company.testing@gmail.com>
sub 2048R/F23A5957 2018-07-18

```

and

```
/var/www/.gnupg/secring.gpg
---------------------------
sec 2048R/08750EFE 2018-07-17
      Key fingerprint = 879D 5094 6E51 18B3 E675 682F 6F7F 2E33 0875 0EFE
uid Marco Zanetti (Chissà a cosa serve) <marco.zanetti@company.com>
ssb 2048R/88638305 2018-07-17

sec 2048R/5335C8B5 2018-07-18
      Key fingerprint = EB8D CF29 1ED1 E680 91E3 8F69 A6DA 4E2D 5335 C8B5
uid company Testing (company Testing key) <company.testing@gmail.com>
ssb 2048R/F23A5957 2018-07-18

```

Fingerprints look pretty the same to me

---

<div class="post-metadata">

### Author: ![mzanetti](https://avatars.discourse-cdn.com/v4/letter/m/b3f665/32.png) [@mzanetti](https://community.passbolt.com/u/mzanetti)
#### Post date: [July 23, 2018, 1:58pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/25 "2018-07-23T13:58:16Z")

</div>

> [@kevin](#):
>
> rm -fr /var/www/.gnupg

I would delete the keyring and import them again but… with which command(s) then?

---

<div class="post-metadata">

### Author: ![kevin](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/kevin/32/128_2.png) [@kevin](https://community.passbolt.com/u/kevin)
#### Post date: [July 23, 2018, 2:04pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/26 "2018-07-23T14:04:14Z")

</div>

Alright. Then indeed it’s best to delete the keyring and start fresh again. There might be some conflicts between GPGv1 and GPGv2, as we have already seen in the past.

The keyring will be created automatically when you import your keys. So:  
`sudo su -s /bin/bash -c "gpg2 --import name_of_your_secret_key" www-data`

The imported key must be the same as the one defined in your passbolt.php file. (same file, same fingerprint)

Then you can run the healthcheck again to see if it’s working.

---

<div class="post-metadata">

### Author: ![mzanetti](https://avatars.discourse-cdn.com/v4/letter/m/b3f665/32.png) [@mzanetti](https://community.passbolt.com/u/mzanetti)
#### Post date: [July 23, 2018, 2:36pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/27 "2018-07-23T14:36:29Z")

</div>

Thank you Kevin.

I performed  
`rm -fr /var/www/.gnupg`  
and then  
`sudo su -s /bin/bash -c "gpg2 --import /var/www/passbolt_api/config/gpg/serverkey_private.asc" www-data`

now if I look at the keys I see

```
mzanetti@localhost:~$ sudo su -s /bin/bash -c "gpg2 --list-keys --fingerprint" www-data
/var/www/.gnupg/pubring.kbx
---------------------------
pub rsa2048/5335C8B5 2018-07-18 [SC]
      Key fingerprint = EB8D CF29 1ED1 E680 91E3 8F69 A6DA 4E2D 5335 C8B5
uid [unknown] company Testing (company Testing key) <company.testing@gmail.com>
sub rsa2048/F23A5957 2018-07-18 [E]

mzanetti@localhost:~$ sudo su -s /bin/bash -c "gpg2 --list-secret-keys --fingerprint" www-data
/var/www/.gnupg/pubring.kbx
---------------------------
sec rsa2048/5335C8B5 2018-07-18 [SC]
      Key fingerprint = EB8D CF29 1ED1 E680 91E3 8F69 A6DA 4E2D 5335 C8B5
uid [unknown] company Testing (company Testing key) <company.testing@gmail.com>
ssb rsa2048/F23A5957 2018-07-18 [E]

```

It looks all VERY fine to me. The keys are the same, I just have one issue…

![Selection_077](https://canada1.discourse-cdn.com/flex031/uploads/passbolt/original/1X/c4045219a4d2832033a58a41ca9fcedfc7185c93.png)

The error is always there!!! -.-

---

<div class="post-metadata">

### Author: ![remy](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/remy/32/17_2.png) [@remy](https://community.passbolt.com/u/remy)
#### Post date: [July 23, 2018, 2:40pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/28 "2018-07-23T14:40:13Z")

</div>

You need to perform a user account recover (or create a new user and follow the setup) for the new server key to be taken into account by the user browser extension.

---

<div class="post-metadata">

### Author: ![mzanetti](https://avatars.discourse-cdn.com/v4/letter/m/b3f665/32.png) [@mzanetti](https://community.passbolt.com/u/mzanetti)
#### Post date: [July 23, 2018, 2:56pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/29 "2018-07-23T14:56:00Z")

</div>

![Selection_078](https://canada1.discourse-cdn.com/flex031/uploads/passbolt/original/1X/918dc84bfe31600429a2fea4314d7346537753f7.png)

Thank you!

I can’t believe that with your help I finally made it! \<3

Thank you so much to all of you!

---

<div class="post-metadata">

### Author: ![kevin](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/kevin/32/128_2.png) [@kevin](https://community.passbolt.com/u/kevin)
#### Post date: [July 23, 2018, 5:33pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/30 "2018-07-23T17:33:58Z")

</div>

Glad that it’s finally working! Enjoy Passbolt 😉

---

<div class="post-metadata">

### Author: ![system](https://canada1.discourse-cdn.com/flex031/uploads/passbolt/original/2X/b/bee7d3f9329f668000d46e9fcb2e5db1e9d31348.svg) [@system](https://community.passbolt.com/u/system)
#### Post date: [July 28, 2018, 5:34pm UTC](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855/31 "2018-07-28T17:34:00Z")

</div>

This topic was automatically closed 5 days after the last reply. New replies are no longer allowed.

[Previous page](https://community.passbolt.com/t/could-not-verify-server-key-the-openpgp-server-key-defined-in-the-config-could-not-be-found-in-the-gnupg-keyring/855.md?page=1)
