# Controller & Router Helm | Windows Edge Tun Can't Auth with Ext-jwt-signer

**URL:** <https://openziti.discourse.group/t/controller-router-helm-windows-edge-tun-cant-auth-with-ext-jwt-signer/4477>\
**Category:** Uncategorized\
**Created:** [May 2, 2025, 7:04pm UTC](https://openziti.discourse.group/t/controller-router-helm-windows-edge-tun-cant-auth-with-ext-jwt-signer/4477 "2025-05-02T19:04:57Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Tetrusp](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/tetrusp/32/3329_2.png) [@Tetrusp](https://openziti.discourse.group/u/Tetrusp)\
**Post date:** [May 5, 2025, 6:07pm UTC](https://openziti.discourse.group/t/controller-router-helm-windows-edge-tun-cant-auth-with-ext-jwt-signer/4477/3 "2025-05-05T18:07:30Z")

</div>

Good Afternoon @TheLumberjack,

Thank you for taking the time to help me!

I have the following errors with a default install of a Ziti Controller && Router in k8s.

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/a/a5c7afcd86667dd35d8c1b58105e89540259081c.png)

After following steps listed here -\> [No\_edge\_routers\_available - Support - openziti](https://openziti.discourse.group/t/no-edge-routers-available/4199/2)

```auto
ziti edge create edge-router-policy all-ids-public-ers --identity-roles '#all' --edge-router-roles '#public'

ziti edge update edge-router <router name> -a 'public'

ziti edge create service-edge-router-policy <router policy name> --service-roles '#all' --edge-router-roles '#all'

```

I get the following result.

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/4/4007336a41e8b920d096804e46c6ff42f23d92ac.png)

Also so far, there are no issues with K8s API access, so I am unsure why adding the policies last time took down the network on that cluster.

In anycase, moving onto this command

```auto
ziti ops verify ext-jwt-signer oidc --controller-url <ziti controller> <ext-jwt-signer name> --ca <ca-file.crt>

```

I get a timeout

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/7/78aecaed53fb20dcbd5ded0461660dd8e47bf5e0.png)

I am not sure why, when testing from the desktop client I was getting through the auth flow properly from Keycloak's perspective, with browser popups to the localhost callback page showing success.

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/6/69c731b55fe265be240a567541290ccfda7eb930.png)

I got a shell in the controller and can confirm the pod can reach the Keycloak server.

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/f/fd11cc408b18b6c730806268b626499451f17c29.png)

Could you also explain why i need to specify the CA file for every command? I checked my client json and can confirm the ca is there, however if I dont specify it, the ziti cli gives me a x509 validation error.

---

_[View the full topic](https://openziti.discourse.group/t/controller-router-helm-windows-edge-tun-cant-auth-with-ext-jwt-signer/4477)._
