Trying to migrate to HA I messed up my previous working configuration.
Short story, my second node, on different host, was misconfigured (same advertiseaddress then first node) so I disabled it and restored backup of first node (replaced full .ziti folder)
Since then, my Android app is unable to connect any more.
I deleted the app storage and created a new identity. Tried to enrol it and everything seem fine on my phone: I'm authenticated and I can see services.
On the controller the new identity is offline and has still the generic desktop icon
On every router I'm getting
{"error":"no api session found for token [eyJhbGciOiJSUzI1NiIsImtpZCI6IjYzZmZkZGQ3MzBiY2VhMzM1NzQ1MzEyMGY5YTk0YTllZTczMThiYjMiLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsib3BlbnppdGkiXSwiZXhwIjoxNzM5NDQ3OTg0LCJpYXQiOjE3Mzk0NDYxODQsImlzcyI6Imh0dHBzOi8veml0aS5jaWN1Y2kuaXQ6NDQzL29pZGMiLCJqdGkiOiJjYTFiN2Y2My1jMTVhLTRhODctODFmNy0yMzc5YzhlYjUxZWMiLCJuYmYiOjE3Mzk0NDYxODQsInN1YiI6InJpNlVqSFhkcSIsInpfYWlkIjoib3BlbnppdGkiLCJ6X2FzaWQiOiI5NDI0YmM5Zi0xMTA2LTRjNjctYjk3MS01MDIxNzkxNDI5MzUiLCJ6X2NmcyI6WyI2NWM5NzRjNDQ3NjQwYWQyNjU1YTEwODdjZDk4NDc5ODRkOTllMDU2IiwiMzE0MWI5Njg0NDQyNmVmYjg0YjQ1NDdmMDUzNDQzZWFlMWUzY2VjMyIsIjgzNmFlMzlmOTdlOTYyOGQ4NzcxNDkzMTViNWEyYThkNDdiNTc1YjgiXSwiel9lbnYiOnt9LCJ6X2ljZSI6dHJ1ZSwiel9yYSI6IjkzLjM4LjI0OS42Mzo2MTQ0NSIsInpfc2RrIjp7fSwiel90IjoiYSJ9.Xv66i0OXOMTmrAjGlO5e29SF-M9bM4doY7B0QPXdnlFrr9N98FdEeQCJGSlEVCKSbbwQlhq150bQYrN8sl9mMjvDR7UKgP07oU1TaM3uISOfblAGtIssBw8jF3S4k6iBbpZMJ2A0nhM-LUmMPuLOpRWdIHDUc6HAlS_FHHYjFK77y10CrE1ZzArurb4JOqGXrwXCXxAYZkYPObE9xgbjMYvfRjBiqkNxD9aMQuRLFcKe63ycsmXotFokn2BSDmThUYZDwdxs69BKDEPad0YPhBJv54I7XLH1Fv8XsOP2NIoYuMWhHbMceZ76KZklOgUaXzL-QuJ89NSPIr22jzbNwiqBPdicUlBn7FKawTV89ESKRJoWypnhhjJh2T9pq9keEPaZW7Hoz2ZyPWoGsO6bCiwf7fV4Bf5mD6mVQrUR00cA6Exiv-Ch-nt2_sLW3FvN-YFxSDLnVSBlPKNCc-fk1piccTgRjuRBMYaM9R69p3ewgxaBBZOX5-Ua-QOln7kawUfqLaauOcpLqyIKBxePGS8-iH2-noviBoUKc7BJtWwo41LkAU0K_BYygVbuhlIaEKTShGrBnrZCdSDFFWhGlzSi83O3EHVrQUyG1J5CdvsE0sr-_pUzrDIdkIIisCIKAHr_ic8LoNQoDWSMBtrt8RUSxJ0nNOBHxuaeawjkCck], fingerprint: [65c974c447640ad2655a1087cd9847984d99e056], subjects [[CN=ri6UjHXdq,O=OpenZiti CN=cqchomeoverlay-signing-intermediate,OU=ADV-DEV,O=NetFoundry,L=Charlotte,C=US CN=cqchomeoverlay-signing-intermediate_grandparent_intermediate,OU=ADV-DEV,O=NetFoundry,L=Charlotte,C=US]]","file":"github.com/openziti/channel/v3@v3.0.5/impl.go:124","func":"github.com/openziti/channel/v3.AcceptNextChannel.func1","level":"error","msg":"failure accepting channel edge with underlay u{classic}-\u003ei{OlxV}","time":"2025-02-13T11:29:54.749Z"}
on the controller I get, during enrolment
Feb 13 11:42:20 cqchomeoverlay ziti[1088321]: {"file":"github.com/openziti/ziti/controller/raft/fsm.go:152","func":"github.com/openziti/ziti/controller/raft.(*BoltDbFsm).Apply","index":374,"level":"info","msg":"apply log with type *model.ReplaceEnrollmentWithAuthenticatorCmd","time":"2025-02-13T11:42:20.848Z"}
Tunnel identities on linux clients are working just fine.
I cannot check my windows client right now.
I also reinstalled from scratch one of my routers, with no difference.