# General Questions

**URL:** https://openziti.discourse.group/c/support/general-questions/7.md?page=4

[Latest](https://openziti.discourse.group/latest.md) · [Categories](https://openziti.discourse.group/categories.md)

**Page:** 5

---

## [How to enroll identity using REST APis](https://openziti.discourse.group/t/how-to-enroll-identity-using-rest-apis/3603)

<div class="topic-metadata">

**Author:** [@quintonn](https://openziti.discourse.group/u/quintonn)\
**Replies:** 17\
**Last updated:** [December 18, 2024, 5:54pm UTC](https://openziti.discourse.group/t/how-to-enroll-identity-using-rest-apis/3603 "2024-12-18T17:54:30Z")

</div>

Hi, I'm following the example JVM project: ziti-sdk-jvm/samples/jdbc-postgres/cheatsheet.md at main · openziti/ziti-sdk-jvm · GitHub In the document there are the following commands: ziti edge create identity pg-clien…

---

## [Building Openziti LAB with VMware](https://openziti.discourse.group/t/building-openziti-lab-with-vmware/3610)

<div class="topic-metadata">

**Author:** [@HooangF4t](https://openziti.discourse.group/u/HooangF4t)\
**Replies:** 5\
**Last updated:** [December 16, 2024, 12:21pm UTC](https://openziti.discourse.group/t/building-openziti-lab-with-vmware/3610 "2024-12-16T12:21:39Z")

</div>

I am building a small lab model. Currently I have created router-public and router-private with console (https://192.168.160.50:1280/zac/). I want to deploy controller(192.168.160.50:1280) VMnet8, router-public(machines …

---

## [Is openziti useful for a small personal network?](https://openziti.discourse.group/t/is-openziti-useful-for-a-small-personal-network/3547)

<div class="topic-metadata">

**Author:** [@amano](https://openziti.discourse.group/u/amano)\
**Replies:** 23\
**Last updated:** [December 10, 2024, 4:29am UTC](https://openziti.discourse.group/t/is-openziti-useful-for-a-small-personal-network/3547 "2024-12-10T04:29:24Z")

</div>

Openziti eliminates routing tables, IP addresses, and so many other things. However, it is also conceptually complex, and for a small setup, it doesn't seem worth the effort it takes to properly learn and set it up. Fo…

---

## [Ziti Tunneler Traffic](https://openziti.discourse.group/t/ziti-tunneler-traffic/3566)

<div class="topic-metadata">

**Author:** [@nvc97](https://openziti.discourse.group/u/nvc97)\
**Replies:** 4\
**Last updated:** [December 10, 2024, 12:18am UTC](https://openziti.discourse.group/t/ziti-tunneler-traffic/3566 "2024-12-10T00:18:46Z")

</div>

Hi, I've been setting up ZT Host Access configurations using Ziti Edge Tunnelers for a while, and I have just a few technical questions regarding how traffic is handled once the tunnel is established: Once the tunnel …

---

## [Does openziti support something like tailnet lock?](https://openziti.discourse.group/t/does-openziti-support-something-like-tailnet-lock/3562)

<div class="topic-metadata">

**Author:** [@amano](https://openziti.discourse.group/u/amano)\
**Replies:** 1\
**Last updated:** [December 9, 2024, 2:12pm UTC](https://openziti.discourse.group/t/does-openziti-support-something-like-tailnet-lock/3562 "2024-12-09T14:12:06Z")

</div>

If someone wants to rent netfoundry's services, the person will want to make sure netfoundry can't meddle with controller config and inject malicious users. tailnet lock was introduced to make sure users don't have to t…

---

## [Error with enabling](https://openziti.discourse.group/t/error-with-enabling/3558)

<div class="topic-metadata">

**Author:** [@nightfallenxyz](https://openziti.discourse.group/u/nightfallenxyz)\
**Replies:** 3\
**Last updated:** [December 8, 2024, 9:44pm UTC](https://openziti.discourse.group/t/error-with-enabling/3558 "2024-12-08T21:44:56Z")

</div>

panic: More data is available. goroutine 1 \[running\]: main.(\*enableCommand).run(0xc000444820, 0xc001d1fbb0?, {0xc000b55070, 0x1, 0x0?}) /home/runner/work/zrok/zrok/cmd/zrok/enable.go:57 +0x132d github.com/spf13/cobra…

---

## [Is there a streamlined configuration guide?](https://openziti.discourse.group/t/is-there-a-streamlined-configuration-guide/3553)

<div class="topic-metadata">

**Author:** [@amano](https://openziti.discourse.group/u/amano)\
**Replies:** 3\
**Last updated:** [December 8, 2024, 3:31pm UTC](https://openziti.discourse.group/t/is-there-a-streamlined-configuration-guide/3553 "2024-12-08T15:31:23Z")

</div>

Controller Deployment | OpenZiti gives me a bash script for configuration. I want to learn how to do it myself. Configuration Quickstart :: strongSwan Documentation seems streamlined enough. That's why I seriously consi…

---

## [Operating System Posture Check](https://openziti.discourse.group/t/operating-system-posture-check/3538)

<div class="topic-metadata">

**Author:** [@devawasthi](https://openziti.discourse.group/u/devawasthi)\
**Replies:** 1\
**Last updated:** [December 6, 2024, 1:28pm UTC](https://openziti.discourse.group/t/operating-system-posture-check/3538 "2024-12-06T13:28:56Z")

</div>

Hey, I had a question regarding postureChecks, when using operatingSystem Posture Check, we have the option to select the version on which we want to perform the check example payload - "operatingSystems": \[ { "type": …

---

## [Why router has multiple endpoints](https://openziti.discourse.group/t/why-router-has-multiple-endpoints/3516)

<div class="topic-metadata">

**Author:** [@ayushhsinghh](https://openziti.discourse.group/u/ayushhsinghh)\
**Replies:** 5\
**Last updated:** [December 4, 2024, 10:44pm UTC](https://openziti.discourse.group/t/why-router-has-multiple-endpoints/3516 "2024-12-04T22:44:58Z")

</div>

Hi, Why does OpenZiti have three API endpoints for routers: /edge-router /routers /transit-router I understand that Ziti routers can be configured differently based on their configuration files. However, does it make…

---

## [Docker example for private share does not work](https://openziti.discourse.group/t/docker-example-for-private-share-does-not-work/3533)

<div class="topic-metadata">

**Author:** [@workmaster2n](https://openziti.discourse.group/u/workmaster2n)\
**Replies:** 3\
**Last updated:** [December 4, 2024, 5:24pm UTC](https://openziti.discourse.group/t/docker-example-for-private-share-does-not-work/3533 "2024-12-04T17:24:40Z")

</div>

Trying to follow the example here: Docker Private Share | Zrok Looking at the contents of the file in the linked video, it appears that https://docs.zrok.io/zrok-private-share/compose.yml has changed and no longer works…

---

## [Change Controller Adresse/Port or migrate to a new controller](https://openziti.discourse.group/t/change-controller-adresse-port-or-migrate-to-a-new-controller/3495)

<div class="topic-metadata">

**Author:** [@tekook](https://openziti.discourse.group/u/tekook)\
**Replies:** 20\
**Last updated:** [December 2, 2024, 5:17pm UTC](https://openziti.discourse.group/t/change-controller-adresse-port-or-migrate-to-a-new-controller/3495 "2024-12-02T17:17:18Z")

</div>

So I have a medium sized setup: 1 Controller, 2 Public edge routers and about 12 private routers and 20 clients. Currently the controller is reachable via ctrl.example.com:1280 and the edge routers via edge1.example.com…

---

## [Stopped by Plume](https://openziti.discourse.group/t/stopped-by-plume/3510)

<div class="topic-metadata">

**Author:** [@Fabro](https://openziti.discourse.group/u/Fabro)\
**Replies:** 9\
**Last updated:** [November 29, 2024, 8:31pm UTC](https://openziti.discourse.group/t/stopped-by-plume/3510 "2024-11-29T20:31:18Z")

</div>

I want to access my website and server via zrok, when I try to do this via 'zrok share public localhost' or 'zrok share public localhost --backend-mod web', the website only comes up with 'Accress to this Website is Bloc…

---

## [Zrok in Australia](https://openziti.discourse.group/t/zrok-in-australia/3452)

<div class="topic-metadata">

**Author:** [@oliverjhn](https://openziti.discourse.group/u/oliverjhn)\
**Replies:** 2\
**Last updated:** [November 21, 2024, 11:45am UTC](https://openziti.discourse.group/t/zrok-in-australia/3452 "2024-11-21T11:45:37Z")

</div>

Hi, I am going to use Zrok to run a game server to get around my CGNAT, and was wondering if you have any Australian.... nodes or whatever the access points are called that would affect ping (I'm still not completely fam…

---

## [Read-Only user for Monitoring?](https://openziti.discourse.group/t/read-only-user-for-monitoring/3442)

<div class="topic-metadata">

**Author:** [@greggw01](https://openziti.discourse.group/u/greggw01)\
**Replies:** 2\
**Last updated:** [November 18, 2024, 9:38pm UTC](https://openziti.discourse.group/t/read-only-user-for-monitoring/3442 "2024-11-18T21:38:59Z")

</div>

Greetings! I am working on ways to monitor the health of my OpenZiti infrastructure. One of the first things I would like to be observable and alertable, is the health of each router. In looking at this, I have found …

---

## [Sockets encapsulation](https://openziti.discourse.group/t/sockets-encapsulation/3434)

<div class="topic-metadata">

**Author:** [@opcode](https://openziti.discourse.group/u/opcode)\
**Replies:** 3\
**Last updated:** [November 15, 2024, 3:55pm UTC](https://openziti.discourse.group/t/sockets-encapsulation/3434 "2024-11-15T15:55:37Z")

</div>

I manage a large number of standard servers and Kubernetes clusters, hosting numerous independent projects. Each project consists of applications and their associated services, such as databases, message queues, file sto…

---

## [How to override/set openziti endpoint in zrok?](https://openziti.discourse.group/t/how-to-override-set-openziti-endpoint-in-zrok/3423)

<div class="topic-metadata">

**Author:** [@jkotra](https://openziti.discourse.group/u/jkotra)\
**Replies:** 7\
**Last updated:** [November 14, 2024, 3:32am UTC](https://openziti.discourse.group/t/how-to-override-set-openziti-endpoint-in-zrok/3423 "2024-11-14T03:32:12Z")

</div>

Hello. I'm getting the following error while connected to a Cisco Secure Client VPN: \[ERROR\]: error creating topTunnel backend (error listening: failed to listen: no apisession, authentication attempt failed: Post "htt…

---

## [Slowness using zrok](https://openziti.discourse.group/t/slowness-using-zrok/3413)

<div class="topic-metadata">

**Author:** [@fedex1](https://openziti.discourse.group/u/fedex1)\
**Replies:** 4\
**Last updated:** [November 12, 2024, 10:58pm UTC](https://openziti.discourse.group/t/slowness-using-zrok/3413 "2024-11-12T22:58:39Z")

</div>

Moments ago (17:50 Eastern Time) we were seeing very slow responses when using zrok. For example, time curl 'https://tidalforce.share.zrok.io/multi\_search?x-typesense-api-key=GGvyHonOH3SQBNNhkyCLr6XnuXFJNHIw' -H 'acc…

---

## [Docker self hosting: failed to verify certificate: x509: certificate is valid for localhost, ziti.zrok.0101.party, not ziti.share.0101.party](https://openziti.discourse.group/t/docker-self-hosting-failed-to-verify-certificate-x509-certificate-is-valid-for-localhost-ziti-zrok-0101-party-not-ziti-share-0101-party/3417)

<div class="topic-metadata">

**Author:** [@jkotra](https://openziti.discourse.group/u/jkotra)\
**Replies:** 3\
**Last updated:** [November 12, 2024, 4:34pm UTC](https://openziti.discourse.group/t/docker-self-hosting-failed-to-verify-certificate-x509-certificate-is-valid-for-localhost-ziti-zrok-0101-party-not-ziti-share-0101-party/3417 "2024-11-12T16:34:11Z")

</div>

Hello everyone, I was trying to setup zrok on personal VPS. However, I'm getting the following error in zrok-frontend docker compose logs zrok-frontend -f zrok-frontend-1 | RESTY 2024/11/12 15:02:23 ERROR Post "https…

---

## [CertificateAuthorityDeletion](https://openziti.discourse.group/t/certificateauthoritydeletion/3411)

<div class="topic-metadata">

**Author:** [@devawasthi](https://openziti.discourse.group/u/devawasthi)\
**Replies:** 1\
**Last updated:** [November 12, 2024, 12:14pm UTC](https://openziti.discourse.group/t/certificateauthoritydeletion/3411 "2024-11-12T12:14:08Z")

</div>

Hi, I have a question regarding identities linked to a Certificate Authority (CA). If I delete this CA, OpenZiti deletes it —so will those linked identities continue to function? If they won’t, could you explain why the …

---

## [Architecture advice for ensuring isolation for multiple apps deployed within multiple private corporate networks](https://openziti.discourse.group/t/architecture-advice-for-ensuring-isolation-for-multiple-apps-deployed-within-multiple-private-corporate-networks/3384)

<div class="topic-metadata">

**Author:** [@SSGeo](https://openziti.discourse.group/u/SSGeo)\
**Replies:** 7\
**Last updated:** [November 8, 2024, 4:02pm UTC](https://openziti.discourse.group/t/architecture-advice-for-ensuring-isolation-for-multiple-apps-deployed-within-multiple-private-corporate-networks/3384 "2024-11-08T16:02:25Z")

</div>

Hi All, Total newbie here looking to see if OpenZiti can fulfill my requirements for a new project, and would be very grateful of any advice as to whether this is the right path to dive down. I have contracted a dev te…

---

## [Issues in scraping controller metrics with otel collector prometheus receiver](https://openziti.discourse.group/t/issues-in-scraping-controller-metrics-with-otel-collector-prometheus-receiver/3389)

<div class="topic-metadata">

**Author:** [@av-dev](https://openziti.discourse.group/u/av-dev)\
**Replies:** 1\
**Last updated:** [November 7, 2024, 1:09pm UTC](https://openziti.discourse.group/t/issues-in-scraping-controller-metrics-with-otel-collector-prometheus-receiver/3389 "2024-11-07T13:09:14Z")

</div>

I am running controller version 1.1.15 and exposing the metrics api over localhost using its own binding. - name: api-metrics-localhost bindPoints: - interface: 127.0.0.1:2112 address: 127.0.0.1:2112…

---

## [AWS Self hosted K8s/DB scenarios](https://openziti.discourse.group/t/aws-self-hosted-k8s-db-scenarios/3356)

<div class="topic-metadata">

**Author:** [@sarasensible](https://openziti.discourse.group/u/sarasensible)\
**Replies:** 6\
**Last updated:** [November 1, 2024, 11:07pm UTC](https://openziti.discourse.group/t/aws-self-hosted-k8s-db-scenarios/3356 "2024-11-01T23:07:27Z")

</div>

Hello, great to find this project! I would like to replace our current Zero Trust network with Open Ziti. I need to connect it to our Kubernetes cluster and to our Aurora databases. Can I self host Open Ziti on a pri…

---

## [Following quick start tutorial wrong DNS as JWT Issuer](https://openziti.discourse.group/t/following-quick-start-tutorial-wrong-dns-as-jwt-issuer/3353)

<div class="topic-metadata">

**Author:** [@joseph-salem](https://openziti.discourse.group/u/joseph-salem)\
**Replies:** 2\
**Last updated:** [November 1, 2024, 4:00pm UTC](https://openziti.discourse.group/t/following-quick-start-tutorial-wrong-dns-as-jwt-issuer/3353 "2024-11-01T16:00:06Z")

</div>

Hi, I am currently trying to follow the quick start Host OpenZiti Anywhere | OpenZiti. I am using a dns while setting the environments. When I finish setting everything up. I go into the console and create a new identi…

---

## [Q:Generating Certificates for ZAC Without Using Docker Quickstart](https://openziti.discourse.group/t/q-generating-certificates-for-zac-without-using-docker-quickstart/3339)

<div class="topic-metadata">

**Author:** [@KerwinKoo](https://openziti.discourse.group/u/KerwinKoo)\
**Replies:** 2\
**Last updated:** [October 31, 2024, 1:46am UTC](https://openziti.discourse.group/t/q-generating-certificates-for-zac-without-using-docker-quickstart/3339 "2024-10-31T01:46:46Z")

</div>

Help. I am trying to simulate ZAC using POSTMAN (I have not actually installed ZAC, but I understand the problem is the same). Through the article at , I only saw "If you have used the Local - With Docker quickstart to…

---

## [Fixing Expired Cert on Existing Frontend](https://openziti.discourse.group/t/fixing-expired-cert-on-existing-frontend/3331)

<div class="topic-metadata">

**Author:** [@0xRy4n](https://openziti.discourse.group/u/0xRy4n)\
**Replies:** 1\
**Last updated:** [October 28, 2024, 7:08pm UTC](https://openziti.discourse.group/t/fixing-expired-cert-on-existing-frontend/3331 "2024-10-28T19:08:05Z")

</div>

I managed to get Zrok setup and working a while back, but I've realized the certs for my API endpoint have expired (api.zrok.mysite.com) I'm not sure how to renew this. I don't think I used Nginx originally since my ngi…

---

## [It's possible to setup zrok on IPv6 VPS?](https://openziti.discourse.group/t/its-possible-to-setup-zrok-on-ipv6-vps/3306)

<div class="topic-metadata">

**Author:** [@mrPatriko](https://openziti.discourse.group/u/mrPatriko)\
**Replies:** 9\
**Last updated:** [October 25, 2024, 9:09am UTC](https://openziti.discourse.group/t/its-possible-to-setup-zrok-on-ipv6-vps/3306 "2024-10-25T09:09:29Z")

</div>

Hi community! I've been trying for a few days to set up zrok on my VPS, which is mostly IPv6. I need to proxy my domain through Cloudflare to point to my public IPv6 address. I'm really new to IPv6. Has anyone done a ful…

---

## [Trying to understand how the edge-router "authenticates" edge-clients](https://openziti.discourse.group/t/trying-to-understand-how-the-edge-router-authenticates-edge-clients/3279)

<div class="topic-metadata">

**Author:** [@plakdawa](https://openziti.discourse.group/u/plakdawa)\
**Replies:** 4\
**Last updated:** [October 24, 2024, 7:07pm UTC](https://openziti.discourse.group/t/trying-to-understand-how-the-edge-router-authenticates-edge-clients/3279 "2024-10-24T19:07:39Z")

</div>

I have a fairly clear understanding of edge-client authentication with the controller. This ends up with an opaque session-token (which is a uuid). The client can use the session-token to retrieve a list of services it h…

---

## [Using https to access services over OpenZiti?](https://openziti.discourse.group/t/using-https-to-access-services-over-openziti/901)

<div class="topic-metadata">

**Author:** [@jruiz94](https://openziti.discourse.group/u/jruiz94)\
**Replies:** 17\
**Last updated:** [October 23, 2024, 12:40pm UTC](https://openziti.discourse.group/t/using-https-to-access-services-over-openziti/901 "2024-10-23T12:40:25Z")

</div>

(Apologies beforehand if I’m misusing some terminology) I have deployed OpenZiti following these tutorial series, and I successfully tested it with a Minecraft Server (just like the examples) This made me thought that …

---

## [Ziti router from quickstart conflicting with existing local DNS after update](https://openziti.discourse.group/t/ziti-router-from-quickstart-conflicting-with-existing-local-dns-after-update/3233)

<div class="topic-metadata">

**Author:** [@Himekaidou](https://openziti.discourse.group/u/Himekaidou)\
**Replies:** 11\
**Last updated:** [October 14, 2024, 7:57pm UTC](https://openziti.discourse.group/t/ziti-router-from-quickstart-conflicting-with-existing-local-dns-after-update/3233 "2024-10-14T19:57:02Z")

</div>

Hello! I have a setup built originally from the quickstart on a raspberry pi that has been working wonderfully for a few months. Recently (from about a week ago), I updated the ziti binaries, but a new problem has come…

---

## [Questions about edge-client certificate extension](https://openziti.discourse.group/t/questions-about-edge-client-certificate-extension/2293)

<div class="topic-metadata">

**Author:** [@plakdawa](https://openziti.discourse.group/u/plakdawa)\
**Replies:** 11\
**Last updated:** [October 13, 2024, 4:38pm UTC](https://openziti.discourse.group/t/questions-about-edge-client-certificate-extension/2293 "2024-10-13T16:38:38Z")

</div>

I have a couple of questions about edge-client certificate extension: Assuming the client certificate is managed by Openziti, do the Openziti tunnellers currently extend client certificates automatically? What is the c…

[Previous page](https://openziti.discourse.group/c/support/general-questions/7.md?page=3)

[Next page](https://openziti.discourse.group/c/support/general-questions/7.md?page=5)
