# Cert validation error when using Service Fabric configuration provider

**URL:** <https://community.traefik.io/t/cert-validation-error-when-using-service-fabric-configuration-provider/1988>\
**Category:** Traefik v1\
**Tags:** service-fabric\
**Created:** [September 28, 2019, 4:11am UTC](https://community.traefik.io/t/cert-validation-error-when-using-service-fabric-configuration-provider/1988 "2019-09-28T04:11:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mike](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/mike/32/242_2.png) [@mike](https://community.traefik.io/u/mike)\
**Post date:** [September 28, 2019, 4:11am UTC](https://community.traefik.io/t/cert-validation-error-when-using-service-fabric-configuration-provider/1988/1 "2019-09-28T04:11:39Z")

</div>

Originally, I used the following backends:

```auto
[backends]
  [backends.api]
    [backends.api.servers.endpoint]
    url = "https://Api:11443"

```

The DNS name `Api` resolves to several web servers, and those servers are signed with a self signed cert. Now, we're switching over to the Service Fabric provider. This provider automatically configures the backend pool:

![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/1X/a0f8b5cfaf941582cea59b0e3325a44e7e77c99c.png)

So, now Traefik knows all the IP addresses of the VMs running that service and doesn't need DNS. The problem is, those servers use an SSL cert signed for "Api", not the IP address. We we make a request, we get the error:

```auto
DEBU[2019-09-27T20:22:07-07:00] '500 Internal Server Error' caused by: x509: cannot validate certificate for 10.111.12.8 because it doesn't contain any IP SANs

```

Is there any way around this, or can we disable the cert validation while still validating the root CA and using HTTPS? Here's my Traefik config:

```auto
debug = true
logLevel = "DEBUG"
defaultEntryPoints = ["http", "https"]
[entryPoints]
[entryPoints.http]
address = ":81"

[api]
entrypoint="dashboard"

[entryPoints.dashboard]
  address = ":8443"

[serviceFabric]

clusterManagementUrl = "https://localhost:19080"
apiVersion = "3.0"
refreshSeconds = 10

[serviceFabric.tls]
  cert = "C:/Users/rdpadmin/TraefikTest/sf.crt"
  key = "C:/Users/rdpadmin/TraefikTest/sf.key"
  insecureSkipVerify = true

[tls.options]
  [tls.options.default]
    [tls.options.default.clientAuth]
      clientAuthType = "RequireAnyClientCert"

```

---

<div class="post-metadata">

**Author:** ![mike](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/mike/32/242_2.png) [@mike](https://community.traefik.io/u/mike)\
**Post date:** [September 28, 2019, 4:19am UTC](https://community.traefik.io/t/cert-validation-error-when-using-service-fabric-configuration-provider/1988/2 "2019-09-28T04:19:52Z")

</div>

Ok I believe I figured this one out as well.

The `insecureSkipVerify = true` under the `[serviceFabric.tls]` is used to ignore cert validation when connecting to the local service fabric endpoint (since we're connecting to it using localhost, and not its signed host name). I need to add another `insecureSkipVerify = true` at the top of the file, which will indicate backend certs are not validated. The entire config file is now:

```auto
debug = true
logLevel = "DEBUG"
insecureSkipVerify = true
defaultEntryPoints = ["http", "https"]
[entryPoints]
[entryPoints.http]
address = ":81"

[api]
entrypoint="dashboard"

[entryPoints.dashboard]
  address = ":8443"

[serviceFabric]

clusterManagementUrl = "https://localhost:19080"
apiVersion = "3.0"
refreshSeconds = 10

[serviceFabric.tls]
  cert = "C:/Users/rdpadmin/TraefikTest/sf.crt"
  key = "C:/Users/rdpadmin/TraefikTest/sf.key"
  insecureSkipVerify = true

[tls.options]
  [tls.options.default]
    [tls.options.default.clientAuth]
      clientAuthType = "RequireAnyClientCert"

```

If there's a better approach for this scenario, I'd love to hear it.
