# Windows Ziti-Tunnel Command Line

**URL:** <https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080>\
**Category:** Uncategorized\
**Created:** [February 14, 2023, 5:47pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080 "2023-02-14T17:47:02Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![cmbryner](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@cmbryner](https://openziti.discourse.group/u/cmbryner)\
**Post date:** [February 14, 2023, 5:47pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/1 "2023-02-14T17:47:02Z")

</div>

I am trying to Enroll a Client and a server into an offline Ziti Network Environment… The inital windows offline installer does not work getting various issues with Certs

I have since moved on to trying to call Ziti-tunnel from the exe without msi installation

The Following Steps were taken belwo:

1. Open command prompt as an admin
2. Run the Ziti-Tunnel. Command: ziti-edge-tunnell.exe run
3. From a second command prompt window enroll. Command: ziti-edge-tunnel.exe enroll -j c:\temp\client.jwt -i c:\some\idenity\path\client.json

The tunnel fails with the following error

 ![Can't connect controller](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/ef00291b100aeadd27a1b9c7e7d29e8baa6eae4a.png)  
 ![Failed Message](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/87472b0e33f789b920191087e1d7392d69564558.png)

---

<div class="post-metadata">

**Author:** ![cmbryner](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@cmbryner](https://openziti.discourse.group/u/cmbryner)\
**Post date:** [February 14, 2023, 6:09pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/2 "2023-02-14T18:09:15Z")

</div>

Going through a different tool it looks to be failing on connection because our controller was setup without dns so it resolves to localhost:1280 problem is the jwt file which is on a different machine resolves to localhost:1280 meaning it is going to itself

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [February 14, 2023, 6:10pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/3 "2023-02-14T18:10:34Z")

</div>

I was just typing all this up… I’ll keep typing but it looks like you got that sorted? Right?

**------------------------------------------------------------**

I would expect your controller certificate didn’t match the advertised address when seeing a “jwt verification failure”.

The jwt will have an ISS field that describes the url the enrolling endpoint must attach to. if you cat the jwt and put it into [jwt.io](http://jwt.io)’s jwt parser, is the url specified therein the “right” one?

**------------------------------------------------------------**

---

<div class="post-metadata">

**Author:** ![cmbryner](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@cmbryner](https://openziti.discourse.group/u/cmbryner)\
**Post date:** [February 14, 2023, 6:13pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/4 "2023-02-14T18:13:19Z")

</div>

Well I know the problem its now thinking about the solution as if I create a simple dns I have no clue the impacts it could have on the controller. Is there a way to update jwt to use the IP instead of dns

I honesty don’t know I have not really ever worked with one before

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [February 14, 2023, 6:16pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/5 "2023-02-14T18:16:14Z")

</div>

The way to influence what is placed into the controller is via the ‘address’ field of the controller’s configuration. Specifically the `edge.api.address` field. I would suspect that is set to “localhost” right now.

Here’s an example of one of mine:

```auto
    # address - required
    # The default address (host:port) to use for enrollment for the Client API. This value must match one of the addresses
    # defined in this Controller.WebListener.'s bindPoints.
    address: sg3:1280

```

Then down below you need a bindPoint that maps to this in the `web.name.bindPoints.address` setting:

```auto
web:
  # name - required
  # Provides a name for this listener, used for logging output. Not required to be unique, but is highly suggested.
  - name: client-management
    # bindPoints - required
    # One or more bind points are required. A bind point specifies an interface (interface:port string) that defines
    # where on the host machine the webListener will listen and the address (host:port) that should be used to
    # publicly address the webListener(i.e. mydomain.com, localhost, 127.0.0.1). This public address may be used for
    # incoming address resolution as well as used in responses in the API.
    bindPoints:
      #interface - required
      # A host:port string on which network interface to listen on. 0.0.0.0 will listen on all interfaces
      - interface: 0.0.0.0:1280
        # address - required
        # The public address that external incoming requests will be able to resolve. Used in request processing and
        # response content that requires full host:port/path addresses.
        address: sg3:1280

```

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [February 14, 2023, 6:18pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/6 "2023-02-14T18:18:30Z")

</div>

This also effects the PKI, you’ll need to make sure the certificates are valid for whatever values you place in there, meaning they have a SANS set for DNS:sg3 or IP:10.10.10.10. I can expand on that if you need/want me to, but if you know what I mean, I don’t need to 🙂

When the quickstart script executes, it makes an attempt to resolve the hostname and use that field but you don’t need to use that if you don’t want to… Let me know if that’s helpful or just more confusing…

---

<div class="post-metadata">

**Author:** ![cmbryner](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@cmbryner](https://openziti.discourse.group/u/cmbryner)\
**Post date:** [February 16, 2023, 1:09pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/7 "2023-02-16T13:09:49Z")

</div>

I was able to follow all your steps and change what was needed to be changed and I believe I am one key value away from working

 ![Valid for](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/241c3071a84c965355705cb61b5fa2039e1fb8a0.png)

---

<div class="post-metadata">

**Author:** ![cmbryner](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@cmbryner](https://openziti.discourse.group/u/cmbryner)\
**Post date:** [February 16, 2023, 1:16pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/8 "2023-02-16T13:16:15Z")

</div>

I only changed the Controller yaml file not the edge router and looking at the edge router localhost is listed quite a bit I have a feeling that is supposed to be updated could be wrong about that

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [February 16, 2023, 1:16pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/9 "2023-02-16T13:16:55Z")

</div>

Hey great!

That error right there means when the controller was created, it generated a PKI that's only valid for "localhost" type stuff. You'll probably have to replace the PKI at this point, and tbh the easiest way to accomplish that is with a total reinstall of the network... 😑 We could work through being surgical, but really, that's "the fastest and easiest" way. It also makes me think we should/could detect all IP addresses at "install" time and ask you which of the IPs you'd like to use along with 127.0.0.1...

The good news is that you _should_ be able to simply set EXTERNAL\_IP="10.50.1.22" and rerun the quickstart.

I just did that locally. (well, i used MY ip: `export EXTERNAL_IP="192.168.128.1"`) and I can see in my output of `expressInstall` this line:

> Creating server cert from ca: sg3-intermediate for sg3,localhost,sg3,sg3 / 127.0.0.1,192.168.128.1

Then I used openssl:

```auto
openssl s_client -connect 192.168.128.1:1280 | openssl x509 -text

```

And I can see the SANS set properly:

```auto
            X509v3 Subject Alternative Name:
                DNS:sg3, DNS:localhost, DNS:sg3, DNS:sg3, IP Address:127.0.0.1, IP Address:192.168.128.1

```

So that should resolve this issue.

---

<div class="post-metadata">

**Author:** ![cmbryner](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@cmbryner](https://openziti.discourse.group/u/cmbryner)\
**Post date:** [February 16, 2023, 1:23pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/10 "2023-02-16T13:23:00Z")

</div>

Stupid question I know but can I take the express Installer offline I had troubles with doing that and made the image and then moved to the lab but it would be so much easier if it can be offline

and if so would it just be the wget command to download it but don’t run the express install

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [February 16, 2023, 1:24pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/11 "2023-02-16T13:24:01Z")

</div>

Yes sure. Let me try it out fully disconnected and I’ll get back to you

---

<div class="post-metadata">

**Author:** ![cmbryner](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@cmbryner](https://openziti.discourse.group/u/cmbryner)\
**Post date:** [February 16, 2023, 1:25pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/12 "2023-02-16T13:25:13Z")

</div>

Yet again you are the best

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [February 16, 2023, 2:13pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/13 "2023-02-16T14:13:40Z")

</div>

Yep. It worked fine. I’m playing around with twitch streaming these sorta things too if you’re interested in watching me fumble and bumble through this as well… 🙂 [Twitch](https://www.twitch.tv/videos/1739816005)

Here’s basically what I did…

- on rhel79: block all outbound except for ssh (so i could USE the vm)

- on my workstation: pull down the `latest ziti-cli-function.sh` from my local computer:

- on my workstation: source `ziti-cli-functions.sh` and issue `getZiti` to pull down the latest ziti

- on my workstation: scp ziti-cli-functions and the ziti binaries to rhel

- on rhel79: set hostname [optional] `hostnamectl set-hostname "rhel79"`

- on rhel79: source ziti-cli-functions.sh

- on rhel79: call ‘unsetZitiEnv’, export ZITI\_BIN\_DIR and ZITI\_PWD, and run expressInstall:

- verify it all worked…

- on rhel79: start the controller: `startController`

- on rhel79: verify it all **actually** worked using openssl:

- see the SANS set properly (albeit with a few extra DNS entries lol):

---

<div class="post-metadata">

**Author:** ![cmbryner](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@cmbryner](https://openziti.discourse.group/u/cmbryner)\
**Post date:** [February 16, 2023, 6:02pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/14 "2023-02-16T18:02:06Z")

</div>

Everything Works perfect now I have a Client and server connected to the overlay I have snapped the baseline and handing it off

Thank you for all your support I will now be doing a lot of documentation

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [February 16, 2023, 7:35pm UTC](https://openziti.discourse.group/t/windows-ziti-tunnel-command-line/1080/15 "2023-02-16T19:35:47Z")

</div>

Excellent, that’s great to hear! If you ever want to share what you did or how you did it, I know we’d love to hear about it.

Cheers
