# 3.4.0 mender-server set up failed

**URL:** <https://hub.mender.io/t/3-4-0-mender-server-set-up-failed/5346>\
**Category:** General Discussions\
**Tags:** failed, mender-server, container, 340, admin, create\
**Created:** [October 26, 2022, 9:24am UTC](https://hub.mender.io/t/3-4-0-mender-server-set-up-failed/5346 "2022-10-26T09:24:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ak8893893](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ak8893893/32/1746_2.png) [@ak8893893](https://hub.mender.io/u/ak8893893)\
**Post date:** [October 26, 2022, 9:24am UTC](https://hub.mender.io/t/3-4-0-mender-server-set-up-failed/5346/1 "2022-10-26T09:24:49Z")

</div>

I followed the 3.4.0 document to set up the mender-server.  
[https://docs.mender.io/3.4/server-installation/installation-with-docker-compose#close](https://docs.mender.io/3.4/server-installation/installation-with-docker-compose#close)

But there are two container can’t be create, I can’t create the first user.

```auto
menderproduction_mender-device-auth_1
menderproduction_mender-useradm_1

```

 ![image](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/2X/c/c75e053cf930259d410386936d73df7ec769dbdb.png)

I tried to use docker logs to check the error.  
It showed:

```auto
failed to read rsa private key: failed to read server private key file: open /etc/deviceauth/rsa/private.pem: permission denied

failed to read rsa private key: failed to read server private key file: open /etc/useradm/rsa/private.pem: permission denied

```

But I didn’t find the private.pem file in that place, I don’t know how to fix the problem.

By the way, the same the same process I create 3.3.0 mender-server demo and enterprise is OK.  
Is there any new step I need to do in 3.4.0 version?

---

<div class="post-metadata">

**Author:** ![ak8893893](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ak8893893/32/1746_2.png) [@ak8893893](https://hub.mender.io/u/ak8893893)\
**Post date:** [October 27, 2022, 10:11am UTC](https://hub.mender.io/t/3-4-0-mender-server-set-up-failed/5346/2 "2022-10-27T10:11:33Z")

</div>

2022/10/27 Update

I solved the issue.

See that his data volume is bound /production/keys-generated/keys/deviceauth/private.key  
Check whether this private.key has permission

found no permission

```auto
$ chmod +777 ~/mender-server/production/keys-generated/keys/useradm/private.key
$ chmod +777 ~/mender-server/production/keys-generated/keys/deviceauth/private.key

$ sudo ~/mender-server/production/run up -d

```

Change the permissions to full and start again, and you will see the useradm and deviceauth can be activated!

 ![image](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/2X/d/d771a7ae0eaf57ba86bf18d4e4233e12844a1ace.png)

You also can check the 3.3.0’s private.key permission and change the 3.4.0’s to the same permission.

---

<div class="post-metadata">

**Author:** ![joelguittet](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/joelguittet/32/1064_2.png) [@joelguittet](https://hub.mender.io/u/joelguittet)\
**Post date:** [November 13, 2022, 8:47pm UTC](https://hub.mender.io/t/3-4-0-mender-server-set-up-failed/5346/3 "2022-11-13T20:47:26Z")

</div>

> [@ak8893893](#):
>
> found no permission

Hello,

I have the same problem but clearly this is not the right solution. It works, yes obviously, but private key should not be accessible to world.  
On my v3.3 private key was permissions 600 and I guess you have the same on v3.4 (I have this.).

Anybody having the same issue with a more convenient solution for that ?

Joel

---

<div class="post-metadata">

**Author:** ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)\
**Post date:** [November 15, 2022, 11:00am UTC](https://hub.mender.io/t/3-4-0-mender-server-set-up-failed/5346/4 "2022-11-15T11:00:45Z")

</div>

Hi @joelguittet,

one way should be to adjust the `prod.yml` to use the actual `UID/GID` like this:

> ```
> mender-useradm:
> command: server --automigrate
> user: "${UID}:${GID}"
> 
> ```

Having said that, we strongly recommend. using the k8s version of the server setup.

Greetz,  
Josef

---

<div class="post-metadata">

**Author:** ![ak8893893](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ak8893893/32/1746_2.png) [@ak8893893](https://hub.mender.io/u/ak8893893)\
**Post date:** [November 15, 2022, 12:51pm UTC](https://hub.mender.io/t/3-4-0-mender-server-set-up-failed/5346/5 "2022-11-15T12:51:58Z")

</div>

> [@ak8893893](#):
>
> ```auto
> $ chmod 004 ~/mender-server/production/keys-generated/keys/useradm/private.key
> $ chmod 004 ~/mender-server/production/keys-generated/keys/deviceauth/private.key
> 
> $ sudo ~/mender-server/production/run up -d
> 
> ```

I tried to let the permission to the less. And it can works when I use 004 permission.

---

<div class="post-metadata">

**Author:** ![Craig-Anderson-Ins](https://avatars.discourse-cdn.com/v4/letter/c/f9ae1b/32.png) [@Craig-Anderson-Ins](https://hub.mender.io/u/Craig-Anderson-Ins)\
**Post date:** [February 23, 2024, 10:34pm UTC](https://hub.mender.io/t/3-4-0-mender-server-set-up-failed/5346/6 "2024-02-23T22:34:36Z")

</div>

I needed to add your ‘user: …’ line to _mender-device-auth_ as well.

After those two changes, all containers were fine.
