# Creating certs for a remote private router

**URL:** <https://openziti.discourse.group/t/creating-certs-for-a-remote-private-router/694>\
**Category:** General Questions\
**Created:** [August 6, 2022, 9:09pm UTC](https://openziti.discourse.group/t/creating-certs-for-a-remote-private-router/694 "2022-08-06T21:09:43Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [August 7, 2022, 12:21pm UTC](https://openziti.discourse.group/t/creating-certs-for-a-remote-private-router/694/6 "2022-08-07T12:21:12Z")

</div>

This is the exact issue I was experiencing. I had to have a few days break to work on something else.. and will be revisiting this over the next few days.

I was getting this error when trying to setup a remote router that connected to a controller that I setup a while ago.. I believe the problem was with the controller PKI.. that caused this error

To resolve, @TheLumberjack provided the following instructions.. I have not gotten around to doing this just yet.. because I am trying to triangulate the specific cause of the problem

> [@Trouble shooting starting a remote public edge router](https://openziti.discourse.group/t/trouble-shooting-starting-a-remote-public-edge-router/687/30):
>
> Thanks for your help with this… I am finding this a very valuable learning experience.

What I understand is that there is some problem with the controller certificates. I should have more updates on this over the next few days. I was hesitant to just do this in case it caused other problems.

In contrast, what I did do in parallel.. to help with understanding the problem ... was to setup a new controller on a new machine using a fresh install. This seems to have worked..

Hence.. I believe the issue relates to the controller PKI.

Maybe.. try setting up a new controller on a new server. If this works.. then you know it's something related to the controller config..

Hopefully I can pin point the exact issue.. of which.. this a great opportunity to learn more about how the controller PKI is setup.

@TheLumberjack also provided some great insights in this post.. definitely work taking a read through.

> [@Verifying the CA / Router certs](https://openziti.discourse.group/t/verifying-the-ca-router-certs/689):
>
> As I learn more about Certificate Authorities… I am keen to better equip myself to verify the validity of certificates. I found the following command in one of the examples that was associated with building a new certificate authority. openssl verify -CAfile intermediate/certs/ca-chain.cert.pem intermediate/certs/www.example.com.cert.pem So… I thought to adapt this and test it out using the certificates created by OpenZiti. openssl verify -CAfile /home/opc/.ziti/quickstart/instance-2022041…

---

_[View the full topic](https://openziti.discourse.group/t/creating-certs-for-a-remote-private-router/694)._
