# How to disable Passenger security check update

**URL:** <https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055>\
**Category:** Get Help\
**Tags:** question\
**Created:** [May 6, 2022, 9:42pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055 "2022-05-06T21:42:17Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![emsisson](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/emsisson/32/1028_2.png) [@emsisson](https://discourse.openondemand.org/u/emsisson)\
**Post date:** [May 6, 2022, 9:42pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/1 "2022-05-06T21:42:18Z")

</div>

Greetings,

I am a new Open OnDemand user attempting to make it work for our clusters. I have installed the RPMs, launched the services, and reached step `Start Services' (https://osc.github.io/ood-documentation/latest/installation/start-apache.html). I created a local user `ood’ and tried to connect. However, I received message

Home directory not found

Your home directory appears to be missing. The home directory mount may be unavailable, or your home directory may need to still be created. Please contact support for help and attempt to restart your web server by clicking below when the problem has been fixed.

The home directory for user `ood’ does exist on a local file system on the Open OnDemand server.

In file /var/log/ondemand-nginx/ood/error.log I found the following:

[E 2022-05-06 15:51:53.1138 238677/T5 age/Cor/SecurityUpdateChecker.h:507]: Security update check failed: SSL connect error while connecting to [https://securitycheck.phusionpassenger.com/v1/check.json](https://securitycheck.phusionpassenger.com/v1/check.json) (if this error persists check your connection security or try upgrading Passenger) (next check in 24 hours)

I suspect that this is the problem. If I should look elsewhere, please tell me.

We are a healthcare institution and are very strict about security (HIPAA violations are subject to criminal penalties). By default, all access by data center servers to external sites is blocked. Firewall exceptions can be requested but are reviewed by our information security department, and anything that provides a whiff of data exfiltration is examined closely and must be justified. I think my best approach is to disable this check.

I found the URL embedded in binary file  
/opt/ood/ondemand/root/usr/lib64/passenger/support-binaries/PassengerAgent

Documentation at  
[Configuration reference - for Passenger Standalone - Passenger Library](https://www.phusionpassenger.com/docs/references/config_reference/standalone/#--disable-security-update-check-disable_security_update_check)  
says that the Passenger security check update can be disabled at a command line, within a configuration file, or via an environment variable.

What is the simplest and most effective method to disable the Passenger security check update, and what is the procedure to do that?

Regards,  
Eric Sisson

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [May 6, 2022, 11:14pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/2 "2022-05-06T23:14:30Z")

</div>

> [@emsisson](#):
>
> What is the simplest and most effective method to disable the Passenger security check update, and what is the procedure to do that?

This is not the issue and to disable it in 2.0 you’d have to edit this file that we distribute. You can see other passenger settings there, simply add the config to disable it.

```auto
/opt/ood/nginx_stage/templates/pun.conf.erb

```

If you do update this template remove all the files here: (I’m not 100% sure about that glob, but it’s basically any conf file you find here).

```auto
/var/lib/ondemand-nginx/config/apps/*/**.conf

```

Back to your issue - it really means what it says. It can’t find the home directory. Did you create it after you hit that page? ‘restarting the webserver’ can restart the state and retry. Some systems won’t create a home directory until the user logs in. Then of course if you made a local user, `usermod` need to specify home creation.

In any case - If the user does indeed have a valid home directory, then you should restart things until starts to work. Start with the link the page gives you then try the entire machine maybe.

---

<div class="post-metadata">

**Author:** ![emsisson](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/emsisson/32/1028_2.png) [@emsisson](https://discourse.openondemand.org/u/emsisson)\
**Post date:** [May 9, 2022, 3:46pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/3 "2022-05-09T15:46:01Z")

</div>

Greetings, Jeff,

Thank you for the quick reply, particularly given that you must have sent it late in your day.

After more experimenting this morning, I finally have traced this to being an SELinux issue of some kind; switching SELInux from Enforcing to Permissive mode made the difference. I had installed the ondemand-selinux RPM, so I guess that something about the way our servers are built must differ from the assumptions in that package. I will try to get more specific information and post it to this thread.

Regards,  
Eric

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [May 9, 2022, 3:54pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/4 "2022-05-09T15:54:27Z")

</div>

Thank you for the update, here’s the TE file for reference.

> <https://github.com/OSC/ondemand/blob/master/packaging/rpm/ondemand-selinux.te>

The SELinux thing I should have caught before. There could be an issue here that we’ve yet to identify. This user had the same issue with HOME.

> [@$Home Directory Doesn't Exist (CAS, SELinux, & University Controlled AD)](https://discourse.openondemand.org/t/home-directory-doesnt-exist-cas-selinux-university-controlled-ad/1880):
>
> Hey All, So we are currently setting up an instance of Open OnDemand on our department’s new HPC cluster’s headnode. We have everything set up pretty stock at the moment (install from the Selinux RPM for Redhat 8) via following the docs. The only difference is setting up CAS based on the fixes posted, which is now working just fine. However, after CAS is confirmed, we are getting the following error (which has come up before on here but never had an answered solution): The following…

---

<div class="post-metadata">

**Author:** ![emsisson](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/emsisson/32/1028_2.png) [@emsisson](https://discourse.openondemand.org/u/emsisson)\
**Post date:** [May 9, 2022, 5:09pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/5 "2022-05-09T17:09:43Z")

</div>

Greetings, Jeff,

Here is a follow-up.

Like the other problem that you posted, we are running RHEL 8 with SELinux. We will be using the institution-controlled Active Directory, but right now, I am trying to make the basics work.

I ran this two times, once with SELinux in Permissive mode and a second time with SELinux in Enforcing mode. I performed a reboot between the two to ensure as much as possible that I was starting from the same conditions. From each attempt, I captured lines from /var/log/audit.log. In each case, I saw a series of 14 lines beginning with `type-USER_ACCT' and ending with `type=CRED\_DISP’. Ignoring differences in timestamps and PID numbers, those lines looked mostly the same except for two lines — `type=USER_START' and `type=USER\_END’ just before the ending CRED\_DISP line:

* * *

Permissive mode

type=USER\_START msg=audit(1652112985.483:130): pid=2419 uid=0 auid=4294967295 ses=4294967295 subj=system\_u:system\_r:httpd\_t:s0 msg='op=PAM:session\_open grantors=pam\_keyinit,pam\_limits,pam\_systemd,pam\_unix acct=“root” exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success’UID=“root” AUID=“unset”

type=USER\_END msg=audit(1652112987.049:131): pid=2419 uid=0 auid=4294967295 ses=4294967295 subj=system\_u:system\_r:httpd\_t:s0 msg='op=PAM:session\_close grantors=pam\_keyinit,pam\_limits,pam\_systemd,pam\_unix acct=“root” exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success’UID=“root” AUID=“unset”

* * *

Enforcing mode

type=USER\_START msg=audit(1652114316.986:127): pid=2461 uid=0 auid=4294967295 ses=4294967295 subj=system\_u:system\_r:httpd\_t:s0 msg='op=PAM:session\_open grantors=pam\_keyinit,pam\_limits,pam\_unix acct=“root” exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success’UID=“root” AUID=“unset”

type=USER\_END msg=audit(1652114318.477:128): pid=2461 uid=0 auid=4294967295 ses=4294967295 subj=system\_u:system\_r:httpd\_t:s0 msg='op=PAM:session\_close grantors=pam\_keyinit,pam\_limits,pam\_unix acct=“root” exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success’UID=“root” AUID=“unset”

* * *

The difference is in section `msg=', subsection `grantors=’:

- Permissive mode includes `pam\_systemd’
- Enforcing mode this specification is absent  
The man page for pam\_systemd says ``Register user sessions in the systemd login manager’’. I confess that I tend to get lost in PAM, so I hope this means something to you.

Regards,  
Eric

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [May 9, 2022, 5:55pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/6 "2022-05-09T17:55:45Z")

</div>

No idea. @tdockendorf any ideas?

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [May 9, 2022, 6:13pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/7 "2022-05-09T18:13:58Z")

</div>

Those audit logs don’t look like denials. There are likely “dontaudit” denials taking place which don’t get logged. It’s a very annoying “feature” of SELinux.

If you’re still using local $HOME then might need to enable the `ondemand_manage_user_home_dir` SELinux boolean: [3. Modify System Security — Open OnDemand 2.0.20 documentation](https://osc.github.io/ood-documentation/latest/installation/modify-system-security.html)

If that boolean doesn’t help, you may have to turn off the “dontaudit” in SELinux, but only leave it off during the shortest timespan possible and then perform the operation that’s blocked then re-enable “dontaudit” as it can floor the logs and auditd might rotate logs too quickly.

Disable “dontaudit”

```auto
semodule -DB

```

Turn back on “dontaudit”

```auto
semodule -B

```

After you perform the operation with dontaudit disabled run this:

```auto
cat /var/log/audit/audit.log | audit2allow

```

And past the output here. There might already be denials you can pull out so might be good to run the above command now just to check.

---

<div class="post-metadata">

**Author:** ![emsisson](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/emsisson/32/1028_2.png) [@emsisson](https://discourse.openondemand.org/u/emsisson)\
**Post date:** [May 9, 2022, 7:27pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/8 "2022-05-09T19:27:58Z")

</div>

Greetings, Trey and Jeff,

That was it. The output from audit2allow included the following:

```
#============= ood_pun_t ==============

#!!!! This avc can be allowed using the boolean 'ondemand_manage_user_home_dir'
allow ood_pun_t user_home_dir_t:dir getattr;
```

and that setting is described at the page linked by Trey. So I entered

```
setsebool -PV ondemand_manage_user_home_dir on
```

and tried again. The first attempt still returned the “Home directory not found” message, but hitting “Restart Web Server” connected.

Of course, in a final deployment, all the user home directories will be mounted by NFS, so this was something of detour into the weeds.

Here is another issue I found earlier that may be helpful to others. Like the person Jeff referenced who was having similar problems a few months ago, we are connecting to an institutional Active Directory for authentication, and we are doing this through sssd. I had to add user apache to file /etc/security/access.conf to allow it to invoke its sudo rule to launch nginx\_stage. That may be a consequence of how our data center people told us to configure authentication rather than something inherent in sssd or PAM, but it did allow me to get past the following error:

```
sudo[234158]: apache : PAM account management error: Permission denied ; TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/opt/ood/nginx_stage/sbin/nginx_stage pun -u ood -a ...
```

Thank you all, again, and I look forward to exercising Open OnDemand further.

Regards,  
Eric

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [May 9, 2022, 7:47pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/9 "2022-05-09T19:47:56Z")

</div>

> [@emsisson](#):
>
> but it did allow me to get past the following error:
> 
> sudo[234158]: apache : PAM account management error: Permission denied ; TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/opt/ood/nginx\_stage/sbin/nginx\_stage pun -u ood -a …

Try running this command and paste output:

```auto
cat /var/log/audit/audit.log | audit2allow

```

There maybe something with SELinux blocking. If there is nothing in SELinux then might be something specific to your PAM stack for sudo so show the contents of `/etc/pam.d/sudo`

---

<div class="post-metadata">

**Author:** ![emsisson](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/emsisson/32/1028_2.png) [@emsisson](https://discourse.openondemand.org/u/emsisson)\
**Post date:** [May 9, 2022, 8:33pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/10 "2022-05-09T20:33:32Z")

</div>

Greetings, Trey,

I have removed apache from access.conf and rebooted the server. I can connect to the web login page, enter the userid and password. After that I received a page with the following text:

```
Error -- sudo: PAM account management error: Permission denied
```

File /var/log/secure contains the following:

```
... sudo[2689]: apache : PAM account management error: Permission denied ; TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/opt/ood/nginx_stage/sbin/nginx_stage pun -u ood -a ...
```

The output from audit2allow contains the following:

```
#============= httpd_t ==============

#!!!! This avc has a dontaudit rule in the current policy
allow httpd_t chkpwd_t:process { noatsecure rlimitinh siginh };

#!!!! This avc has a dontaudit rule in the current policy
allow httpd_t initrc_var_run_t:file read;

#!!!! This avc has a dontaudit rule in the current policy
allow httpd_t self:capability net_admin;

#============= system_dbusd_t ==============

#!!!! This avc has a dontaudit rule in the current policy
allow system_dbusd_t self:capability net_admin;

#!!!! This avc has a dontaudit rule in the current policy
allow system_dbusd_t setroubleshootd_t:process { noatsecure rlimitinh siginh };

#!!!! This avc has a dontaudit rule in the current policy
allow system_dbusd_t unconfined_service_t:process { noatsecure rlimitinh siginh };
```

File /etc/pam.d/sudo is very simple:

```
#%PAM-1.0
auth include system-auth
account include system-auth
password include system-auth
session include system-auth
```

File system-auth is a symlink to “/etc/authselect/system-auth”, which is provided by RPM authselect-libs and has the following contents:

```
# Generated by authselect on Tue Apr 12 07:55:13 2022
# Do not modify this file manually.

auth required pam_env.so
auth required pam_faildelay.so delay=2000000
auth [default=1 ignore=ignore success=ok] pam_usertype.so isregular
auth [default=1 ignore=ignore success=ok] pam_localuser.so
auth sufficient pam_unix.so nullok
auth [default=1 ignore=ignore success=ok] pam_usertype.so isregular
auth sufficient pam_sss.so forward_pass
auth required pam_deny.so

account required pam_access.so
account required pam_unix.so
account sufficient pam_localuser.so
account sufficient pam_usertype.so issystem
account [default=bad success=ok user_unknown=ignore] pam_sss.so
account required pam_permit.so

password requisite pam_pwquality.so local_users_only
password sufficient pam_unix.so sha512 shadow nullok use_authtok
password sufficient pam_sss.so use_authtok
password required pam_deny.so

session optional pam_keyinit.so revoke
session required pam_limits.so
-session optional pam_systemd.so
session optional pam_oddjob_mkhomedir.so
session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session required pam_unix.so
session optional pam_sss.so
```

Regards,  
Eric

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [May 10, 2022, 12:24pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/11 "2022-05-10T12:24:52Z")

</div>

So it looks like we have some of those httpd\_t items allowed with the `ondemand_use_kubernetes` boolean so try this:

```auto
setsebool -PV ondemand_use_kubernetes on

```

If that works, then we just need to move some of the items to be not gated behind the Kubernetes boolean. If that doesn’t work, try this:

```auto
mkdir /tmp/selinux
cd /tmp/selinux
cat /var/log/audit/audit.log | audit2allow -M ood
# Edit ood.te to remove system_dbusd_t allow lines
make -f /usr/share/selinux/devel/Makefile
semodule -i ood.pp

```

If that Makefile path doesn’t exist, you’ll need to install `selinux-policy-devel`.

Note the comment in those commands, I don’t think the system\_dbusd\_t items are related to OnDemand so first let’s just try allowing the httpd\_t contexts.

If those httpd\_t items work for you I can update the OnDemand SELinux policies to handle those when `ondemand-selinux` package is installed. If those work also please include contents of `ood.pp` that you applied

---

<div class="post-metadata">

**Author:** ![emsisson](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/emsisson/32/1028_2.png) [@emsisson](https://discourse.openondemand.org/u/emsisson)\
**Post date:** [May 10, 2022, 1:33pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/12 "2022-05-10T13:33:13Z")

</div>

Greetings, Trey,

Setting the ondemand\_use\_kubernetes boolean to on made no difference. I still receive the page with message

```
Error -- sudo: PAM account management error: Permission denied
```

I reset the audit.log file before running this test, but the output from the audit2allow step for that file was

```
Nothing to do
```

I grabbed the previous audit.log file, and that did generate an ood.te file. I modified that to remove the `allow system_dbusd_t …` lines, installed the RPM, ran make, and ran the semodule step, which took several seconds to return. However, the result is the same; I still receive the message above.

Here is the final ood.te file

```
module ood 1.0;

require {
	type unconfined_service_t;
	type setroubleshootd_t;
	type system_dbusd_t;
	type httpd_t;
	type fsdaemon_t;
	class capability net_admin;
	class process { noatsecure rlimitinh siginh };
}

#============= fsdaemon_t ==============

#!!!! This avc has a dontaudit rule in the current policy
allow fsdaemon_t self:capability net_admin;

#============= httpd_t ==============

#!!!! This avc has a dontaudit rule in the current policy
allow httpd_t self:capability net_admin;
```

Regards,  
Eric

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [May 10, 2022, 1:53pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/13 "2022-05-10T13:53:44Z")

</div>

That leads me to believe the issue is with either sudo configuration or PAM.

Do you have the file `/etc/sudoers.d/ood` that allows the Apache user to execute `/opt/ood/nginx_stage/sbin/nginx_stage`. This is what ours looks like, can ignore Kubernetes parts if not using:

```auto
# cat /etc/sudoers.d/ood 
# This file is managed by Puppet; changes may be overwritten
Defaults:apache !requiretty, !authenticate
Defaults:apache env_keep += "NGINX_STAGE_* OOD_*"
apache ALL=(ALL) NOPASSWD: /opt/ood/nginx_stage/sbin/nginx_stage
Cmnd_Alias KUBECTL = /usr/local/bin/kubectl
Defaults!KUBECTL !syslog

```

So one thing we do different with PAM is we don’t put `pam_access` into the main `system-auth` and `password-auth` files because those files are used by things we don’t want to use pam\_access with, like sudo. We only put `pam_access.so` into `/etc/pam.d/sshd` since that’s the only access we care about. If you do need to put pam\_access in the system-auth you might try adding this to `/etc/security/access.conf`:

```auto
+ : apache : ALL

```

I’m not sure if `sudo` is an option in access.conf, I only ever fill in cron/crond and hostnames for SSH access.

---

<div class="post-metadata">

**Author:** ![emsisson](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/emsisson/32/1028_2.png) [@emsisson](https://discourse.openondemand.org/u/emsisson)\
**Post date:** [May 10, 2022, 3:21pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/14 "2022-05-10T15:21:12Z")

</div>

Greetings, Trey,

In fact, what I had done was to add line

```
+ : apache : ALL
```

to `/etc/security/access.conf`. That was the extra step I mentioned yesterday, earlier in this thread, that I had to perform to make things work.

Just now, I tried specifying `sudo` in place of `ALL`, but that did not work.

I am reluctant to modify PAM configurations because that is something that we do very rarely, if at all, whereas modifying `access.conf` is a basic configuration action (typically by specifying Active Directory groups), so it is a typical place to look for changes.

I guess we have reached an end stage here. Thank you for your time looking into this.

Regards,  
Eric

---

<div class="post-metadata">

**Author:** ![emsisson](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/emsisson/32/1028_2.png) [@emsisson](https://discourse.openondemand.org/u/emsisson)\
**Post date:** [May 10, 2022, 3:24pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/15 "2022-05-10T15:24:04Z")

</div>

Greetings, Trey,

I should have mentioned that our `/etc/sudoers.d/ood` looks almost identical to yours except that it adds a couple of paths for KUBECTL.

Regards,  
Eric

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [May 10, 2022, 4:18pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/16 "2022-05-10T16:18:03Z")

</div>

Based on the man page for `access.conf` I don’t think `sudo` is recognized by pam\_access. So you’re likely going to have to stick with `ALL`. You might be able to say `LOCAL` but not sure if that applies to the way sudo is using pam\_access.

---

<div class="post-metadata">

**Author:** ![emsisson](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/emsisson/32/1028_2.png) [@emsisson](https://discourse.openondemand.org/u/emsisson)\
**Post date:** [May 10, 2022, 4:46pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/17 "2022-05-10T16:46:43Z")

</div>

Greetings, Trey,

Good shot! Changing to `LOCAL` worked. Earlier I had tried specifying `127.0.0.1` but had no luck with that.

Thanks for the persistence and the follow-up.

Regards,  
Eric

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [November 6, 2022, 4:47pm UTC](https://discourse.openondemand.org/t/how-to-disable-passenger-security-check-update/2055/18 "2022-11-06T16:47:16Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
