# Creating certs for a remote private router

**URL:** <https://openziti.discourse.group/t/creating-certs-for-a-remote-private-router/694>\
**Category:** General Questions\
**Created:** [August 6, 2022, 9:09pm UTC](https://openziti.discourse.group/t/creating-certs-for-a-remote-private-router/694 "2022-08-06T21:09:43Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [August 7, 2022, 1:40pm UTC](https://openziti.discourse.group/t/creating-certs-for-a-remote-private-router/694/8 "2022-08-07T13:40:47Z")

</div>

> [@arslane](#):
>
> Looks like the certificate is denying the controller’s connextion `certificate is valid for 127.0.0.1, not 144.24.198.122`, do you know what may cause this issue ?

Hunh. I must say that this is not expected. At first I thought this was going to be straightforward and that the external IP wasn't in the cert, but when I probed it, I could see this wasn't gonna be 'easy'.

Using openssl and this command one can inspect the certificate that is being returned:

```auto
openssl s_client -connect 144.24.198.122:6262 -showcerts | openssl x509 -text

```

When I did that, I can see in there that it is returning DNS/IP that 'seem' OK, but I think there's a bug in the quickstart. When we tell you to set the external dns to the external ip, it looks like the certificates that get generated by the controller will have entries for both the DNS name and the IP. Let me show you what I mean, here's what your server is returning (using that command above. i added line-wrapping in this post to make it more legible):

```auto
            X509v3 Subject Alternative Name:
                DNS:instance-20220723-2134, DNS:localhost, 
                DNS:instance-20220723-2134, DNS:144.24.198.122, DNS:144.24.198.122, 
                IP Address:127.0.0.1, IP Address:144.24.198.122, 
                IP Address:144.24.198.122

```

See how the SANS has DNS:144.24.198.122 **and also** has IP Address:144.24.198.122? I expect that the DNS is overriding the IP and this is what is causing the problem.

The easiest way to fix this will probably be to regenerate the server certificate, update the config, and restart the controller. I actually just covered this recently [with markamind over at here](https://openziti.discourse.group/t/trouble-shooting-starting-a-remote-public-edge-router/687/31). I think if you follow those instructions and get a "clean" server certificate where the SANS doesn't report a IP in the DNS section, it should work. I also think those steps are pretty clear, but if not, post back. We'll get this going, I'm sure of it! 🙂

---

_[View the full topic](https://openziti.discourse.group/t/creating-certs-for-a-remote-private-router/694)._
