After upgrading the PBXware system from v4.x to v6.x there may be an issue with client-certificates.crt file missing and nginx service faling to start. Your PBXware GUI shall not be available if this error is present.
If you try to start nginx service with the command:
- /opt/pbxware/sh/nginx
If the following error is displayed:
- nginx: [emerg] SSL_CTX_load_verify_locations("/etc/ssl/client-ca/client-certificates.crt") failed (SSL: error:02001002:system library:fopen:No such file or directory:fopen('/etc/ssl/client-ca/client-certificates.crt','r') error:2006D080:BIO routines:BIO_new_file:no such file error:0B084002:x509 certificate routines:X509_load_cert_crl_file:system lib)
If you check:
- ls -lah /opt/pbxware/pw/etc/ssl/certs/
You shall notice that folder client-ca is missing as well as the client-certificates.crt file. You will need to create these manually.
Make sure to perform the steps below to fix it:
- Make sure nginx service is stopped
/opt/pbxware/sh/nginx -s stop
- If you are unable to stop it using the command above, make sure to kill the running any active process
ps fax | grep nginx
kill -9 PID
- Navigate to :
cd /opt/pbxware/pw/etc/ssl/
mkdir client-ca
- Navigate to the created directory
cd client-ca
touch client-certificates.crt
After this try to start nginx:
- /opt/pbxware/sh/nginx
If it still fails to start, make sure to stop the process again and copy the content of the file:
- /opt/pbxware/pw/etc/ssl/nginx/nginx.crt
into
- /opt/pbxware/pw/etc/ssl/certs/client-ca/client-certificates.crt