# Access to file denied Cert-chain

**URL:** <https://forum.collaboraonline.com/t/access-to-file-denied-cert-chain/498>\
**Category:** Installation & Configuration\
**Created:** [July 27, 2021, 10:37am UTC](https://forum.collaboraonline.com/t/access-to-file-denied-cert-chain/498 "2021-07-27T10:37:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![guenie](https://avatars.discourse-cdn.com/v4/letter/g/c5a1d2/32.png) [@guenie](https://forum.collaboraonline.com/u/guenie)\
**Post date:** [July 27, 2021, 10:37am UTC](https://forum.collaboraonline.com/t/access-to-file-denied-cert-chain/498/1 "2021-07-27T10:37:19Z")

</div>

I have a Problem to install loolwsd my Certificates was not read  
I have this ERROR in the Log  
cloud loolwsd[84797]: Access to file denied: /etc/letsencrypt/live/cloud.xxxxxxxxx.at/chain-ecdsa.pem

Is the path to long ? I have the same path and cert in apache server this is working?  
I have set up before a test system this is working

Can any help for this Problem

Thanks Günther

---

<div class="post-metadata">

**Author:** ![rpear](https://avatars.discourse-cdn.com/v4/letter/r/b5ac83/32.png) [@rpear](https://forum.collaboraonline.com/u/rpear)\
**Post date:** [July 29, 2021, 8:38am UTC](https://forum.collaboraonline.com/t/access-to-file-denied-cert-chain/498/2 "2021-07-29T08:38:32Z")

</div>

I don’t know about your setup, just thought I’d mention that 6.4.10-6 was released a day ago, it includes this fix which has helped a lot of people out, hope it helps you too, pls reply to let others know if it helps:

> <https://github.com/CollaboraOnline/online/commit/77cb6faa2726824ecb7c2538e6b2cb00f87b71be>
>
> For some servers we receive failure with HTTP 403 Forbidden in WOPI::CheckFileIn…fo
> 
> "Reason: The client software did not provide a hostname using Server
> Name Indication (SNI), which is required to access this server"
> 
> fixes #2771 : https://github.com/CollaboraOnline/online/issues/2771
> 
> Signed-off-by: Szymon Kłos \<szymon.klos@collabora.com\>
> Change-Id: I761b179580481f8882a4526c1d8be4f1c14ad929

---

<div class="post-metadata">

**Author:** ![guenie](https://avatars.discourse-cdn.com/v4/letter/g/c5a1d2/32.png) [@guenie](https://forum.collaboraonline.com/u/guenie)\
**Post date:** [July 30, 2021, 10:16am UTC](https://forum.collaboraonline.com/t/access-to-file-denied-cert-chain/498/3 "2021-07-30T10:16:48Z")

</div>

I have the newest now 6.4.10.20 but the same Problem?

a question is there a limit for the length of the ssl paths? Because I have already set up two test systems where I had no problems with the certificates?  
what works is  
/etc/letsencrypt/live/cloud.xxxx.xxx/chain-ecdsa.pem

what is not working  
/etc/letsencrypt/live/cloud.xxxxxxxxx.xx/chain-ecdsa.pem  
I have exactly the same configuration on all systems

---

<div class="post-metadata">

**Author:** ![bearon](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@bearon](https://forum.collaboraonline.com/u/bearon)\
**Post date:** [September 2, 2021, 4:35pm UTC](https://forum.collaboraonline.com/t/access-to-file-denied-cert-chain/498/4 "2021-09-02T16:35:40Z")

</div>

I don’t think it’s the length of the path… `/etc/letsencrypt/live/` tends to be owned by root, and not accessible to anyone else (which is generally desirable, as you want private keys to be actually private). A couple of options on how to solve this situation are detailed here: [node.js - Let's encrypt SSL couldn't start by "Error: EACCES: permission denied, open '/etc/letsencrypt/live/domain.net/privkey.pem'" - Stack Overflow](https://stackoverflow.com/questions/48078083/lets-encrypt-ssl-couldnt-start-by-error-eacces-permission-denied-open-et)

Another option is to set up a terminating reverse proxy, so the certificate handling is done by the reverse proxy (eg. Apache2 or nginx), and not by Collabora Online.

---

<div class="post-metadata">

**Author:** ![guenie](https://avatars.discourse-cdn.com/v4/letter/g/c5a1d2/32.png) [@guenie](https://forum.collaboraonline.com/u/guenie)\
**Post date:** [September 21, 2021, 1:47pm UTC](https://forum.collaboraonline.com/t/access-to-file-denied-cert-chain/498/5 "2021-09-21T13:47:17Z")

</div>

Hello everyone

After the last update, loolwsd no longer works on the installations that have been working up to now? loowsd can simply no longer read in the certificate files (permission denied), someone could look up why this is getting more and more annoying

---

<div class="post-metadata">

**Author:** ![bearon](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@bearon](https://forum.collaboraonline.com/u/bearon)\
**Post date:** [September 28, 2021, 12:02am UTC](https://forum.collaboraonline.com/t/access-to-file-denied-cert-chain/498/6 "2021-09-28T00:02:38Z")

</div>

Please read my comment above. Also, you could try switching user to `lool`, and try accessing the certificate file to confirm if it’s indeed a permission problem. If it is, you will have to resolve that yourself based on the suggestions given.
