The server metadata private key is not valid

Checklist
I have read intro post: https://community.passbolt.com/t/about-the-installation-issues-category/12
I have read the tutorials, help and searched for similar issues
I provide relevant information about my server (component names and versions, etc.)
I provide a copy of my logs and healthcheck
I describe the steps I have taken to trouble shoot the problem
I describe the steps on how to reproduce the issue

I have an error in healthcheck:

[FAIL] The server metadata private key is not valid. Unable to validate metadata private key (id: <id>) cleartext data.

before that, I changed the domain name and migrated to another server.

the system itself is working correctly, all users have no problems with keys and metadata.

how can I fix the error in healthcheck output?

 Environment

 [WARN] Cannot detect your system distribution details.
 [HELP] See `uname -a`.
 [PASS] PHP version 8.3.6.
 [PASS] PHP version is 8.2 or above.
 [PASS] 64-bit architecture system detected.
 [WARN] Cannot detect your `gpg` or `libgcrypt` version.
 [HELP] See `gpg --version | grep gpg` and `gpg --version | grep libgcrypt`.
 [PASS] PCRE compiled with unicode support.
 [PASS] Mbstring extension is installed.
 [PASS] Intl extension is installed.
 [PASS] GD or Imagick extension is installed.
 [PASS] The temporary directory and its content are writable and not executable.
 [PASS] The logs directory /var/log/passbolt/ and its content are writable.
 [WARN] System clock and NTP service information cannot be found.
 [HELP] See `timedatectl | grep -i -A 1 clock`. More information: https://www.passbolt.com/docs/hosting/configure/ntp/

 Config files

 [PASS] The application config file is present
 [PASS] The passbolt config file is present

 Core config

 [PASS] Cache is working.
 [PASS] Debug mode is off.
 [PASS] Unique value set for security.salt
 [PASS] Full base url is set to https://pwd.magicwebs.dev
 [PASS] App.fullBaseUrl validation OK.
 [PASS] /healthcheck/status is reachable.

 SSL Certificate

 [PASS] SSL peer certificate validates.
 [PASS] Hostname is matching in SSL certificate.
 [PASS] Not using a self-signed certificate.

 SMTP settings

 [PASS] The SMTP Settings plugin is enabled.
 [PASS] SMTP Settings coherent. You may send a test email to validate them.
 [PASS] The SMTP Settings source is: database.
 [WARN] The SMTP Settings plugin endpoints are enabled.
 [HELP] It is recommended to disable the plugin endpoints.
 [HELP] Set the PASSBOLT_SECURITY_SMTP_SETTINGS_ENDPOINTS_DISABLED environment variable to true.
 [HELP] Or set passbolt.security.smtpSettings.endpointsDisabled to true in /etc/passbolt/passbolt.php.
 [PASS] No custom SSL configuration for SMTP server.

 JWT Authentication

 [PASS] The JWT Authentication plugin is enabled.
 [PASS] The /etc/passbolt/jwt/ directory is not writable.
 [PASS] A valid JWT key pair was found.

 GPG Configuration

 [PASS] PHP GPG Module is installed and loaded.
 [PASS] The environment variable GNUPGHOME is set to /var/lib/passbolt/.gnupg.
 [PASS] The directory /var/lib/passbolt/.gnupg containing the keyring is writable by the webserver user.
 [PASS] The server OpenPGP key is not the default one.
 [PASS] The public key file is defined in /etc/passbolt/passbolt.php and readable.
 [PASS] The private key file is defined in /etc/passbolt/passbolt.php and readable.
 [PASS] The server key fingerprint matches the one defined in /etc/passbolt/passbolt.php.
 [PASS] The server public key defined in the /etc/passbolt/passbolt.php (or environment variables) is in the keyring.
 [PASS] There is a valid email id defined for the server key.
 [PASS] The public key can be used to encrypt a message.
 [PASS] The private key can be used to sign a message.
 [PASS] The public and private keys can be used to encrypt and sign a message.
 [PASS] The private key can be used to decrypt a message.
 [PASS] The private key can be used to decrypt and verify a message.
 [PASS] The public key can be used to verify a signature.
 [PASS] The server public key format is Gopengpg compatible.
 [PASS] The server private key format is Gopengpg compatible.

 Application configuration

 [PASS] Using latest passbolt version (5.7.2).
 [PASS] Passbolt is configured to force SSL use.
 [PASS] App.fullBaseUrl is set to HTTPS.
 [PASS] Selenium API endpoints are disabled.
 [PASS] Search engine robots are told not to index content.
 [INFO] The Self Registration plugin is enabled.
 [INFO] Registration is closed, only administrators can add users.
 [WARN] The deprecated self registration public setting was found in /etc/passbolt/passbolt.php.
 [HELP] You may remove the "passbolt.registration.public" setting.
 [WARN] Host availability checking is disabled.
 [HELP] Make sure this instance is not publicly available on the internet.
 [HELP] Or set the PASSBOLT_EMAIL_VALIDATE_MX environment variable to true.
 [HELP] Or set passbolt.email.validate.mx to true in /etc/passbolt/passbolt.php.
 [PASS] Serving the compiled version of the javascript app.
 [WARN] Some email notifications are disabled by the administrator.
 [PASS] The database schema is up to date.

 Database

 [PASS] The application is able to connect to the database
 [PASS] 35 tables found.
 [PASS] Some default content is present.

 Metadata

 [PASS] The server is able to decrypt the metadata private key.
 [PASS] Active metadata key found or not required.
 [PASS] The server has access to the metadata keys or does not require access to it.
 [FAIL] The server metadata private key is not valid. Unable to validate metadata private key (id: ef963a84-0e98-4dd6-8745-8109a95ec870) cleartext data.

 [FAIL] 1 error(s) found. Hang in there!

Hello @sergei57701, apologies for the delay there :slight_smile:

This error seems similar than this one, can you please double-check and proceed with the instructions shared? Don’t forget to take a backup before moving further for the peace sake of mind :rocket:

Hi,

we actually do encounter the same problem i have checked the other Thread as well, but it does not seem to fit the problem.

After installing passbolt and setting up the server with a CLI generated gpg key as mentioned here ( https://www.passbolt.com/docs/hosting/install/ce/debian/#:\~:text=to%20use%20it.-,WARNING,-Since%20GnuPG%202.2.0 ) When logging in first the first user that we set up, after choosing a Password and the BrowserIdentification Thingy we get the following error.

{
“fileName”: “moz-extension://3e85b2a7-02ea-4a4a-b1c9-399962189dc3/index.min.js”,
“lineNumber”: 2,
“columnNumber”: 58504,
“message”: “Der Metadaten-Schlüssel konnte nicht gespeichert werden.”,
“name”: “PassboltApiFetchError”,
“data”: {
“code”: 400,
“body”: {
“armored_key”: {
“isPublicKeyValidStrict”: “Der armored Schlüssel ist ungültig.”
}
}
}
}

If we now go to the Administraion of the Organisation we are presented with the first steps →

If we try to activate the Metadata we get the following error →

{
“code”: 400,
“body”: {
“armored_key”: {
“isPublicKeyValidStrict”: “Der armored Schlüssel ist ungültig.”
}
}
}