Passbolt is an open-source password manager built for teams: every secret is encrypted in the browser with OpenPGP, and the server only stores ciphertext and sharing permissions. In this tutorial you will install Passbolt Community Edition (CE) on Ubuntu 24.04 using the official Debian package, which sets up PHP, Nginx and a Let's Encrypt certificate for you, with a local MariaDB database. You will then run the web setup wizard, configure outgoing email and create the first administrator.

Prerequisites

To follow this tutorial you need:

  • A fresh server running Ubuntu 24.04 LTS, for example a CubePath VPS, with at least 2 GB of RAM. Passbolt's package configures Nginx and PHP-FPM itself, so do not install it on a server that already hosts other Nginx sites.
  • A non-root user with sudo privileges.
  • A domain or subdomain (this guide uses passbolt.your_domain) with a DNS A record pointing to your_server_ip.
  • SMTP credentials for sending email (host, port, username and password). Passbolt uses email for invitations and account recovery, so it is required in practice.
  • A desktop browser supported by the Passbolt extension (Chrome, Firefox, Edge or Brave).

Step 1 - Opening the firewall

Let's Encrypt must reach the server on port 80 during installation, so open the web ports before installing anything:

sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status
Status: active

To                         Action      From
--                         ------      ----
OpenSSH                    ALLOW       Anywhere
80/tcp                     ALLOW       Anywhere
443/tcp                    ALLOW       Anywhere

Also check that the domain resolves to this server:

dig +short passbolt.your_domain

The output must be your_server_ip.

Step 2 - Creating the MariaDB database

Install MariaDB from the Ubuntu repositories:

sudo apt update
sudo apt install mariadb-server

Create a dedicated database and user for Passbolt. Replace your_strong_password with a long random password and keep it at hand for Step 5:

sudo mariadb <<'SQL'
CREATE DATABASE passbolt CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'passbolt'@'localhost' IDENTIFIED BY 'your_strong_password';
GRANT ALL PRIVILEGES ON passbolt.* TO 'passbolt'@'localhost';
FLUSH PRIVILEGES;
SQL

Confirm that the new user can log in and see its database:

mariadb -u passbolt -p -e "SHOW DATABASES;"
+--------------------+
| Database           |
+--------------------+
| information_schema |
| passbolt           |
+--------------------+

Step 3 - Adding the Passbolt repository

Passbolt publishes a script that adds its APT repository and signing key. Download it together with its checksum file and only run it if the checksum matches:

cd /tmp
curl -LO https://download.passbolt.com/ce/installer/passbolt-repo-setup.ce.sh
curl -LO https://github.com/passbolt/passbolt-dep-scripts/releases/latest/download/passbolt-ce-SHA512SUM.txt
sha512sum -c passbolt-ce-SHA512SUM.txt
passbolt-repo-setup.ce.sh: OK

If you see OK, you can read the script with less passbolt-repo-setup.ce.sh and then run it:

sudo bash ./passbolt-repo-setup.ce.sh

If the checksum fails, delete the file and download it again. Do not run a script that does not match.

Step 4 - Installing the Passbolt package

Install the server package:

sudo apt install --no-install-recommends passbolt-ce-server

The package asks several questions through debconf:

  1. Configure a MySQL/MariaDB database for Passbolt? Answer No. You already created the database, and you will enter its credentials in the web wizard.
  2. Configure Nginx? Answer Yes.
  3. SSL setup: choose auto to request a Let's Encrypt certificate automatically.
  4. Enter your domain (passbolt.your_domain) and an email address for Let's Encrypt notices.

When the installation finishes, confirm that Nginx and PHP-FPM are running and that the site answers over HTTPS:

systemctl is-active nginx php8.3-fpm
curl -sI https://passbolt.your_domain | head -n 1
active
active
HTTP/2 302

The redirect points to the setup wizard, which is expected at this stage.

Step 5 - Running the web setup wizard

Open https://passbolt.your_domain in your browser. The wizard walks you through these screens:

  1. Healthcheck: confirms PHP extensions and permissions are correct. Click Start configuration.
  2. Database: enter host localhost, port 3306, username passbolt, the password from Step 2 and database name passbolt.
  3. Server key: Passbolt generates an OpenPGP key pair for the server. Enter a server name (for example Passbolt your_domain) and an email address.
  4. Options: keep the full base URL https://passbolt.your_domain and leave Force SSL enabled.
  5. Email: enter your SMTP settings and use Send test email to confirm delivery before continuing.
  6. First user: enter the administrator's first name, last name and email.

When the wizard ends, it redirects you to install the Passbolt browser extension. Install it, then continue in the same tab: you will set a passphrase for your personal key and download the recovery kit. Store the recovery kit somewhere safe outside Passbolt. Without it and the passphrase, your account cannot be recovered.

Step 6 - Verifying the installation

Passbolt ships a healthcheck command that must run as the web server user:

sudo -u www-data /usr/share/php/passbolt/bin/cake passbolt healthcheck

The output groups checks by area (environment, config files, core, SSL, database, GPG, application). A healthy install ends with:

 [PASS] No error found. Nice one sparky!

Fix any [FAIL] line before inviting users; the message tells you what is wrong. To test email delivery from the command line, run:

sudo -u www-data /usr/share/php/passbolt/bin/cake passbolt send_test_email --recipient=you@your_domain

The package installs a cron job in /etc/cron.d/ that sends queued emails, so invitations and notifications leave within a minute or two.

Step 7 - Inviting users and sharing passwords

In the Passbolt web UI:

  1. Go to Users, click Create, enter the person's name and email and pick the User or Admin role. They receive an email invitation and complete the same extension and passphrase setup you did.
  2. Go to Users, then Groups, to create a group (for example DevOps) and add members.
  3. Go to Passwords, click Create, fill in name, URL, username and password, then use Share to give a user or group can read, can update or is owner access.

Because encryption happens in the browser, a secret is readable only by the people it is shared with. Administrators manage users but cannot read passwords that were not shared with them.

Step 8 - Backing up Passbolt

A usable backup needs three things: the database, the server OpenPGP keys and the configuration file. Create a backup directory readable only by root:

sudo install -d -m 700 /var/backups/passbolt

Dump the database and copy the keys and configuration:

sudo mariadb-dump --single-transaction passbolt | gzip | sudo tee /var/backups/passbolt/passbolt-db-$(date +%F).sql.gz > /dev/null
sudo tar czf /var/backups/passbolt/passbolt-config-$(date +%F).tar.gz /etc/passbolt/gpg /etc/passbolt/passbolt.php
sudo ls -lh /var/backups/passbolt

Copy these files to storage outside the server. The server keys in /etc/passbolt/gpg/ are essential: a database restored without them cannot be used.

Step 9 - Updating Passbolt

Passbolt updates arrive through APT like any other package. The package runs the database migrations during the upgrade:

sudo apt update
sudo apt upgrade

Run the healthcheck from Step 6 after each upgrade.

Troubleshooting

  • Let's Encrypt failed during installation: usually DNS does not point to the server yet or port 80 is closed. Fix it and rerun the Nginx and SSL questions with sudo dpkg-reconfigure passbolt-ce-server.
  • Wizard cannot connect to the database: test the credentials with mariadb -u passbolt -p passbolt. The host must be localhost, matching the user created in Step 2.
  • Emails never arrive: run the send_test_email command from Step 6 and read the SMTP error it prints. Many providers require port 587 with TLS and an app-specific password.
  • Healthcheck reports [FAIL] on the full base URL: the value in /etc/passbolt/passbolt.php must exactly match https://passbolt.your_domain.

Conclusion

Passbolt CE is now running on Ubuntu 24.04 with HTTPS, a dedicated MariaDB database, working email and an administrator account protected by the browser extension and a recovery kit. As next steps, schedule the backup commands from Step 8, enable multi-factor authentication under Administration, and invite your team so shared credentials move out of spreadsheets and chat.