# Internal Server error on fresh install RHEL9

**URL:** <https://discourse.openondemand.org/t/internal-server-error-on-fresh-install-rhel9/3250>\
**Category:** Get Help\
**Tags:** question\
**Created:** [February 6, 2024, 8:37pm UTC](https://discourse.openondemand.org/t/internal-server-error-on-fresh-install-rhel9/3250 "2024-02-06T20:37:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmorand17](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/dmorand17/32/1851_2.png) [@dmorand17](https://discourse.openondemand.org/u/dmorand17)\
**Post date:** [February 6, 2024, 8:37pm UTC](https://discourse.openondemand.org/t/internal-server-error-on-fresh-install-rhel9/3250/1 "2024-02-06T20:37:42Z")

</div>

I’m testing a fresh install of OnDemand v3 on RHEL9. When I try to launch the login screen I get an HTTP 500 error (Internal Server Error). I’m using dex (ldap) and checked the apache error logs for the OOD instance and this is all I’m showing. I don’t see anything being created in the ondemand-nginx logs folder.

```auto
[Tue Feb 06 20:21:08.735446 2024] [auth_openidc:error] [pid 15110:tid 15301] [client 10.0.0.160:41248] oidc_util_http_call: curl_easy_perform() failed on: https://ood.REDACTED/dex/.well-known/openid-configuration ()
[Tue Feb 06 20:21:08.735480 2024] [auth_openidc:error] [pid 15110:tid 15301] [client 10.0.0.160:41248] oidc_provider_static_config: could not retrieve metadata from url: https://ood.REDACTED/dex/.well-known/openid-configuration

```

This is the /etc/ood/config/ood\_portal.yml file

```auto
servername: {{REDACTED}
  # Default based on if ssl key for ood-portal-generator is defined
  # Only used if SSL is disabled
  # Only used if SSL is enabled
  # tls_cert and tls_key take OnDemand configured values for ssl and copy keys to /etc/ood/dex maintaining file names
  # Client ID, defaults to servername or FQDN
  # Client secret, value auto generated
  # A value that is a filesystem path can be used to store secret in a file
   # The OnDemand redirectURI is auto-generated, this option allows adding additional URIs
  # Additional Dex OIDC clients to configure
  # The following example is to configure OpenLDAP
  # Docs: https://github.com/dexidp/dex/blob/master/Documentation/connectors/ldap.md
ssl:
  - 'SSLCertificateFile "/etc/ssl/private/cert.crt"'
  - 'SSLCertificateKeyFile "/etc/ssl/private/private_key.key"'
dex_uri: /dex
dex:
    ssl: true
    connectors:
        - type: ldap
          id: ldap
          name: LDAP
          config:
            host: {{REDACTED}
            insecureSkipVerify: false
            insecureNoSSL: true
            bindDN: CN=Admin,OU=Users,OU=hpclab,DC=hpclab,DC=local
            bindPW: {{REDACTED}
            userSearch:
              baseDN: dc=hpclab,dc=local
              filter: "(objectClass=user)"
              username: name
              idAttr: name
              emailAttr: name
              nameAttr: name
              preferredUsernameAttr: name
host_regex: '[^/]+'
node_uri: '/node'
rnode_uri: '/rnode'
user_map_cmd: '/etc/ood/add_user.sh'

```

---

<div class="post-metadata">

**Author:** ![dmorand17](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/dmorand17/32/1851_2.png) [@dmorand17](https://discourse.openondemand.org/u/dmorand17)\
**Post date:** [February 7, 2024, 2:42am UTC](https://discourse.openondemand.org/t/internal-server-error-on-fresh-install-rhel9/3250/2 "2024-02-07T02:42:42Z")

</div>

I figured it out eventually. I reviewed some errors in /var/log/audit/audit.log and realized I needed to install `ondemand-selinux`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [August 5, 2024, 2:43am UTC](https://discourse.openondemand.org/t/internal-server-error-on-fresh-install-rhel9/3250/3 "2024-08-05T02:43:19Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
