Passbolt is an open-source password manager built for teams: every secret is encrypted in the browser with OpenPGP, and the server only stores ciphertext and sharing permissions. In this tutorial you will install Passbolt Community Edition (CE) on Ubuntu 24.04 using the official Debian package, which sets up PHP, Nginx and a Let's Encrypt certificate for you, with a local MariaDB database. You will then run the web setup wizard, configure outgoing email and create the first administrator.
Prerequisites
To follow this tutorial you need:
- A fresh server running Ubuntu 24.04 LTS, for example a CubePath VPS, with at least 2 GB of RAM. Passbolt's package configures Nginx and PHP-FPM itself, so do not install it on a server that already hosts other Nginx sites.
- A non-root user with
sudoprivileges. - A domain or subdomain (this guide uses
passbolt.your_domain) with a DNSArecord pointing toyour_server_ip. - SMTP credentials for sending email (host, port, username and password). Passbolt uses email for invitations and account recovery, so it is required in practice.
- A desktop browser supported by the Passbolt extension (Chrome, Firefox, Edge or Brave).
Step 1 - Opening the firewall
Let's Encrypt must reach the server on port 80 during installation, so open the web ports before installing anything:
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status
Status: active
To Action From
-- ------ ----
OpenSSH ALLOW Anywhere
80/tcp ALLOW Anywhere
443/tcp ALLOW Anywhere
Also check that the domain resolves to this server:
dig +short passbolt.your_domain
The output must be your_server_ip.
Step 2 - Creating the MariaDB database
Install MariaDB from the Ubuntu repositories:
sudo apt update
sudo apt install mariadb-server
Create a dedicated database and user for Passbolt. Replace your_strong_password with a long random password and keep it at hand for Step 5:
sudo mariadb <<'SQL'
CREATE DATABASE passbolt CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'passbolt'@'localhost' IDENTIFIED BY 'your_strong_password';
GRANT ALL PRIVILEGES ON passbolt.* TO 'passbolt'@'localhost';
FLUSH PRIVILEGES;
SQL
Confirm that the new user can log in and see its database:
mariadb -u passbolt -p -e "SHOW DATABASES;"
+--------------------+
| Database |
+--------------------+
| information_schema |
| passbolt |
+--------------------+
Step 3 - Adding the Passbolt repository
Passbolt publishes a script that adds its APT repository and signing key. Download it together with its checksum file and only run it if the checksum matches:
cd /tmp
curl -LO https://download.passbolt.com/ce/installer/passbolt-repo-setup.ce.sh
curl -LO https://github.com/passbolt/passbolt-dep-scripts/releases/latest/download/passbolt-ce-SHA512SUM.txt
sha512sum -c passbolt-ce-SHA512SUM.txt
passbolt-repo-setup.ce.sh: OK
If you see OK, you can read the script with less passbolt-repo-setup.ce.sh and then run it:
sudo bash ./passbolt-repo-setup.ce.sh
If the checksum fails, delete the file and download it again. Do not run a script that does not match.
Step 4 - Installing the Passbolt package
Install the server package:
sudo apt install --no-install-recommends passbolt-ce-server
The package asks several questions through debconf:
- Configure a MySQL/MariaDB database for Passbolt? Answer No. You already created the database, and you will enter its credentials in the web wizard.
- Configure Nginx? Answer Yes.
- SSL setup: choose auto to request a Let's Encrypt certificate automatically.
- Enter your domain (
passbolt.your_domain) and an email address for Let's Encrypt notices.
When the installation finishes, confirm that Nginx and PHP-FPM are running and that the site answers over HTTPS:
systemctl is-active nginx php8.3-fpm
curl -sI https://passbolt.your_domain | head -n 1
active
active
HTTP/2 302
The redirect points to the setup wizard, which is expected at this stage.
Step 5 - Running the web setup wizard
Open https://passbolt.your_domain in your browser. The wizard walks you through these screens:
- Healthcheck: confirms PHP extensions and permissions are correct. Click Start configuration.
- Database: enter host
localhost, port3306, usernamepassbolt, the password from Step 2 and database namepassbolt. - Server key: Passbolt generates an OpenPGP key pair for the server. Enter a server name (for example
Passbolt your_domain) and an email address. - Options: keep the full base URL
https://passbolt.your_domainand leave Force SSL enabled. - Email: enter your SMTP settings and use Send test email to confirm delivery before continuing.
- First user: enter the administrator's first name, last name and email.
When the wizard ends, it redirects you to install the Passbolt browser extension. Install it, then continue in the same tab: you will set a passphrase for your personal key and download the recovery kit. Store the recovery kit somewhere safe outside Passbolt. Without it and the passphrase, your account cannot be recovered.
Step 6 - Verifying the installation
Passbolt ships a healthcheck command that must run as the web server user:
sudo -u www-data /usr/share/php/passbolt/bin/cake passbolt healthcheck
The output groups checks by area (environment, config files, core, SSL, database, GPG, application). A healthy install ends with:
[PASS] No error found. Nice one sparky!
Fix any [FAIL] line before inviting users; the message tells you what is wrong. To test email delivery from the command line, run:
sudo -u www-data /usr/share/php/passbolt/bin/cake passbolt send_test_email --recipient=you@your_domain
The package installs a cron job in /etc/cron.d/ that sends queued emails, so invitations and notifications leave within a minute or two.
Step 7 - Inviting users and sharing passwords
In the Passbolt web UI:
- Go to Users, click Create, enter the person's name and email and pick the User or Admin role. They receive an email invitation and complete the same extension and passphrase setup you did.
- Go to Users, then Groups, to create a group (for example
DevOps) and add members. - Go to Passwords, click Create, fill in name, URL, username and password, then use Share to give a user or group can read, can update or is owner access.
Because encryption happens in the browser, a secret is readable only by the people it is shared with. Administrators manage users but cannot read passwords that were not shared with them.
Step 8 - Backing up Passbolt
A usable backup needs three things: the database, the server OpenPGP keys and the configuration file. Create a backup directory readable only by root:
sudo install -d -m 700 /var/backups/passbolt
Dump the database and copy the keys and configuration:
sudo mariadb-dump --single-transaction passbolt | gzip | sudo tee /var/backups/passbolt/passbolt-db-$(date +%F).sql.gz > /dev/null
sudo tar czf /var/backups/passbolt/passbolt-config-$(date +%F).tar.gz /etc/passbolt/gpg /etc/passbolt/passbolt.php
sudo ls -lh /var/backups/passbolt
Copy these files to storage outside the server. The server keys in /etc/passbolt/gpg/ are essential: a database restored without them cannot be used.
Step 9 - Updating Passbolt
Passbolt updates arrive through APT like any other package. The package runs the database migrations during the upgrade:
sudo apt update
sudo apt upgrade
Run the healthcheck from Step 6 after each upgrade.
Troubleshooting
- Let's Encrypt failed during installation: usually DNS does not point to the server yet or port 80 is closed. Fix it and rerun the Nginx and SSL questions with
sudo dpkg-reconfigure passbolt-ce-server. - Wizard cannot connect to the database: test the credentials with
mariadb -u passbolt -p passbolt. The host must belocalhost, matching the user created in Step 2. - Emails never arrive: run the
send_test_emailcommand from Step 6 and read the SMTP error it prints. Many providers require port 587 with TLS and an app-specific password. - Healthcheck reports
[FAIL]on the full base URL: the value in/etc/passbolt/passbolt.phpmust exactly matchhttps://passbolt.your_domain.
Conclusion
Passbolt CE is now running on Ubuntu 24.04 with HTTPS, a dedicated MariaDB database, working email and an administrator account protected by the browser extension and a recovery kit. As next steps, schedule the backup commands from Step 8, enable multi-factor authentication under Administration, and invite your team so shared credentials move out of spreadsheets and chat.
