# Self-Signed Certificate in Traefik not trusted even when I add CA Cert to Browser

**URL:** <https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136>\
**Category:** Traefik v2\
**Tags:** docker-swarm, letsencrypt-acme\
**Created:** [April 4, 2023, 3:45pm UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136 "2023-04-04T15:45:00Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cloufish](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/cloufish/32/6900_2.png) [@Cloufish](https://community.traefik.io/u/Cloufish)\
**Post date:** [April 4, 2023, 3:45pm UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/1 "2023-04-04T15:45:00Z")

</div>

When I generate certificate for e.g. proxmox I am able to perform the general procedure to make this Self-Signed certificate trusted.

But that is not the case with Traefik Routes  
I followed these guides:

1. [Traefik Proxy 2.x and TLS 101 [Updated 2022] | Traefik Labs](https://traefik.io/blog/traefik-2-tls-101-23b4fbee81f1/)
2. [How to create & sign SSL/TLS certificates - DEV Community](https://dev.to/techschoolguru/how-to-create-sign-ssl-tls-certificates-2aai)  
**And everything in my setup is almost the same.**

When it comes to generating the Certificate _I try to generate a wildcard certificate to \*.home_

```bash
# 1. Generate CA's private key and self-signed certificate

openssl req -x509 -newkey rsa:4096 -days 3650 -nodes -keyout ca-key.pem -out ca-cert.pem -subj "/C=FR/ST=Occitanie/L=Toulouse/O=Tech School/OU=Education/CN=*.home/emailAddress=bartmok17@gmail.com"

echo "CA's self-signed certificate"

openssl x509 -in ca-cert.pem -noout -text

echo "subjectAltName=DNS:*.home" > server-ext.cnf

# 2. Generate web server's private key and certificate signing request (CSR)
openssl req -newkey rsa:4096 -nodes -keyout server-key.pem -out server-req.pem -subj "/C=FR/ST=Ile de France/L=Paris/O=PC Book/OU=Computer/CN=*.home/emailAddress=bartmok17@gmail.com"

# 3. Use CA's private key to sign web server's CSR and get back the signed certificate
openssl x509 -req -in server-req.pem -days 3650 -CA ca-cert.pem -CAkey ca-key.pem -CAcreateserial -out server-cert.pem -extfile server-ext.cnf

echo "Server's signed certificate"
openssl x509 -in server-cert.pem -noout -text

```

**`traefik-stack.j2`**

```yml
version: '3.5'

services:
  reverse-proxy:
    image: {{traefik_app_image}}
    command:
      - "--api.dashboard=true"
      - "--providers.docker"
      - "--providers.docker.swarmMode=true"
      - "--entrypoints.web.address=:{{traefik_listen_port}}"
      - "--entrypoints.{{traefik_secure_network_name}}.address=:{{traefik_secure_listen_port}}"
      - "--providers.docker.exposedByDefault=false"
      - "--log.level=DEBUG" 
+ - "--providers.file.directory=/configuration/"
+ - "--providers.file.watch=true"
+ - "--serversTransport.insecureSkipVerify=true" # I thought It would fix the issue
    ports:
      - "{{traefik_listen_port}}:{{traefik_listen_port}}"
      - "{{traefik_admin_port}}:8080"
+ - "{{traefik_secure_listen_port}}:{{traefik_secure_listen_port}}" 
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
 + - "/home/{{ansible_user}}/traefik/configuration/:/configuration/"
 + - "/home/{{ansible_user}}/traefik/certs/:/certs/"
    networks:
      - {{traefik_network_name}}

    deploy:
      labels:
      - "traefik.enable=true"
      - "traefik.http.routers.api.rule=Host(`{{traefik_app_name}}.{{app_domain_name}}`)"
      - "traefik.http.routers.api.service=api@internal"
      - "traefik.http.routers.api.middlewares=auth"
      - "traefik.http.middlewares.auth.basicauth.users={{traefikpassword.stdout}}"
      # Dummy service for Swarm port detection. The port can be any valid integer value.
      - "traefik.http.services.dummy-svc.loadbalancer.server.port=9999"
      mode: global
      placement:
        constraints: [node.role == manager]

networks:
  {{traefik_network_name}}:
    driver: overlay
    attachable: true
    name: {{traefik_network_name}}

```

**`example-app-stack.j2`:**

```yml
version: "3.5"

services:
  {{dsomm_app_name}}:
    image: "{{dsomm_app_image}}"
    container_name: {{dsomm_app_name}}
    ports:
      - "{{app_default_port}}"
    networks:
      - {{traefik_network_name}}
      - {{dsomm_network_name}}
    volumes:
      - {{dsomm_volume_name}}:/app
    deploy:
      labels:
        - "traefik.enable=true"
        - "traefik.http.routers.{{dsomm_app_name}}.rule=Host(`{{dsomm_app_name}}.{{app_domain_name}}`)"
        - "traefik.http.services.{{dsomm_app_name}}.loadbalancer.server.port={{dsomm_admin_port}}"
        - "traefik.docker.network={{traefik_network_name}}"
        - "io.portainer.accesscontrol.users=admin"
 + - "traefik.http.routers.{{dsomm_app_name}}.tls=true"

networks:
  {{dsomm_network_name}}:
    driver: overlay 
    attachable: true
    name: {{dsomm_network_name}}
  {{traefik_network_name}}:
    external: true
    name: {{traefik_network_name}}

volumes: 
  {{dsomm_volume_name}}:
    driver: {{filesystem_driver}} 

```

**certificates.yml**

```auto
tls:
  certificates:
    # first certificate
    - certFile: "/certs/server-cert.pem" 
      keyFile: "/certs/server-key.pem"

```

And the self-signed certificate is used

 ![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/7/79812f3b02d6bb48df5c08cbe9bcc2691799c395.png)

**But adding the CA Cert doesn't make this domain Trusted ☹**

**Please help**

---

<div class="post-metadata">

**Author:** ![Cloufish](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/cloufish/32/6900_2.png) [@Cloufish](https://community.traefik.io/u/Cloufish)\
**Post date:** [April 5, 2023, 2:57pm UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/2 "2023-04-05T14:57:35Z")

</div>

I'd like to add that I also tried:

1. Adding `ca-cert.pem` into the traefik container and using `- "--serverstransport.rootcas=/certs/ca-cert.pem"` command in Docker Compose
2. Adding ` - "traefik.http.services.dashboard.loadbalancer.server.scheme=https"` label to each of my service  
^ From -\> [Problem using ssl Backend with selfsigned certificates - #9 by trajano](https://community.traefik.io/t/problem-using-ssl-backend-with-selfsigned-certificates/1974/9)

But it still doesn't work 😕

I also give the plain docker-compose files for better readibility:

**traefik.yml**

```auto
version: '3.5'

services:
  reverse-proxy:
    image: traefik:v2.10
    command:
      - "--api.dashboard=true"
      - "--providers.docker"
      - "--providers.docker.swarmMode=true"
      - "--entrypoints.web.address=:80"
      - "--entrypoints.websecure.address=:443"
      - "--providers.docker.exposedByDefault=false"
      - "--log.level=DEBUG"
      - "--providers.file.directory=/configuration/"
      - "--serverstransport.rootcas=/certs/ca-cert.pem"
      - "--providers.file.watch=true"
      - "--serversTransport.insecureSkipVerify=true"
    ports:
      - "80:80"
      - "8080:8080"
      - "443:443"
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
      - "/home/swarm/traefik/configuration/:/configuration/"
      - "/home/swarm/traefik/certs/:/certs/"
    networks:
      - web

    deploy:
      labels:
      - "traefik.enable=true"
      - "traefik.http.routers.api.rule=Host(`traefik.home`)"
      - "traefik.http.routers.api.service=api@internal"
      - "traefik.http.routers.api.middlewares=auth"
      - "traefik.http.middlewares.auth.basicauth.users=<REDACTED>:<REDACTED>"
      # Dummy service for Swarm port detection. The port can be any valid integer value.
      - "traefik.http.services.dummy-svc.loadbalancer.server.port=9999"
      mode: global
      placement:
        constraints: [node.role == manager]

networks:
  web:
    driver: overlay
    attachable: true
    name: web

```

**Example App** :

```auto
version: "3.5"

services:
  dsomm:
    image: "wurstbrot/dsomm:latest"
    container_name: dsomm
    ports:
      - "80"
    networks:
      - web
      - dsomm
    volumes:
      - dsomm-volume:/app
    deploy:
      labels:
        - "traefik.enable=true"
        - "traefik.http.routers.dsomm.rule=Host(`dsomm.home`)"
        - "traefik.http.services.dsomm.loadbalancer.server.port=8080"
        - "traefik.docker.network=web"
        - "io.portainer.accesscontrol.users=admin"
        - "traefik.http.routers.dsomm.tls=true"
        - "serverstransport.insecureskipverify=true"

networks:
  dsomm:
    driver: overlay
    attachable: true
    name: dsomm
  web:
    external: true
    name: web

volumes:
  dsomm-volume:
    driver: local

```

---

<div class="post-metadata">

**Author:** ![pplmx](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/pplmx/32/6840_2.png) [@pplmx](https://community.traefik.io/u/pplmx)\
**Post date:** [April 8, 2023, 6:48am UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/3 "2023-04-08T06:48:31Z")

</div>

# Try [`mkcert`](https://github.com/FiloSottile/mkcert).

Here is my demo:

 ![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/e/e1ffad798a72eed39ab44fddfe63478886c30458.png)

## generate certs

```shell
install -d certs
mkcert -key-file certs/key.pem -cert-file certs/cert.pem m.local *.m.local
mkcert -install

```

## `compose.yml`

```yml
version: Compose specification

services:
    traefik:
        image: traefik:3.0
        ports:
            - "80:80"
            - "443:443"
            - "8080:8080"
        environment:
            - TZ=Asia/Shanghai
        volumes:
            # /traefik.yml and /etc/traefik/traefik.yml are both available.
            - "./traefik.yml:/etc/traefik/traefik.yml"
            # dynamic-conf dir is self-defined
            - "./dynamic-conf:/etc/traefik/dynamic-conf"
            - "./certs:/certs"
            - "/var/run/docker.sock:/var/run/docker.sock:ro"
        networks:
            - traefik-net

networks:
    traefik-net:
        name: traefik-net
        ipam:
            config:
                - subnet: 172.16.238.0/24

```

## `traefik.yml`

```yml
### Static Configuration
log:
    level: INFO
api:
    dashboard: true
entryPoints:
    web:
        address: :80
        http:
            redirections:
                entryPoint:
                    to: websecure
                    scheme: https
                    permanent: true
    websecure:
        address: :443
providers:
    file:
        directory: /etc/traefik/dynamic-conf
        watch: true

```

## `self.yml` in `./dynamic-conf/`

```yml
### Dynamic Configuration
tls:
    certificates:
        - certFile: /certs/cert.pem
            keyFile: /certs/key.pem
http:
    routers:
        dashboard:
            rule: Host(`traefik.m.local`)
            service: api@internal
            tls: { }

```

---

<div class="post-metadata">

**Author:** ![Cloufish](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/cloufish/32/6900_2.png) [@Cloufish](https://community.traefik.io/u/Cloufish)\
**Post date:** [April 8, 2023, 9:29am UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/4 "2023-04-08T09:29:17Z")

</div>

> [@pplmx](#):
>
> Try [`mkcert`](https://github.com/FiloSottile/mkcert).

Thank you for the demo!  
I've tried it with my setup, **but the cert is still not trusted**

```auto
mkcert -key-file server-key.pem -cert-file server-cert.pem "home" "*.home" 

```

 ![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/d/d04f011216ee56c9bd4d2ab2b311602ad35f3d45.png)

```auto
mkcert --install

```

 ![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/2/2b41abe7f13a0e164d6759b4e862fd5a6a733a43.png)

 ![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/2/2c9d3e2cdf90a09ba7f5d60e5d13d14d34c22d44.png)  
 ![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/a/a3e3233440687dbafced0cbd80d37664123f2a79.png)  
 ![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/1/1e4b5d116ffb2f5a48bc278428d9573e872b371d.png)

---

<div class="post-metadata">

**Author:** ![pplmx](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/pplmx/32/6840_2.png) [@pplmx](https://community.traefik.io/u/pplmx)\
**Post date:** [April 8, 2023, 9:33am UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/5 "2023-04-08T09:33:19Z")

</div>

1. try a non second-level domain
2. restart your browser
3. maybe try it on Chrome

---

<div class="post-metadata">

**Author:** ![Cloufish](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/cloufish/32/6900_2.png) [@Cloufish](https://community.traefik.io/u/Cloufish)\
**Post date:** [April 8, 2023, 9:39am UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/6 "2023-04-08T09:39:56Z")

</div>

> [@pplmx](#):
>
> - restart your browser
> - maybe try it on Chrome

I've already tried restarting Browser, PC,  
And other browsers: Firefox, Chromium

> [@pplmx](#):
>
> - 
> 1. try a non second-level domain

What do you mean by that?  
If it's about a simple `https://home` without anything occupying then it still shows not secure  
 ![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/d/dfa1f5f587a8191d2932130db7bbd0816edb46aa.png)

---

<div class="post-metadata">

**Author:** ![pplmx](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/pplmx/32/6840_2.png) [@pplmx](https://community.traefik.io/u/pplmx)\
**Post date:** [April 8, 2023, 9:41am UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/7 "2023-04-08T09:41:36Z")

</div>

![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/9/9c5aa1058a03db396da3205c27fd656758a8a856.png)  
Look this.

---

<div class="post-metadata">

**Author:** ![Cloufish](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/cloufish/32/6900_2.png) [@Cloufish](https://community.traefik.io/u/Cloufish)\
**Post date:** [April 8, 2023, 10:10am UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/8 "2023-04-08T10:10:49Z")

</div>

Even when I generate certs without second level wildcards so in my case:

```auto
mkcert -key-file server-key.pem -cert-file server-cert.pem "home" 

```

I still get the same issue

Then I tried importing the `rootCA.pem` to another Operating System (Windows), but doesn't work either

Thank you pplmx though for your support 🙂  
I might come with the solution

---

<div class="post-metadata">

**Author:** ![pplmx](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/pplmx/32/6840_2.png) [@pplmx](https://community.traefik.io/u/pplmx)\
**Post date:** [April 8, 2023, 10:19am UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/9 "2023-04-08T10:19:05Z")

</div>

The domain name that is issued should consist of at least two segments, for example m.dev or xx.local.  
Like this:

```shell
mkcert -key-file certs/key.pem -cert-file certs/cert.pem m.dev

```

![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/0/0e3616b21a3131b97887ccab723ff95b5e244e23.png)

---

<div class="post-metadata">

**Author:** ![Cloufish](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/cloufish/32/6900_2.png) [@Cloufish](https://community.traefik.io/u/Cloufish)\
**Post date:** [April 8, 2023, 10:34am UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/10 "2023-04-08T10:34:06Z")

</div>

Okay so:

1. I didn't realized that _traefik container needs to be restarted each time new `cert.pem` is mounted_ - so my testing wasn't really done (I thought `docker deploy [...]` did update it)
2. pplmx was right about second level wildcards. When I issue one by one cert for each service it is trusted
  - Or maybe I just generated the wildcards in the wrong way? 😕 Idk.

---

<div class="post-metadata">

**Author:** ![pplmx](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/pplmx/32/6840_2.png) [@pplmx](https://community.traefik.io/u/pplmx)\
**Post date:** [April 8, 2023, 10:35am UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/11 "2023-04-08T10:35:44Z")

</div>

Maybe it just that you don't restart the traefik.  
I tried [https://home](https://home), it works fine. ✅

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bd81ebdb578656e76e56ff3cc3eed021d3ba132d.png) [@system](https://community.traefik.io/u/system)\
**Post date:** [April 11, 2023, 10:36am UTC](https://community.traefik.io/t/self-signed-certificate-in-traefik-not-trusted-even-when-i-add-ca-cert-to-browser/18136/12 "2023-04-11T10:36:23Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
