mirror of
https://github.com/amidaware/tacticalrmm.git
synced 2026-04-26 15:05:57 +03:00
[GH-ISSUE #851] x509 certificate signed by unknown authority - Installing Agent Windows 10 #535
Labels
No labels
In Process
bug
bug
dev-triage
documentation
duplicate
enhancement
fixed
good first issue
help wanted
integration
invalid
pull-request
question
requires agent update
security
ui tweak
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/tacticalrmm#535
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @al3xOA on GitHub (Dec 10, 2021).
Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/851
Successfully installed tacticalrmm. When test installing an agent, during install I get the error described in the title. I've been poking and prodding around but my guess is the ssl cert correct? I'm using cloudflare as my dns but proxy is turned off on the api.x.com domain.
Would it be fair to see this is an ssl cert issue and to use the cloudflare ca cert to resolve the issue?
@dinger1986 commented on GitHub (Dec 10, 2021):
Maybe I suggest first of all that you redact your domain asap.
However I have checked and your rmm & mesh urls are working fine but your api one is showing a certificate error.
Are you using docker or standard install?
@al3xOA commented on GitHub (Dec 10, 2021):
I'm using a traditional install on esxi, fresh ubuntu lts. I'm thinking of possibly pointing the default lets encrypt certs to the cloudflare wildcard certs provided by cloudflare. I plan on uploading them to a certs folder as recommended by one of the torubleshooting pages on rmm to see if that's the issue.
Attached is the NAT service status error i'm seeing:
Dec 10 17:54:00 rmm nats-server[5521]: [5521] 2021/12/10 17:54:00.526011 [ERR] "redacted but personal ip":62762 - cid:5 - TLS handshake error: EOF
@dinger1986 commented on GitHub (Dec 10, 2021):
Yes put them on the machine and that should solve the issue, theres a guide for using your own certs
@dinger1986 commented on GitHub (Dec 11, 2021):
can we close this now?
@al3xOA commented on GitHub (Dec 11, 2021):
actually, after setting up the custom certs location and moving the cloudflare public and pirvate keys to the custom locations I still get the error. One final thing I was thinking is the original letsencrypt fullchain.pem has 3 certificates embedded as it should. My /certs/x.domain.com/fullchain.pem has the public key only. Could this be an issue?
@dinger1986 commented on GitHub (Dec 11, 2021):
Could just use cloudflare without proxy and dns only for all domains and would work fine
Suggest you discuss on #unsupported on our discord channel.
Closing on here as unsupported config.