# \[RESOLVED\] Client Unauthorized to access its cookbooks - 403 Forbidden

**URL:** <https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444>\
**Category:** Chef Infra (archive)\
**Created:** [February 17, 2017, 10:45am UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444 "2017-02-17T10:45:28Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ant4r3s](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/ant4r3s/32/1807_2.png) [@ant4r3s](https://discourse.chef.io/u/ant4r3s)\
**Post date:** [February 17, 2017, 10:45am UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/1 "2017-02-17T10:45:28Z")

</div>

Hi,  
I'm facing a problem with a node which is not allowed to access its cookbook. The message I see in the log is:

> # ================================================================================ Error Resolving Cookbooks for Run List:

> ## Authorization Error
> 
> This client is not authorized to read some of the information required to  
> access its cookbooks (HTTP 403).

> To access its cookbooks, a client needs to be able to read its environment and  
> all of the cookbooks in its expanded run list.

> ## Expanded Run List:
> 
> - chef-client::config
> - chef-client
> - spacewalk-client::rhel

> ## Server Response:
> 
> missing read permission

> ## Platform:
> 
> x86\_64-linux

> Running handlers:  
> [2017-02-17T11:29:02+01:00] ERROR: Running exception handlers  
> Running handlers complete  
> [2017-02-17T11:29:02+01:00] ERROR: Exception handlers complete  
> Chef Client failed. 0 resources updated in 02 seconds  
> [2017-02-17T11:29:02+01:00] FATAL: Stacktrace dumped to /home/security/.chef/cache/chef-stacktrace.out  
> [2017-02-17T11:29:02+01:00] FATAL: Please provide the contents of the stacktrace.out file if you file a bug report  
> [2017-02-17T11:29:02+01:00] ERROR: 403 "Forbidden"  
> [2017-02-17T11:29:02+01:00] FATAL: Chef::Exceptions::ChildConvergeError: Chef run process exited unsuccessfully (exit code 1)

Any suggestion?

---

<div class="post-metadata">

**Author:** ![nic\_chef](https://avatars.discourse-cdn.com/v4/letter/n/fbc32d/32.png) [@nic\_chef](https://discourse.chef.io/u/nic_chef)\
**Post date:** [February 17, 2017, 10:50am UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/2 "2017-02-17T10:50:49Z")

</div>

Change the permission of the cookbook [https://docs.chef.io/server\_manage\_cookbooks.html](https://docs.chef.io/server_manage_cookbooks.html)

To set permissions list for a cookbook object:

Open the Chef management console.  
Click Policy.  
Click Cookbooks.  
Select a cookbook.  
Click the Permissions tab.  
For each group listed under Name, select or de-select the Read, Update, Delete, and Grant permissions.

---

<div class="post-metadata">

**Author:** ![waseemahammed](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/waseemahammed/32/1708_2.png) [@waseemahammed](https://discourse.chef.io/u/waseemahammed)\
**Post date:** [February 17, 2017, 10:54am UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/3 "2017-02-17T10:54:50Z")

</div>

> [@ant4r3s](#):
>
> missing read permission

It clearly says that "client needs to be able to read its environment and all of the cookbooks in its expanded run list."

Go to policy, click on cookbook and on permissions tab, change the permission of desired cookbooks.

Regards,  
Waseem

---

<div class="post-metadata">

**Author:** ![ant4r3s](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/ant4r3s/32/1807_2.png) [@ant4r3s](https://discourse.chef.io/u/ant4r3s)\
**Post date:** [February 17, 2017, 10:59am UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/4 "2017-02-17T10:59:17Z")

</div>

Thank you for your responses but I've already checked the permissions and it looks like all is good, because read permission is checked on Read action. Here below a screenshot of the chef-client cookbook. Am I wrong? Any other suggestions?

![](https://sea2.discourse-cdn.com/flex016/images/transparent.png)

---

<div class="post-metadata">

**Author:** ![ant4r3s](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/ant4r3s/32/1807_2.png) [@ant4r3s](https://discourse.chef.io/u/ant4r3s)\
**Post date:** [February 17, 2017, 11:12am UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/5 "2017-02-17T11:12:12Z")

</div>

I’ve also tried to reset the key of the client, installing it on the node but without improvements. Could it be that the log is misleading?

---

<div class="post-metadata">

**Author:** ![nic\_chef](https://avatars.discourse-cdn.com/v4/letter/n/fbc32d/32.png) [@nic\_chef](https://discourse.chef.io/u/nic_chef)\
**Post date:** [February 17, 2017, 11:27am UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/6 "2017-02-17T11:27:33Z")

</div>

Change the permission under the Clients tab not the Cookbooks,: under Policy =\> Clients =\> click on the node and change the permission there.

---

<div class="post-metadata">

**Author:** ![ant4r3s](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/ant4r3s/32/1807_2.png) [@ant4r3s](https://discourse.chef.io/u/ant4r3s)\
**Post date:** [February 17, 2017, 11:35am UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/7 "2017-02-17T11:35:08Z")

</div>

It's quite the same: the permissions here are the same as all the other clients registered on the server. See screenshot below. I've also tried to bootstrap again the node but the message is exactly the same. How can I proceed?

![](https://sea2.discourse-cdn.com/flex016/images/transparent.png)

---

<div class="post-metadata">

**Author:** ![nic\_chef](https://avatars.discourse-cdn.com/v4/letter/n/fbc32d/32.png) [@nic\_chef](https://discourse.chef.io/u/nic_chef)\
**Post date:** [February 17, 2017, 11:52am UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/8 "2017-02-17T11:52:01Z")

</div>

you user ant4r3s is missing, you need to add it on the list.

---

<div class="post-metadata">

**Author:** ![ant4r3s](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/ant4r3s/32/1807_2.png) [@ant4r3s](https://discourse.chef.io/u/ant4r3s)\
**Post date:** [February 17, 2017, 12:00pm UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/9 "2017-02-17T12:00:32Z")

</div>

I don’t think so because all other hosts don’t have that permission and they work. In fact, I’ve added the ant4r3s user to the node3 but the result is the same : (  
Other idea?

---

<div class="post-metadata">

**Author:** ![nic\_chef](https://avatars.discourse-cdn.com/v4/letter/n/fbc32d/32.png) [@nic\_chef](https://discourse.chef.io/u/nic_chef)\
**Post date:** [February 17, 2017, 1:08pm UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/10 "2017-02-17T13:08:53Z")

</div>

i ran out of ideas :-/ restart the chef server…

---

<div class="post-metadata">

**Author:** ![ant4r3s](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/ant4r3s/32/1807_2.png) [@ant4r3s](https://discourse.chef.io/u/ant4r3s)\
**Post date:** [February 17, 2017, 2:00pm UTC](https://discourse.chef.io/t/resolved-client-unauthorized-to-access-its-cookbooks-403-forbidden/10444/11 "2017-02-17T14:00:07Z")

</div>

The restart of the server doesn’t work unfortunately.

Anyway I’ve found a solution deleting the node from the server as well as the client key on the node. As last operation I’ve bootstraped the node from the workstation ☹
