1. Bicom Systems
  2. Solution home
  3. SERVERware
  4. HOWTOs SERVERware 5

How To fix NGINX unable to start after upgrade from v4.x to v6.x

After upgrading the PBXware system from v4.x to v6.x there may be an issue with client-certificates.crt file missing and nginx service faling to start. Your PBXware GUI shall not be available if this error is present.



If you try to start nginx service with the command:


  • /opt/pbxware/sh/nginx


If the following error is displayed:

  • nginx: [emerg] SSL_CTX_load_verify_locations("/etc/ssl/client-ca/client-certificates.crt") failed (SSL: error:02001002:system library:fopen:No such file or directory:fopen('/etc/ssl/client-ca/client-certificates.crt','r') error:2006D080:BIO routines:BIO_new_file:no such file error:0B084002:x509 certificate routines:X509_load_cert_crl_file:system lib)


If you check:

  • ls -lah /opt/pbxware/pw/etc/ssl/certs/

You shall notice that folder client-ca is missing as well as the client-certificates.crt file. You will need to create these manually. 


Make sure to perform the steps below to fix it:


  • Make sure nginx service is stopped

               /opt/pbxware/sh/nginx -s stop

  • If you are unable to stop it using the command above, make sure to kill the running any active process 

               ps fax | grep nginx

               kill -9 PID


  • Navigate to :

                cd /opt/pbxware/pw/etc/ssl/

                mkdir client-ca

  • Navigate to the created directory

               cd client-ca

                touch client-certificates.crt


After this try to start nginx:


  • /opt/pbxware/sh/nginx


If it still fails to start, make sure to stop the process again and copy the content of the file:


  • /opt/pbxware/pw/etc/ssl/nginx/nginx.crt

           into

  • /opt/pbxware/pw/etc/ssl/certs/client-ca/client-certificates.crt