Install Passbolt CE on Ubuntu 20.04
For this tutorial, you will need:
A minimal Ubuntu 20.04 server.
A domain / host name pointing to your server, or at least being able to reach your server through a static IP address.
The recommended server requirements are:
- 2 cores
- 2GB of RAM
1. Install the server components
1.1. Package repository setup
For easier installation and update tasks Passbolt provides a package repository that you need to setup before you download Passbolt CE and install it.
These steps assume you have already installed sudo and added your user to the sudo group.
Step 1. Update the apt indexes and install packages to allow apt to use https repositories:
sudo apt update sudo apt install \ apt-transport-https \ ca-certificates \ curl \ gnupg-agent \ software-properties-common
Step 2. Let’s Encrypt
Install certbot if you plan to manage your SSL certificates with Let’s Encrypt:
sudo apt install certbot python3-certbot-nginx
Step 3. Add Passbolt package official GnuPG key from keys.mailvelope.com:
gpg --keyserver hkps://keys.mailvelope.com --recv-keys 0xDE8B853FC155581D
Or alternatively from hkps://pgp.mit.edu or hkps://keys.gnupg.net.
Step 4. Check that the GPG fingerprint matches
3D1A 0346 C8E1 802F 774A EF21 DE8B 853F C155 581D
gpg --list-key --with-fingerprint 0xDE8B853FC155581D
pub rsa2048 2020-05-18 [SC] [expires: 2022-05-18] 3D1A 0346 C8E1 802F 774A EF21 DE8B 853F C155 581D uid [ unknown] Passbolt SA package signing key <[email protected]> sub rsa2048 2020-05-18 [E] [expires: 2022-05-18]
Step 5. Create GPG package keyring
gpg --export 0xDE8B853FC155581D | sudo tee \ /usr/share/keyrings/passbolt-repository.gpg >/dev/null
Step 6. Add passbolt repository:
cat << EOF | sudo tee /etc/apt/sources.list.d/passbolt.sources > /dev/null Types: deb URIs: https://download.passbolt.com/ce/ubuntu Suites: focal Components: stable Signed-By: /usr/share/keyrings/passbolt-repository.gpg EOF
Step 7. Update the apt indexes with the new passbolt apt repository:
sudo apt update
1.2. Install passbolt
By default, passbolt Ubuntu package will install Passbolt server component, mariadb-server, php-fpm and nginx as dependencies.
There are two main ways to install the passbolt Ubuntu package:
- Interactive: the package will guide the user through a set of questions to setup mariadb and nginx. If you are going to use existing SSL certs for the web server, they need to be created and installed to the location of your choosing before beginning. The user will be asked for the path and name of the certificate and key.
- Non-interactive: no questions will be asked. Useful for users with specific needs or users that want to automate the installation. Read this FAQ page to know more
Install passbolt package
Install the main passbolt server component:
sudo apt install passbolt-ce-server
If not instructed otherwise passbolt ubuntu package will install mariadb-server locally. This step will help you create an empty mariadb database for passbolt to use.
The configuration process will ask you for the credentials of the mariadb admin user to create a new database.
By default in most installations the admin username would be
root and the password would be empty.
Now we need to create a mariadb user with reduced permissions for passbolt to connect. These values will also be requested later on the webconfiguration tool of passbolt so please keep them in mind.
Lastly we need to create a database for passbolt to use, for that we need to name it:
Configure nginx for serving HTTPS
Depending on your needs there are two different options to setup nginx and SSL using the Ubuntu package:
2. Configure passbolt
Before you can use the application, you need to configure it. Point your browser to the hostname / ip where passbolt can be reached. You will reach a getting started page.
The first page of the wizard will tell you if your environment is ready for passbolt. Solve issues if any and click on “Start configuration” when ready.
This step is about telling passbolt which database to use. Enter the host name, port number, database name, username and password.
2.3. GPG key
In this section you can either generate or import a GPG key pair. This key pair will be used by passbolt API to authenticate itself during the login handshake process.
Generate a key if you don’t have one.
Optional: Import a key if you already have one and you want your server to use it.
To create a new GnuPG key without passphrase:
gpg --batch --no-tty --gen-key <<EOF Key-Type: default Key-Length: 2048 Subkey-Type: default Subkey-Length: 2048 Name-Real: John Doe Name-Email: [email protected] Expire-Date: 0 %no-protection %commit EOF
Feel free to replace Name-Real and Name-Email with your own.
To display your new key:
gpg --armor --export-secret-keys [email protected]
2.4. Mail server (SMTP)
At this stage, the wizard will ask you to enter the details of your SMTP server.
You can also test that your configuration is correct by using the test email feature at the right of your screen. Enter the email address at which you want the wizard to send you a test email and click on “Send test email”.
The wizard will then ask you what preferences you prefer for your instance of passbolt. The recommended defaults are already pre-populated but you can also change them if you know what you are doing.
2.6. First user creation
You need to create the first admin user account. This first admin user is probably you, so enter your details and click on next.
That’s it. The wizard has now enough information to proceed with the configuration of passbolt. Sit back and relax for a few seconds while the configuration process is going on.
Your user account is now created. You will see a redirection page for a few second and then will be redirected to the user setup process so that you can configure your user account.
3. Configure your administrator account
3.1. Download the plugin
Before continuing passbolt will require you to download its plugin. If you already have it installed you can go to the next step.
3.2. Create a new key
Passbolt will ask you to create or import a key that will be later use to identify you and encrypt your passwords. Your key needs to be protected by a password. Choose it wisely, it will be the gatekeeper to all your other passwords.
3.3. Download your recovery kit
This step is essential. Your key is the only way to access your account and passwords. If you lose this key (by breaking or losing your computer and not having a backup for example), your encrypted data will be lost even if you remember your passphrase.
3.4. Define your security token
Choosing a color and a three characters token is a secondary security mechanism that helps you to mitigate phishing attacks. Each time you are performing a sensitive operation on passbolt, you should see this token.
3.5. That’s it!
Your administrator account is configured. You will be redirected to the login page of passbolt. Enjoy!
This article was last updated on November 24th, 2021.