# No public Keys found with OIDC and Traefik Dashboard

**URL:** <https://community.traefik.io/t/no-public-keys-found-with-oidc-and-traefik-dashboard/25450>\
**Category:** Traefik v2\
**Tags:** cli, dashboard-api, plugin, docker\
**Created:** [December 7, 2024, 1:31am UTC](https://community.traefik.io/t/no-public-keys-found-with-oidc-and-traefik-dashboard/25450 "2024-12-07T01:31:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![phillf](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/phillf/32/9667_2.png) [@phillf](https://community.traefik.io/u/phillf)\
**Post date:** [December 7, 2024, 1:31am UTC](https://community.traefik.io/t/no-public-keys-found-with-oidc-and-traefik-dashboard/25450/1 "2024-12-07T01:31:48Z")

</div>

I have configured a middleware with the traefik-oidc-auth plugin. I get the "no public keys" after successfully authenticating against Authentik SSO.

Just trying to put the dashboard behind behind authentication here. Yes, basicAuth was only there as a test when I was trying to figure out why middlewares weren't loading.

**Log Entries:**

```auto
2024-12-06 20:10:01 [ERROR] [traefik-oidc-auth] Failed reading state cookie: http: named cookie not present

2024-12-06 20:10:02 [ERROR] [traefik-oidc-auth] Returned token is not valid: no public Keys found

```

**config.yml:**

```auto
global:
  checknewversion: true # Periodically check if a new version has been released.
  sendanonymoususage: true # Periodically send anonymous usage statistics.

log:
  level: WARN

api:
  dashboard: true

serversTransport:
  insecureSkipVerify: true

entryPoints:
  https:
    address: ":443" # Create the HTTPS entrypoint on port 443

  metrics:
    address: ":8082" # Create the HTTP metrics entrypoint on port 8082

certificatesResolvers:
  dns-cloudflare-nti:
    acme:
      caServer: https://acme-v02.api.letsencrypt.org/directory #LE Production
      # caServer: https://acme-staging-v02.api.letsencrypt.org/directory # LE Staging
      dnsChallenge:
        provider: cloudflare
        resolvers: 1.1.1.1:53,1.0.0.1:53
        delayBeforeCheck: 90
      email: (redacted)
      storage: /etc/traefik/acme.json

providers:
  docker:
    endpoint: "tcp://socket-proxy-traefik:2375" # Listen to the UNIX Docker socket
    exposedByDefault: false # Only expose container that are explicitly enabled (using label traefik.enabled)
    network: "traefik-backend" # Default network to use for connections to all containers.
    watch: true # Watch Docker Swarm events
  file:
    filename: "/etc/traefik/configs/config.yml" # Link to the dynamic configuration
    directory: "/etc/traefik/configs/dynamic" # Link to the dynamic configuration
    watch: true  
  providersThrottleDuration: 10 # Configuration reload frequency

metrics:
  prometheus:
    manualRouting: true
    buckets:
      - 0.1
      - 0.3
      - 1.2
      - 5.0

experimental:
  plugins:
    traefik-oidc-auth:
      moduleName: "github.com/sevensolutions/traefik-oidc-auth"
      version: "v0.4.1"

```

**middlewares.yml:**

```auto
http:
  middlewares:
    traefik-auth:
      basicAuth:
        users:
          - "user:passwd"
    TraefikOIDC:
      plugin:
        traefik-oidc-auth:
          Provider:
            Url: "https://sso.example.com/application/o/traefik/"
            ClientId: "...."
            ClientSecret: "...."
          Scopes: ["openid", "profile", "email"]
          Authorization:
            AssertClaims:
              - Name: "roles"
                AllOf: ["Traefik - Admins"]

```

**docker-compose.yml:**

```auto
services:
  traefik:
    image: docker.io/library/traefik:v3.2.1
    container_name: traefik
    stdin_open: true
    tty: true
    command:
      - --configFile=/etc/traefik/configs/config.yml
    ports:
      - 443:443
    volumes:
      - traefik-dynamic:/etc/traefik
    environment:
      - CF_DNS_API_TOKEN=(redacted)
      - TZ=America/New_York
    networks:
      - traefik-backend
      - socket_proxy
    restart: unless-stopped
    labels:
      # Enable Traefik
      - "traefik.enable=true"

      # HTTP Router - traefik-secure
      - "traefik.http.routers.traefik-secure.tls=true"
      - "traefik.http.routers.traefik-secure.entrypoints=https"
      - "traefik.http.routers.traefik-secure.rule=Host(`proxy.mydomain.com`)"
      - "traefik.http.routers.traefik-secure.tls.certresolver=dns-cloudflare-nti"
      - "traefik.http.routers.traefik-secure.service=api@internal"
      - "traefik.http.routers.traefik-secure.middlewares=TraefikOIDC@file"

      # HTTP Router - traefik-stats
      - "traefik.http.routers.stats-traefik-secure.tls=true"
      - "traefik.http.routers.stats-traefik-secure.entrypoints=https"
      - "traefik.http.routers.stats-traefik-secure.rule=Host(`stats.proxy.mydomain.com`)"
      - "traefik.http.routers.stats-traefik-secure.service=prometheus@internal"

volumes:
  traefik-config:
    driver: local
  traefik-dynamic:
    driver: local

networks:
  traefik-backend:
    name: traefik-backend
  socket_proxy:
    name: socket_proxy
    external: true

```

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [December 7, 2024, 7:37am UTC](https://community.traefik.io/t/no-public-keys-found-with-oidc-and-traefik-dashboard/25450/2 "2024-12-07T07:37:21Z")

</div>

This seems like a very specific plugin question, it's probably better to ask directly on their Github ([link](https://github.com/sevensolutions/traefik-oidc-auth?tab=readme-ov-file)).

So far `authentik` isn’t listed as compatible provider.

* * *

Not sure why you set those:

> [@phillf](#):
>
> ```auto
> stdin_open: true
> tty: true
> 
> ```

---

<div class="post-metadata">

**Author:** ![phillf](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/phillf/32/9667_2.png) [@phillf](https://community.traefik.io/u/phillf)\
**Post date:** [December 7, 2024, 1:10pm UTC](https://community.traefik.io/t/no-public-keys-found-with-oidc-and-traefik-dashboard/25450/3 "2024-12-07T13:10:45Z")

</div>

Posted [issue on plugins GH](https://github.com/sevensolutions/traefik-oidc-auth/issues/27).

Documenting link for reference.

---

<div class="post-metadata">

**Author:** ![phillf](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/phillf/32/9667_2.png) [@phillf](https://community.traefik.io/u/phillf)\
**Post date:** [December 7, 2024, 1:12pm UTC](https://community.traefik.io/t/no-public-keys-found-with-oidc-and-traefik-dashboard/25450/4 "2024-12-07T13:12:48Z")

</div>

> [@bluepuma77](#):
>
> Not sure why you set those:
> 
> ```auto
> stdin_open: true
> tty: true
> 
> ```

Without those I couldn't get the console in Portainer to work. I should probably go back and figure out which one is actually required.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bd81ebdb578656e76e56ff3cc3eed021d3ba132d.png) [@system](https://community.traefik.io/u/system)\
**Post date:** [December 10, 2024, 1:13pm UTC](https://community.traefik.io/t/no-public-keys-found-with-oidc-and-traefik-dashboard/25450/5 "2024-12-10T13:13:34Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
