• Recent
    • Unsolved
    • Tags
    • Popular
    • Users
    • Groups
    • Search
    • Register
    • Login

    ...boot.php... Permission denied

    Scheduled Pinned Locked Moved Solved
    FOG Problems
    6
    21
    6.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Malte Will @george1421
      last edited by

      @george1421 ,
      I can access the web UI without any problems.
      I can also access the boot.php in my browser.

      In the apache logs there is nothing appearing.

      The certificates we use are valid till august.

      george1421G 1 Reply Last reply Reply Quote 0
      • S
        Sebastian Roth Moderator
        last edited by

        @Malte-Will URLs are https://. Did you manually enable this or install with --force-https option?

        Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

        Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

        M 1 Reply Last reply Reply Quote 0
        • george1421G
          george1421 Moderator @Malte Will
          last edited by george1421

          @Malte-Will You can access the web ui using https?

          If ipxe was not recompiled with the certificate so that I understands https you might get that error message too.

          Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG!

          M 1 Reply Last reply Reply Quote 0
          • S
            Sebastian Roth Moderator
            last edited by

            @Malte-Will said in .../boot.php... Permission denied:

            After the weekend, our FOG-Server is not working properly anymore.

            Certificate not valid anymore? But that would mean you’ve installed your FOG server many years ago.

            Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

            Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

            1 Reply Last reply Reply Quote 0
            • M
              Malte Will @Sebastian Roth
              last edited by

              @Sebastian-Roth,
              I eneabled https on installation with the -S (–force-https) option.
              I build ipxe with the correct certificate.

              1 Reply Last reply Reply Quote 0
              • M
                Malte Will @george1421
                last edited by

                @george1421,
                We use our own certificates and I compiled the ipxe with the correct CA certificate.

                george1421G 1 Reply Last reply Reply Quote 0
                • george1421G
                  george1421 Moderator @Malte Will
                  last edited by george1421

                  @Malte-Will So you are able to connect to https://<fog_server_ip>/fog/service/ipxe/boot.php just fine AND by inspecting the certificate it is the correct certificate to what you expected? This sure does appear like a certificate mismatch between ipxe and the apache web server.

                  Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG!

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    Malte Will @george1421
                    last edited by Malte Will

                    @george1421 I just rebuild the ipxe files with the correct CA-certificate, just to check if I messed up and I am still getting the error. I don’t think it is a mismatch. It worked before with the exact same certificates.

                    Yes I am able to connect to https://<fog_server_ip>/fog/service/ipxe/boot.php just fine. It also shows the correct certificate.

                    george1421G 1 Reply Last reply Reply Quote 0
                    • george1421G
                      george1421 Moderator @Malte Will
                      last edited by

                      @Malte-Will I don’t know of a way off the top of my head to confirm the certificate identity in ipxe vs what the web server has. I wonder for grins if you edit /tftpboot/default.ipxe and for a test remove the s from https and then save it. Then pxe boot. I’m interested if you get the same permission denied message.

                      Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG!

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        Malte Will @george1421
                        last edited by

                        @george1421 I first tried to set the SSLCertificateChainFile in the apache site config to the original cert and then back to the one we use, after restarting apache I now get the following error code while booting with pxe: 0x432fe698
                        I think my system is cursed.

                        1 Reply Last reply Reply Quote 0
                        • S
                          Sebastian Roth Moderator
                          last edited by Sebastian Roth

                          @Malte-Will said:

                          I first tried to set the SSLCertificateChainFile in the apache site config …

                          Good you mention this. Take a look at my comment here: https://github.com/FOGProject/fogproject/pull/354#discussion_r359494768 - seems like we still have this issue in the code. While I am not sure if this is causing the iPXE issue it definitely should be changed! Please try SSLCACertificateFile (instead of SSLCertificateChainFile) and ca.cert.pem (instead of ca.cert.der).

                          If not then we need to start taking a closer look at the certificates you are actually using.

                          After the weekend, our FOG-Server is not working properly anymore.

                          I am still wondering why it worked before? What changed? Did you do Linux system updates? Changed a config? Re-ran the FOG installer?

                          Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                          Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                          1 Reply Last reply Reply Quote 0
                          • S
                            Sebastian Roth Moderator
                            last edited by

                            @Malte-Will bump

                            Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                            Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                            1 Reply Last reply Reply Quote 0
                            • S
                              Sebastian Roth Moderator
                              last edited by

                              @Malte-Will When doing some testing myself yesterday I figured what’s wrong with this. Should have done this earlier but there was so much else on the list.

                              Take a look at this change: https://github.com/FOGProject/fogproject/commit/e424b0417fc56dba2d7ba34665817e0f7b0f857c

                              For some yet unknown reason the build parameters need to be in different order to make this work. I find it very strange because we had a similar thing with the build parameter (ref) and I am fairly sure I did test this when pushing the change in Jun 2019. My assumption is a change in the make files were causing this again. Hope this is fixed now and shouldn’t come back.

                              Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                              Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                              1 Reply Last reply Reply Quote 0
                              • J
                                jasonm
                                last edited by jasonm

                                @Sebastian-Roth

                                I have just upgraded my fog server to 1.5.9-RC1.4 not sure if this issue is still present. I am receiving the following error message when trying to pxe boot.

                                https://“InternalIPAddress”/fog/service/ipxe/boot.php… Permission denied (http://ipxe.org/0216eb8f)
                                Could not boot: Permission denied (http://ipxe.org/0216eb8f)

                                Cheers

                                Jason

                                1 Reply Last reply Reply Quote 0
                                • S
                                  Sebastian Roth Moderator
                                  last edited by

                                  @jasonm Please try this:

                                  sudo -i
                                  touch /opt/fog/snapins/ssl/CA/.fogCA.pem
                                  cd /path/to/fogproject/bin
                                  ./installfog.sh
                                  

                                  Please let us know if the issue can be solved this way. I will need to fix that in the installer.

                                  Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                                  Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                                  1 Reply Last reply Reply Quote 1
                                  • Chris ShipleyC
                                    Chris Shipley
                                    last edited by

                                    @Sebastian-Roth I had the same symptoms that @jasonm had. I tried the resolution you put on May 6, 2020 and that worked to resolve my permission denied issue.

                                    1 Reply Last reply Reply Quote 1
                                    • S
                                      Sebastian Roth Moderator
                                      last edited by

                                      @Chris-Shipley Thanks for bringing this topic back up again as I had lost track of this.

                                      Just pushed a commit to take care of this.

                                      Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                                      Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                                      Chris ShipleyC 1 Reply Last reply Reply Quote 1
                                      • Chris ShipleyC
                                        Chris Shipley @Sebastian Roth
                                        last edited by

                                        @Sebastian-Roth excellent, thanks!

                                        1 Reply Last reply Reply Quote 0
                                        • N
                                          nickw @Sebastian Roth
                                          last edited by george1421

                                          @Sebastian-Roth
                                          https://forums.fogproject.org/topic/14733/permission-denied-on-boot-php

                                          Mod note: Moved topics to new above thread -Geo

                                          1 Reply Last reply Reply Quote 0
                                          • 1
                                          • 2
                                          • 1 / 2
                                          • First post
                                            Last post

                                          150

                                          Online

                                          12.0k

                                          Users

                                          17.3k

                                          Topics

                                          155.2k

                                          Posts
                                          Copyright © 2012-2024 FOG Project