Installation at CH-VPS-Provider: Error on Pritunl-Start

Hi all,

after I have had some Issues at Provider “Servinga”, described here I changed Provider.

Unfortunately new problems occured:
It seems that the whole Pritunl-Server could not be started this time due to a “Permission denied”-

Error:

[root@ch ~]# sudo systemctl status pritunl
× pritunl.service - Pritunl Daemon
     Loaded: loaded (/etc/systemd/system/pritunl.service; enabled; preset: disabled)
     Active: failed (Result: exit-code) since Mon 2026-08-10 00:48:55 CEST; 23min ago
   Duration: 3.361s
 Invocation: 85850c80d1f246749c2c69c518d33c23
    Process: 755 ExecStart=/usr/lib/pritunl/usr/bin/pritunl start (code=exited, status=1/FAILURE)
   Main PID: 755 (code=exited, status=1/FAILURE)
   Mem peak: 39.2M
        CPU: 671ms

Aug 10 00:48:55 ch.vpn.pbhosting.eu pritunl[755]:                             ^^^^^^^^^^
Aug 10 00:48:55 ch.vpn.pbhosting.eu pritunl[755]:   File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/settings/settings.py",>
Aug 10 00:48:55 ch.vpn.pbhosting.eu pritunl[755]:     self._init_modules()
Aug 10 00:48:55 ch.vpn.pbhosting.eu pritunl[755]:   File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/settings/settings.py",>
Aug 10 00:48:55 ch.vpn.pbhosting.eu pritunl[755]:     group_cls.load()
Aug 10 00:48:55 ch.vpn.pbhosting.eu pritunl[755]:   File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/settings/group_file.py>
Aug 10 00:48:55 ch.vpn.pbhosting.eu pritunl[755]:     os.chmod(self.path, 0o600)
Aug 10 00:48:55 ch.vpn.pbhosting.eu pritunl[755]: PermissionError: [Errno 13] Permission denied: '/etc/pritunl.conf'
Aug 10 00:48:55 ch.vpn.pbhosting.eu systemd[1]: pritunl.service: Main process exited, code=exited, status=1/FAILURE
Aug 10 00:48:55 ch.vpn.pbhosting.eu systemd[1]: pritunl.service: Failed with result 'exit-code'.

To my surprise a manual systemctl start pritunl was able to start the server just fine.

Seems that the manual restart of the server process has not lasted long.

I was able to login once.
I have setup organisation “users” and a VPN-Server “server”, then I attached the server to the organisation and clicked on “Start server”.

Unfortunately then I got the same error (which i also got on my previous VPS-Hoster):

[local][2026-08-10 01:28:33,760][INFO] Starting setup server
[local][2026-08-10 01:28:33,761][INFO] Generating setup server ssl cert
[radium-3916][2026-08-10 01:31:30,358][INFO] Starting server
  version         = "1.34.4681.89"
  python_version  = "3.12.13 (main, Jul  8 2026, 12:24:28) [GCC 11.5.0 20240719 (Red Hat 11.5.0-14)]"
  ssl_version     = "OpenSSL 3.5.5 27 Jan 2026"
  selinux_context = "system_u:system_r:unconfined_service_t:s0"
  web_auth_strict = true
[radium-3916][2026-08-10 01:31:30,358][INFO] Generating server certificate...
[local][2026-08-10 01:31:52,623][INFO] Getting default administrator password
[radium-3916][2026-08-10 01:33:15,104][INFO] Parsing account key...
[radium-3916][2026-08-10 01:33:15,108][INFO] Parsing CSR...
[radium-3916][2026-08-10 01:33:15,114][INFO] Found domains: ch.vpn.pbhosting.eu
[radium-3916][2026-08-10 01:33:15,114][INFO] Getting directory...
[radium-3916][2026-08-10 01:33:15,510][INFO] Directory found!
[radium-3916][2026-08-10 01:33:15,511][INFO] Registering account...
[radium-3916][2026-08-10 01:33:16,416][INFO] Registered!
[radium-3916][2026-08-10 01:33:16,416][INFO] Creating new order...
[radium-3916][2026-08-10 01:33:17,480][INFO] Order created!
[radium-3916][2026-08-10 01:33:17,894][INFO] Verifying ch.vpn.pbhosting.eu...
[radium-3916][2026-08-10 01:33:24,036][INFO] ch.vpn.pbhosting.eu verified!
[radium-3916][2026-08-10 01:33:24,036][INFO] Signing certificate...
[radium-3916][2026-08-10 01:33:26,055][INFO] Certificate signed!
[radium-3916][2026-08-10 01:33:26,060][INFO] Settings changed, restarting server...
  ssl_changed             = false
  cert_changed            = true
  key_changed             = true
  port_changed            = false
  redirect_server_changed = false
  reverse_proxy_changed   = false
  admin_api_auth_changed  = false
[radium-3916][2026-08-10 01:33:27,523][INFO] Server restarting...
[radium-3916][2026-08-10 01:33:27,526][INFO] Starting server
  version         = "1.34.4681.89"
  python_version  = "3.12.13 (main, Jul  8 2026, 12:24:28) [GCC 11.5.0 20240719 (Red Hat 11.5.0-14)]"
  ssl_version     = "OpenSSL 3.5.5 27 Jan 2026"
  selinux_context = "system_u:system_r:unconfined_service_t:s0"
  web_auth_strict = true
[radium-3916][2026-08-10 21:36:28,430][INFO] Starting vpn server
  server_id        = "6a7a281d46f0a3a82a7c30b2"
  instance_id      = "6a7a283c46f0a3a82a7c3113"
  instances        = []
  instances_count  = 0
  route_count      = 2
  network          = "10.150.60.0/22"
  network6         = "fd00:a963:c00::/64"
  ovpn_dco         = false
  dynamic_firewall = false
  bypass_sso_auth  = false
  geo_sort         = false
  force_connect    = false
  sso_auth         = false
  route_dns        = false
  device_auth      = false
  host_id          = "f13abd40e1f24d02a032d0fd2a25b767"
  host_address     = "179.237.108.226"
  host_address6    = "2001:1600:18:209::1e2"
  host_networks    = ["179.237.108.0/24"]
  cur_timestamp    = "2026-08-10 19:36:28.430794"
  libipt           = false
[radium-3916][2026-08-10 21:36:28,479][ERROR] Server error occurred while running
Traceback (most recent call last):
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/server/instance.py", line 1910, in _run_thread
    self.generate_iptables_rules()
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/server/instance.py", line 872, in generate_iptables_rules
    self.iptables.generate()
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/iptables.py", line 1270, in generate
    self._generate_sets()
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/iptables.py", line 219, in _generate_sets
    self._create_sets()
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/iptables.py", line 1493, in _create_sets
    utils.check_output_logged(
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/utils/misc.py", line 224, in check_output_logged
    raise subprocess.CalledProcessError(
subprocess.CalledProcessError: Command '['ipset', 'create', '6a7a283c46f0a3a82a7c3113_or', 'hash:net', 'family', 'inet']' returned non-zero exit status 1.
  server_id   = "6a7a281d46f0a3a82a7c30b2"
  instance_id = "6a7a283c46f0a3a82a7c3113"
[radium-3916][2026-08-10 21:36:28,481][ERROR] Popen returned error exit code
  cmd         = ["ipset", "create", "6a7a283c46f0a3a82a7c3113_or", "hash:net", "family", "inet"]
  return_code = 1
[radium-3916][2026-08-10 21:36:57,948][ERROR] Exception on /server/6a7a281d46f0a3a82a7c30b2/operation/start [PUT]
Traceback (most recent call last):
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/flask/app.py", line 1511, in wsgi_app
    response = self.full_dispatch_request()
               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/flask/app.py", line 919, in full_dispatch_request
    rv = self.handle_user_exception(e)
         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/flask/app.py", line 917, in full_dispatch_request
    rv = self.dispatch_request()
         ^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/flask/app.py", line 902, in dispatch_request
    return self.ensure_sync(self.view_functions[rule.endpoint])(**view_args)  # type: ignore[no-any-return]
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/auth/app.py", line 10, in _wrapped
    return call(*args, **kwargs)
           ^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/handlers/server.py", line 1530, in server_operation_put
    svr.start()
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/server/server.py", line 1802, in start
    raise ServerStartError('Server start timed out', {
pritunl.exceptions.ServerStartError: Server start timed out. {'server_id': ObjectId('6a7a281d46f0a3a82a7c30b2')}
[radium-3916][2026-08-10 21:36:57,948][ERROR] Exception on /server/6a7a281d46f0a3a82a7c30b2/operation/start [PUT]
Traceback (most recent call last):
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/flask/app.py", line 1511, in wsgi_app
    response = self.full_dispatch_request()
               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/flask/app.py", line 919, in full_dispatch_request
    rv = self.handle_user_exception(e)
         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/flask/app.py", line 917, in full_dispatch_request
    rv = self.dispatch_request()
         ^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/flask/app.py", line 902, in dispatch_request
    return self.ensure_sync(self.view_functions[rule.endpoint])(**view_args)  # type: ignore[no-any-return]
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/auth/app.py", line 10, in _wrapped
    return call(*args, **kwargs)
           ^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/handlers/server.py", line 1530, in server_operation_put
    svr.start()
  File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/server/server.py", line 1802, in start
    raise ServerStartError('Server start timed out', {
pritunl.exceptions.ServerStartError: Server start timed out. {'server_id': ObjectId('6a7a281d46f0a3a82a7c30b2')}
[radium-3916][2026-08-10 21:40:09,951][INFO] Stopping server

I then installed - as previously suggested by @zach - dnf install kernel-modules-extra and issued reboot-command.

After that reboot I ended where this thread started: It is not possible to start pritunl.service:

Aug 10 21:51:47 ch.vpn.pbhosting.eu systemd[1]: Started pritunl.service - Pritunl Daemon.
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]: Traceback (most recent call last):
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:   File "/usr/lib/pritunl/usr/bin/pritunl", line 33, in <module>
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:     sys.exit(load_entry_point('pritunl==1.34.4681.89', 'console_scripts', 'pritunl')())
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:              ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:   File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/__main__.py", line 63>
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:     from pritunl import settings
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:   File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/settings/__init__.py">
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:     sys.modules[__name__] = Settings()
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:                             ^^^^^^^^^^
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:   File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/settings/settings.py">
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:     self._init_modules()
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:   File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/settings/settings.py">
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:     group_cls.load()
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:   File "/usr/lib/pritunl/usr/lib/python3.12/site-packages/pritunl/settings/group_file.p>
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]:     os.chmod(self.path, 0o600)
Aug 10 21:51:47 ch.vpn.pbhosting.eu pritunl[1505]: PermissionError: [Errno 13] Permission denied: '/etc/pritunl.conf'
Aug 10 21:51:47 ch.vpn.pbhosting.eu systemd[1]: pritunl.service: Main process exited, code=exited, status=1/FAILURE
Aug 10 21:51:47 ch.vpn.pbhosting.eu systemd[1]: pritunl.service: Failed with result 'exit-code'.

@zach Any suggestions why this keeps happening to me? As I already started over with a new installation also on a different VPS-Provider it appears to be a somehow and somewhat “reproducible”?!

System is AlmaLinux 10.

It’s possible that caused SELinux to become enabled and it’s blocking access. Run sudo getenforce to check if it’s enabled. If it is disable with the commands below.

sudo setenforce 0
sudo sed -i 's/^SELINUX=.*/SELINUX=disabled/g' /etc/selinux/config
sudo systemctl restart pritunl

Although this would suggest it’s an incorrectly configured OS image. You could instead attempt to fix it by keeping SELinux enabled and reboot with a autorelabel using the commands below. It may also require reinstalling pritunl if the previous install failed to add the SELinux modules.

sudo dnf -y reinstall pritunl
touch /.autorelabel
reboot

sudo dnf -y reinstall pritunl throws the following error:

Failed to resolve typeattributeset statement at /var/lib/selinux/targeted/tmp/modules/400/pritunl/cil:77
Failed to resolve AST
semodule:  Failed!

Complete CLI-Output of reinstall (Sorry; CLI-Language is set to German):

sudo dnf -y reinstall pritunl
Letzte Prüfung auf abgelaufene Metadaten: vor 0:16:19 am Di 11 Aug 2026 00:19:09 CEST.
Abhängigkeiten sind aufgelöst.
===========================================================================================================================================
 Paket                       Architektur                Version                                          Paketquelle                 Größe
===========================================================================================================================================
Neuinstallieren:
 pritunl                     x86_64                     1.34.4681.89-1.el9.almalinux                     pritunl                      79 M

Transaktionszusammenfassung
===========================================================================================================================================

Gesamte Downloadgröße: 79 M
Installationsgröße: 383 M
Pakete werden heruntergeladen:
pritunl-1.34.4681.89-1.el9.almalinux.x86_64.rpm                                                             76 MB/s |  79 MB     00:01
-------------------------------------------------------------------------------------------------------------------------------------------
Gesamt                                                                                                      76 MB/s |  79 MB     00:01
Transaktionsüberprüfung wird ausgeführt
Transaktionsüberprüfung war erfolgreich.
Transaktion wird getestet
Transaktionstest war erfolgreich.
Transaktion wird ausgeführt
  Vorbereitung läuft    :                                                                                                              1/1
  Ausgeführtes Scriptlet: pritunl-1.34.4681.89-1.el9.almalinux.x86_64                                                                  1/2
  Neuinstallieren       : pritunl-1.34.4681.89-1.el9.almalinux.x86_64                                                                  1/2
  Ausgeführtes Scriptlet: pritunl-1.34.4681.89-1.el9.almalinux.x86_64                                                                  1/2
Failed to resolve typeattributeset statement at /var/lib/selinux/targeted/tmp/modules/400/pritunl/cil:77
Failed to resolve AST
semodule:  Failed!

  Aufräumen             : pritunl-1.34.4681.89-1.el9.almalinux.x86_64                                                                  2/2
  Ausgeführtes Scriptlet: pritunl-1.34.4681.89-1.el9.almalinux.x86_64                                                                  2/2

Erneut installiert:
  pritunl-1.34.4681.89-1.el9.almalinux.x86_64

Fertig!

You’re installing the AlmaLinux 9 version on AlmaLinux 10. Run the commands below.

sudo tee /etc/yum.repos.d/pritunl.repo << EOF
[pritunl]
name=Pritunl Repository
baseurl=https://repo.pritunl.com/stable/yum/almalinux/10/
gpgcheck=1
enabled=1
gpgkey=https://raw.githubusercontent.com/pritunl/pgp/master/pritunl_repo_pub.asc
EOF
sudo dnf clean metadata
sudo dnf -y reinstall pritunl

It may also require running sudo semodule -r pritunl before the reinstall to remove the broken EL9 module.

AI maybe pointed me in the right direction:
At Install Pritunl Server | Pritunl VPN | Pritunl Documentation I missed that this installation script is only valid for AlmaLinux 9.

May I suggest that the docs get an update (maybe also include version Numbers in the heading of the paragraph (e.g: “[Other Providers] AlmaLinux 9/Rocky Linux 9/RHEL (Oracle Linux) 9”) or include the nice table of the different Install-Scripts from Pritunl - Enterprise VPN Server in the documentation.