# Your First Service - Zero Trust Host Access

**URL:** <https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202>\
**Category:** Uncategorized\
**Created:** [March 4, 2024, 3:43pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202 "2024-03-04T15:43:30Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![rhansen](https://avatars.discourse-cdn.com/v4/letter/r/22d042/32.png) [@rhansen](https://openziti.discourse.group/u/rhansen)\
**Post date:** [March 4, 2024, 3:43pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/1 "2024-03-04T15:43:30Z")

</div>

I get the following error when doing step #4 of the Guide from [Your First Service | OpenZiti](https://openziti.io/docs/learn/quickstarts/services/ztha/)

ziti edge create config http.host.v1 host.v1 '{"protocol":"tcp", "address":"'"${http\_server}"'", "port":80}'  
error: error creating configs instance in Ziti Edge Controller at [https://serveroek.mywire.org:8441/edge/management/v1](https://serveroek.mywire.org:8441/edge/management/v1). Status code: 400 Bad Request, Server returned: {  
"error": {  
"cause": {  
"field": "address",  
"reason": "address is invalid: address: Must not validate the schema (not)",  
"value": ""  
},  
"code": "COULD\_NOT\_VALIDATE",  
"message": "The supplied request contains an invalid document or no valid accept content were available, see cause",  
"requestId": "HeEm5vrlx"  
},  
"meta": {  
"apiEnrollmentVersion": "0.0.1",  
"apiVersion": "0.0.1"  
}  
}

I initially used zitiLogin and then #1, #2 and #3 successfully created the two identities and the intercept.v1 configuration. When I copy [https://serveroek.mywire.org:8441/edge/management/v1](https://serveroek.mywire.org:8441/edge/management/v1) into my browser it does show the following content:

{  
"data": {  
"apiVersions": {  
"edge": {  
"v1": {  
"apiBaseUrls": [  
"[https://serveroek.mywire.org:8441/edge/client/v1](https://serveroek.mywire.org:8441/edge/client/v1)"  
],  
"path": "/edge/client/v1"  
}  
},  
"edge-client": {  
"v1": {  
"apiBaseUrls": [  
"[https://serveroek.mywire.org:8441/edge/client/v1](https://serveroek.mywire.org:8441/edge/client/v1)"  
],  
"path": "/edge/client/v1"  
}  
},  
"edge-management": {  
"v1": {  
"apiBaseUrls": [  
"[https://serveroek.mywire.org:8441/edge/management/v1](https://serveroek.mywire.org:8441/edge/management/v1)"  
],  
"path": "/edge/management/v1"  
}  
}  
},  
"buildDate": "2024-02-10T05:53:17Z",  
"capabilities": ,  
"revision": "7c53aa006529",  
"runtimeVersion": "go1.21.6",  
"version": "v0.32.2"  
},  
"meta": {}  
}

Any Ideas why this might not work? Or what I could do to make it work?

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [March 4, 2024, 4:05pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/2 "2024-03-04T16:05:30Z")

</div>

Hi @rhansen, welcome to the community and to OpenZiti!

This problem happens now-and-then... We should tighten up that example and maybe make it bespoke to how you deploy your network, and not require docker...

Let's take a step back and just get an overview of where you're at. It'll help me help you. How'd you deploy your OpenZiti overlay network? Can you just give me the topology of how it's laid out a little bit?

Generally sepaking the `address is invalid: address` error from the first message you posted means the address field -- this here: `"address":"'"${http_server}"'"` is probably incorrect, probably because the http\_server variable isn't quite set right.

We can simplify it by just using straight ziti commands, without the messiness of variables causing confusion though.

From that guide, the main takeaway is that to make a first service using tunnelers (the way most people start), the following things need to be configured/setup:

- a hosting identity needs to exist - you do that by creating an identity however you like (ziti cli or ZAC)
- a dialing identity needs to exist - you do that by creating an identity however you like (ziti cli or ZAC)
- a **config** needs to exist specifying the 'client' side (also referred to as the intercept or dial side sometimes)
- a **config** needs to exist specifying the 'offload' side (also referred to as the host or bind side sometimes)
- a **service** needs to exist that ties those two configs together
- a **service-policy** needs to exist that authorizes the client/dial/intercepting identity to 'dial' the service
- a **service-policy** needs to exist that authorizes the host/server/bind identity to 'bind' the service

Those are all represented on that page in the "Configuring the Overlay - Overview" section as steps 1 through 7 and I've just re-paraphrased the content here...

Your step 4 seems to be failing because `http_server` isn't set, is my guess.

Assuming you have started a demo server like the page shows:

```auto
docker run -d --rm --name web-test -p 80:8000 openziti/hello-world

```

Step 4 would look something like this

```auto
ziti edge create config http.host.v1 host.v1 '{"protocol":"tcp", "address":"127.0.0.1", "port":80}'

```

You need to use the correct value for the address. shown above, I've used 127.0.0.1 but that address needs to be something the "hosting" tunneler side can reach. So if you're say, running your ziti-edge-tunnel host in AWS, well then you should start that docker conatiner in AWS (ideally on that same machine) and then you can jsut use 127.0.0.1...

That help? I dunno if this is too much info or if this is helpful... 🙂

---

<div class="post-metadata">

**Author:** ![rhansen](https://avatars.discourse-cdn.com/v4/letter/r/22d042/32.png) [@rhansen](https://openziti.discourse.group/u/rhansen)\
**Post date:** [March 18, 2024, 11:52am UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/3 "2024-03-18T11:52:45Z")

</div>

Hi @TheLumberjack,

thanks for the response. I apologise I have been away and have not responded because of that. I have a very simply linux server on a VM showing a webpage. I wanted to use this example to make my initial contact with OpenZiti as simply as possible.

Unfortunately, I have gone a few steps backwards, since now my Ziti commands are no longer found. Do you know why this might be the case?

I have run sudo systemctl -q status ziti-controller --lines=0 --no-pager and sudo systemctl -q status ziti-router --lines=0 --no-pager and the controller and router both started automatically after reboot as intended, but the commands no longer work.

Thanks for the help 🙂

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [March 18, 2024, 12:00pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/4 "2024-03-18T12:00:07Z")

</div>

> [@rhansen](#):
>
> Unfortunately, I have gone a few steps backwards, since now my Ziti commands are no longer found. Do you know why this might be the case?

The expressInstall will download the ziti binary and put it into the location of the quickstart for you. That's generally convenient, but it's easy to lose track of that. It also adds that location to your "path" so that the `ziti` command is always found. If you want to use the ziti-cli-function.sh script has a "getZiti" that I use all the time which will fetch the latest ziti for you and put it on the path: `source /dev/stdin <<< "$(wget -qO- https://get.openziti.io/ziti-cli-functions.sh)"; getZiti "yes"`... do be careful, you should know what version you're running. I tend to "only ever want the latest", so for me this is great but if you want control over the version, you should know what `ziti` version you're installing, where it is etc. My guess is that you never got to this point the last time around...

Your binaries are likely located at the default path for the quickstart:

```auto
$HOME/.ziti/quickstart/$(hostname)/ziti-bin/ziti-v0.*

```

For me that path looks like this:

```auto
/home/ubuntu/.ziti/quickstart/ip-172-31-47-200/ziti-bin/ziti-v0.33.1

```

To get `ziti` back working, add the correct path to your `$PATH` environment variable.

hth

---

<div class="post-metadata">

**Author:** ![rhansen](https://avatars.discourse-cdn.com/v4/letter/r/22d042/32.png) [@rhansen](https://openziti.discourse.group/u/rhansen)\
**Post date:** [March 21, 2024, 11:40am UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/5 "2024-03-21T11:40:44Z")

</div>

That worked and my Ziti commands are working again.

When I try to Login with **ziti edge login** it promts me for a password and I enter the automatically generated password that ziti generated (this worked the first time around before I made the original post) and now It is saying, that there is an invalid Auth:

Using controller url: [https://serveroek.mywire.org:8441/edge/management/v1](https://serveroek.mywire.org:8441/edge/management/v1) from identity 'default' in config file: /home/useroek/.config/ziti/ziti-cli.json  
Using username: admin from identity 'default' in config file: /home/useroek/.config/ziti/ziti-cli.json  
Enter password:  
error: unable to authenticate to [https://serveroek.mywire.org:8441/edge/management/v1](https://serveroek.mywire.org:8441/edge/management/v1). Status code: 401 Unauthorized, Server returned: {  
"error": {  
"code": "INVALID\_AUTH",  
"message": "The authentication request failed",  
"requestId": "Hw92V03RK"  
},  
"meta": {  
"apiEnrollmentVersion": "0.0.1",  
"apiVersion": "0.0.1"  
}  
}

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [March 21, 2024, 11:44am UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/6 "2024-03-21T11:44:03Z")

</div>

So you copied the big long password that express install generates and saved it somewhere, and you haven't re-run expressInstall, right?

Your password is also saved into a .env file. if you grep it with:

```auto
grep ZITI_PWD $HOME/.ziti/quickstart/$(hostname)/$(hostname).env

```

you'll find it:

```auto
if [["$ZITI_PWD" == ""]]; then export ZITI_PWD=" __YOUR_PWD_HERE__!";

```

You're sure you have that same password? Does it contain a `#` character or `'` or something else that's interfering with your terminal?

---

<div class="post-metadata">

**Author:** ![rhansen](https://avatars.discourse-cdn.com/v4/letter/r/22d042/32.png) [@rhansen](https://openziti.discourse.group/u/rhansen)\
**Post date:** [March 26, 2024, 9:20am UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/7 "2024-03-26T09:20:02Z")

</div>

I did copy it and it seems that it copied all but the last character and then it worked again. I have since logged into the edge controller of a college using the ZAC in a browser but not I cannot log into my own edge server anymore using the ziti CLI commands.

Instead of promting a password after `ziti edge login` I now get the following:

```auto
Using controller url: https://serveroek.mywire.org:8441/edge/management/v1 from identity 'default' in config file: /home/useroek/.config/ziti/ziti-cli.json
[30.002] INFO ziti/ziti/cmd/helpers.StandardErrorMessage: Connection error: Get https://serveroek.mywire.org:8441/.well-known/est/cacerts: dial tcp: lookup serveroek.mywire.org: i/o timeout
Unable to connect to the server: dial tcp: lookup serveroek.mywire.org: i/o timeout

```

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [March 26, 2024, 8:12pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/8 "2024-03-26T20:12:53Z")

</div>

My guess is that the server is offline? Can you connect to that url? You sure it's running? 🙂

If it's running then make sure the docker port is exposed properly. It's easy for local or web firewalls to get in the way of connecting.

---

<div class="post-metadata">

**Author:** ![rhansen](https://avatars.discourse-cdn.com/v4/letter/r/22d042/32.png) [@rhansen](https://openziti.discourse.group/u/rhansen)\
**Post date:** [April 5, 2024, 8:11am UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/9 "2024-04-05T08:11:37Z")

</div>

The server was running and the URL was available the whole time. I then ran  
`sudo apt list --upgradable`  
and got a whole list of packages to upgrade:

> Listing... Done  
> libapache2-mod-php8.2/jammy 8.2.17-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.2.15-1+ubuntu22.04.1+deb.sury.org+1]  
> libapache2-mod-php8.3/jammy 8.3.4-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.3.3-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.2-cli/jammy 8.2.17-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.2.15-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.2-common/jammy 8.2.17-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.2.15-1+ubuntu22.04.1+deb.sury.org+1]php8.2-mbstring/jammy 8.2.17-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.2.15-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.2-mysql/jammy 8.2.17-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.2.15-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.2-opcache/jammy 8.2.17-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.2.15-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.2-readline/jammy 8.2.17-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.2.15-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.2-zip/jammy 8.2.17-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.2.15-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.2/jammy 8.2.17-1+ubuntu22.04.1+deb.sury.org+1 all [upgradable from: 8.2.15-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.3-cli/jammy 8.3.4-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.3.3-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.3-common/jammy 8.3.4-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.3.3-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.3-opcache/jammy 8.3.4-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.3.3-1+ubuntu22.04.1+deb.sury.org+1]  
> php8.3-readline/jammy 8.3.4-1+ubuntu22.04.1+deb.sury.org+1 amd64 [upgradable from: 8.3.3-1+ubuntu22.04.1+deb.sury.org+1]php8.3/jammy 8.3.4-1+ubuntu22.04.1+deb.sury.org+1 all [upgradable from: 8.3.3-1+ubuntu22.04.1+deb.sury.org+1]  
> ziti-edge-tunnel/jammy 0.22.25 amd64 [upgradable from: 0.22.24]

When I then run  
`sudo apt upgrade`  
I get the following and am not sure how to fix this issue (possibly has nothing to do with OpenZiti)

> Reading package lists... Done  
> Building dependency tree... Done  
> Reading state information... Done  
> Calculating upgrade... Done  
> The following packages will be upgraded:  
> libapache2-mod-php8.2 libapache2-mod-php8.3 php8.2 php8.2-cli php8.2-common php8.2-mbstring php8.2-mysql php8.2-opcache php8.2-readline php8.2-zip php8.3 php8.3-cli php8.3-common php8.3-opcache  
> php8.3-readline ziti-edge-tunnel  
> 16 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.  
> Need to get 12.5 MB of archives.  
> After this operation, 6,144 B of additional disk space will be used.  
> Do you want to continue? [Y/n] y  
> Ign:1 [https://packages.openziti.org/zitipax-openziti-deb-stable](https://packages.openziti.org/zitipax-openziti-deb-stable) jammy/main amd64 ziti-edge-tunnel amd64 0.22.25  
> Ign:2 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-zip amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:3 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-readline amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:1 [https://packages.openziti.org/zitipax-openziti-deb-stable](https://packages.openziti.org/zitipax-openziti-deb-stable) jammy/main amd64 ziti-edge-tunnel amd64 0.22.25  
> Ign:4 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-opcache amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:1 [https://packages.openziti.org/zitipax-openziti-deb-stable](https://packages.openziti.org/zitipax-openziti-deb-stable) jammy/main amd64 ziti-edge-tunnel amd64 0.22.25  
> Ign:5 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-mysql amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Err:1 [https://packages.openziti.org/zitipax-openziti-deb-stable](https://packages.openziti.org/zitipax-openziti-deb-stable) jammy/main amd64 ziti-edge-tunnel amd64 0.22.25  
> Temporary failure resolving '[packages.openziti.org](http://packages.openziti.org)'  
> Ign:6 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-mbstring amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:7 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 libapache2-mod-php8.2 amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:8 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-cli amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:9 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-common amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:10 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-readline amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:11 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-opcache amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:12 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 libapache2-mod-php8.3 amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:13 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-cli amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:14 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-common amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:15 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2 all 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:16 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3 all 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:2 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-zip amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:3 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-readline amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:4 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-opcache amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:5 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-mysql amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:6 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-mbstring amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:7 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 libapache2-mod-php8.2 amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:8 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-cli amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:9 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-common amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:10 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-readline amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:11 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-opcache amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:12 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 libapache2-mod-php8.3 amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:13 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-cli amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:14 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-common amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:15 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2 all 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:16 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3 all 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:2 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-zip amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:3 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-readline amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:4 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-opcache amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:5 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-mysql amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:6 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-mbstring amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:7 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 libapache2-mod-php8.2 amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:8 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-cli amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:9 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-common amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:10 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-readline amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:11 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-opcache amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:12 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 libapache2-mod-php8.3 amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:13 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-cli amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:14 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-common amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:15 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2 all 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Ign:16 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3 all 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Err:2 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-zip amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:3 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-readline amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:4 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-opcache amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:5 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-mysql amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:6 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-mbstring amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:7 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 libapache2-mod-php8.2 amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:8 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-cli amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:9 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2-common amd64 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:10 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-readline amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:11 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-opcache amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:12 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 libapache2-mod-php8.3 amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:13 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-cli amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:14 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3-common amd64 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:15 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.2 all 8.2.17-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> Err:16 [Index of /ondrej/php/ubuntu](https://ppa.launchpadcontent.net/ondrej/php/ubuntu) jammy/main amd64 php8.3 all 8.3.4-1+ubuntu22.04.1+deb.sury.org+1  
> Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-zip\_8.2.17-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-zip_8.2.17-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-readline\_8.2.17-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-readline_8.2.17-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-opcache\_8.2.17-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-opcache_8.2.17-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-mysql\_8.2.17-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-mysql_8.2.17-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-mbstring\_8.2.17-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-mbstring_8.2.17-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/libapache2-mod-php8.2\_8.2.17-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/libapache2-mod-php8.2_8.2.17-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-cli\_8.2.17-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-cli_8.2.17-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-common\_8.2.17-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2-common_8.2.17-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/php8.3-readline\_8.3.4-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/php8.3-readline_8.3.4-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/php8.3-opcache\_8.3.4-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/php8.3-opcache_8.3.4-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/libapache2-mod-php8.3\_8.3.4-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/libapache2-mod-php8.3_8.3.4-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/php8.3-cli\_8.3.4-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/php8.3-cli_8.3.4-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/php8.3-common\_8.3.4-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_amd64.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/php8.3-common_8.3.4-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_amd64.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2\_8.2.17-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_all.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.2/php8.2_8.2.17-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_all.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/php8.3\_8.3.4-1%2Bubuntu22.04.1%2Bdeb.sury.org%2B1\_all.deb](https://ppa.launchpadcontent.net/ondrej/php/ubuntu/pool/main/p/php8.3/php8.3_8.3.4-1%2bubuntu22.04.1%2bdeb.sury.org%2b1_all.deb) Temporary failure resolving '[ppa.launchpadcontent.net](http://ppa.launchpadcontent.net)'  
> E: Failed to fetch [https://packages.openziti.org/zitipax-openziti-deb-stable/pool/ziti-edge-tunnel/jammy/amd64/ziti-edge-tunnel-0.22.25-1.deb](https://packages.openziti.org/zitipax-openziti-deb-stable/pool/ziti-edge-tunnel/jammy/amd64/ziti-edge-tunnel-0.22.25-1.deb) Temporary failure resolving '[packages.openziti.org](http://packages.openziti.org)'  
> E: Unable to fetch some archives, maybe run apt-get update or try with --fix-missing?

I tried running `sudo apt-get update` before running `sudo apt upgrade` and have tried `sudo apt update --fix-missing` but with no success.

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 6, 2024, 4:36pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/10 "2024-04-06T16:36:35Z")

</div>

Yeah, I don't think that apt-related output isn't relevant to this thread and I'm not going to be able to address any of that unfortunately. From your message I saw:

> unable to connect to the server: dial tcp: lookup [serveroek.mywire.org](http://serveroek.mywire.org)

That generally indicates a problem somewhere else, like the server isn't running, or DNS isn't working etc.

If you run `ziti edge login your.server:port` you should be prompted for a username and password. If you're getting a connection error, you need to diagnose that first. I personally rely on openssl s\_client -connect to verify the server is online at that point.

Are you still having troubles with ziti edge login telling you `Connection error: Get https://serveroek.mywire.org:8441/.well-known/est/cacerts: dial tcp: lookup serveroek.mywire.org: i/o timeout`

I can't connect to it either. Is the firewall blocking connections?

---

<div class="post-metadata">

**Author:** ![rhansen](https://avatars.discourse-cdn.com/v4/letter/r/22d042/32.png) [@rhansen](https://openziti.discourse.group/u/rhansen)\
**Post date:** [April 11, 2024, 10:22am UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/11 "2024-04-11T10:22:19Z")

</div>

It was not the firewall. Somehow the .yaml file did not contain the default gateway and the server could not connect because of that. That works for now though thanks for the feedback!

I am currently trying to install the ZAC console and am stuck at step 5 of step 2 for cloning from Github where one sohuld run the following:

```auto
ln -s "${ZITI_PKI}/${ZITI_CTRL_EDGE_NAME}-intermediate/certs/${ZITI_CTRL_EDGE_ADVERTISED_ADDRESS}-server.chain.pem" "${ZITI_HOME}/ziti-console/server.chain.pem"
ln -s "${ZITI_PKI}/${ZITI_CTRL_EDGE_NAME}-intermediate/keys/${ZITI_CTRL_EDGE_ADVERTISED_ADDRESS}-server.key" "${ZITI_HOME}/ziti-console/server.key"

```

I am not entirely sure though, where to find those variables using the CLI such as the ${ZITI\_CTRL\_EDGE\_NAME} or the ${ZITI\_CTRL\_EDGE\_ADVERTISED\_ADDRESS}?

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 11, 2024, 12:13pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/12 "2024-04-11T12:13:56Z")

</div>

As to those environment variables.... They assume that you ran the expressInstall quickstart in that same shell (which I'd expect is unlikely at this point) or that you have sourced the environment. Currently, the express install leaves behind an .env file you can use to put those variables back into your shell. You can run: `source $HOME/.ziti/quickstart/$(hostname)/$(hostname).env` and those environment variables will be available to you.

> [@rhansen](#):
>
> the .yaml file did not contain the default gateway

Do you mean the controller's yaml file had an incorrectly specified address in it? Perhaps just the 'hostname' was shown? If that's the case, you definitely want to check your PKI was created properly, it's a vital step of the expressInstall script. It's possible you haven't gotten far enough to check that yet, but **it's really important** otherwise none of the connectivity will work.

Once you source that .env file, try connecting to it using this command and openssl:

```auto
openssl s_client \
	-connect $ZITI_CTRL_EDGE_ADVERTISED_ADDRESS:$ZITI_CTRL_EDGE_ADVERTISED_PORT </dev/null | \
	openssl x509 -text

```

After you run that, scroll back a page and find this block:

```auto
            X509v3 Subject Alternative Name:
                DNS:ec2-3-18-113-172.us-east-2.compute.amazonaws.com, DNS:ip-172-31-47-200, DNS:localhost, IP Address:127.0.0.1, IP Address:3.18.113.172

```

MAKE SURE you see your expected address in the DNS fields (or if IP only, the IP field). Notice mine shows my DNS entry from AWS: `ec2-3-18-113-172.us-east-2.compute.amazonaws.com`

hth

---

<div class="post-metadata">

**Author:** ![Alex](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@Alex](https://openziti.discourse.group/u/Alex)\
**Post date:** [April 5, 2026, 9:07pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/13 "2026-04-05T21:07:39Z")

</div>

Hi,

I am new to OpenZiti. I started with [Local - Docker Compose](https://netfoundry.io/docs/openziti/learn/quickstarts/network/local-docker-compose) and it works as explained. However, “Your first Service” doesn’t work. I have checked other posts, set http\_server as web.test.blue, port to 8000, and @${http\_server\_id} as ziti-private-blue. I also added ziti-edge-controller  
and ziti-edge-router to my hosts’ /etc/hosts file (both as 127.0.0.1).

My host machine has ubuntu, I have installed ziti-edge-tunnel, and the enroll command seems to work (http-client.json is created). However, when executing ziti run, I get this error message:

(261292)[1.861] ERROR ziti-sdk:ziti\_ctrl.c:504 ctrl\_body\_cb() ctrl[[https://ziti-edge-controller:1280](https://ziti-edge-controller:1280)] API request[/current-api-session] failed code[UNAUTHORIZED] message[The request could not be completed. The session is not authorized or the credentials are invalid]  
(261292)[1.861] ERROR ziti-sdk:ziti.c:2409 api\_session\_cb() ztx[1] failed to get api session: UNAUTHORIZED/The request could not be completed. The session is not authorized or the credentials are invalid

I am sure I missing something, but I have repeated the steps with no success. I would appreciate some help. Thanks.

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 7, 2026, 12:09pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/14 "2026-04-07T12:09:50Z")

</div>

Hi @Alex, welcome to the community and to OpenZiti!

I just went through all the steps locally. I've copied my exact steps I used below. **I am going to guess that you didn't remember to `down -v` between attempts and that you are using a token that is no longer valid**... I think that's the problem you're having?

I would recommend you clean up and start the overlay back up. My steps contain that step but you'll have to adjust based on how you started docker... I also took all the prose out of the sample. The other gotcha when using docker I took care of as well below (port 80 vs 8000, documented in the steps) Hope this helps?

## Terminal 1:

copy/paste:

> docker compose --project-name docker down -v; ZITI\_PWD=admin docker compose --project-name docker up

## Terminal 2:

```auto
ziti edge login localhost:1280 -u admin -p admin -y
ziti edge create identity http-client -a 'http-clients' -o http.client.jwt 
ziti edge create identity http-server -o http.server.jwt
ziti edge create config http.intercept.v1 intercept.v1 '{"protocols":["tcp"],"addresses":["http.ziti"], "portRanges":[{"low":80, "high":80}]}'
    
http_server=web.test.blue
http_server_port=8000
ziti edge create config http.host.v1 host.v1 '{"protocol":"tcp", "address":"'"${http_server}"'", "port":'$http_server_port'}'

ziti edge create service http.svc --configs http.intercept.v1,http.host.v1
ziti edge create service-policy http.policy.dial Dial --service-roles "@http.svc" --identity-roles '#http-clients'

http_server_id=$(ziti edge list ers 'name="ziti-private-blue"' -j | jq -r .data[].id)
ziti edge create service-policy http.policy.bind Bind --service-roles '@http.svc' --identity-roles "@${http_server_id}"

ziti edge create edge-router-policy "all-routers-all-identities" --edge-router-roles '#all' --identity-roles '#all'

ziti-edge-tunnel enroll --jwt ./http.client.jwt --identity ./http.client.json

# run ziti-edge-tunnel for the client
sudo ./ziti-edge-tunnel run -i ./http.client.json

#12. Access the HTTP server securely over the OpenZiti zero trust overlay
curl http.ziti
<pre>
Hello World

                        ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
                        :::::::::::::::::::,::$77777777777777,:,::::::::::::::::::::
                        ::::::::::::::::::77777777777777777777777~,:::::::::::::::::
                        :::::::::::::::77777777777777II7777777777777,:::::::::::::::
                        ::::::::::::$777777777777777I.:7777777777777777,::::::::::::
                        ::::::::::77777777777777777I...I7777777777777777I:::::::::::
                        :::::::::77777777777777777I....?777777777777777777::::::::::
                        :::::::$77777777777777777I......77777777777777777777::::::::
                        ::::::777777777777777777I.......I77777777777777777777,::::::
                        :::::777777777777777777I....?...?777777777777777777777::::::
                        :::,777777777777777777I....I7?...777777777777777777777$:::::
                        :::777777777777777777I....I77I...I777777777777777777777$::::
                        :::77777777777777777I....I7777...?7777777777777777777777::::
                        ::77777777777777777I....I77777?..,77777777777777777777777:::
                        ::7777777777777777I....I777777I...I77777777777777$7$$$$7$,::
                        :$777777777777777I....I77777777...?7777777777777$$77777777::
                        :777777777777777I ...I777II7777?...I.I7777777$777777777777::
                        :77777777777777I....I777I..7777I.......?I777$$$$$77$$$$7$$::
                        :7777777777777I....?I77I...I7777..........I777777$$$$$7$$$,:
                        :77777777777777?.. .??. ?7777? ..??. .?7$7$$$7$$$$$7::
                        ,7777777777777777I..........I$77I...I777?....77777$7$$$$$$,,
                        :7777777777777777777?.......I7$$7..I777I....7$$$$$$$$$$$$$::
                        :777777777777777777777I.I=..?77777777$7....77$$$$$$$$7$$$$::
                        :777777777777777777777777I...I$7777777....77$$$$$$$$$$$$$$::
                        ::77777777777777$7$7$$$$$I...?7$$7$77....7$$$$$$$$$$$$$$$:::
                        ::777777777777777777$$$777+..~77$$7I....77$$$$$$$$$$$$$$$:::
                        :::77777777777777777777$$7I...7$$$I....7$7$$$$$$$$$$$$$$::::
                        :::Z77777777$7777777777$77I...?$77....I$$$$$$$$$$$$$$$$$::::
                        ::::77777$$$$$7777$$$$$$$$7:..+77....I$$$$$$$$$$$$$$$$$:::::
                        :::::77777$777$$$$777$$$$77I...I....I$$$$$$$$$$$$$$$$$::::::
                        ::::::$7777777$7777$$$7$$$$I...... I$$$$$$$$$$$$$$$$7:::::::
                        :::::::?$$$$$$$$$$$$$$$$$$$7=.....I$$$$$$$$$$$$$$$$=::::::::
                        :::::::::7$$$$$7$$$$$$$$$$$$?....77$$$$$$$$$$$$$$$::::::::::
                        ::::::::::,7$$7$$$$$$$$$$$$$7...I$$$$$$$$$$$$$$$::::::::::::
                        ::::::::::::~$$$$$$$$$$$$$$$7?.I$$$$$$$$$$$$$$::::::::::::::
                        :::::::::::::::$$$$$$$$$$$$$$77$$$$$$$$$$$$$::::::::::::::::
                        ::::::::::::::::::7$$$$$$$$$$$$$$$$$$$$$$:::::::::::::::::::
                        :::::::::::::::::::::::$$$$$$$$$$$$$::::::::::::::::::::::::
                        ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

</pre>

```

---

<div class="post-metadata">

**Author:** ![Alex](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@Alex](https://openziti.discourse.group/u/Alex)\
**Post date:** [April 7, 2026, 2:57pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/15 "2026-04-07T14:57:35Z")

</div>

Thank you very much!!! It works now!

I guess you are right and after several attemps it seems that some docker/networks were still active.

However, in addition to your code, I have also included ziti-private-blue and ziti-private-red in my hosts’ /etc/hosts file, using the IPs assigned by docker. Otherwise, when running the last command in my host “sudo ziti-edge-tunnel run -i ./http.client.json” I got these messages:  
(1145045)[57.482] ERROR ziti-sdk:channel.c:980 on\_tls\_connect() ch[1] failed to connect to ER[ziti-private-blue] [-3008/unknown node or service]  
(1145045)[57.482] INFO ziti-sdk:channel.c:837 reconnect\_channel() ch[1] reconnecting in 3554ms (attempt = 1)  
(1145045)[63.112] ERROR ziti-sdk:channel.c:980 on\_tls\_connect() ch[2] failed to connect to ER[ziti-private-red] [-3008/unknown node or service]  
(1145045)[63.112] INFO ziti-sdk:channel.c:837 reconnect\_channel() ch[2] reconnecting in 19496ms (attempt = 2)

If I have understood the network overlay correctly, my host machine should be “taking to” the controller and the edge-router, why should I need to provide the IP address of ziti-private-blue and ziti-private-red?

Thanks again for your help!!

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 7, 2026, 2:59pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/16 "2026-04-07T14:59:23Z")

</div>

> [@Alex](#):
>
> I have also included ziti-private-blue and ziti-private-red in my hosts’ /etc/hosts file, using the IPs assigned by docker.

So, you probably don't WANT to do that fwiw. You want those routers to emulate being in some other network so your client shouldn't be able to reach them... If that doesn't make sense just yet, I think after you use OpenZiti for a while it'll start to click. 🙂

I'm glad you got it working!

---

<div class="post-metadata">

**Author:** ![Alex](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@Alex](https://openziti.discourse.group/u/Alex)\
**Post date:** [April 7, 2026, 3:12pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/17 "2026-04-07T15:12:44Z")

</div>

Yes, I agree. So, do you know why I get this error if not included in /etc/hosts?

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 7, 2026, 4:06pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/18 "2026-04-07T16:06:28Z")

</div>

Sure. You're seeing that due to the `all-routers-all-identities` edge router policy. This policy is setup as shown:

```auto
ziti edge list erps
╭────────────────────────┬───────────────────────────────┬────────────────────────┬────────────────────────╮
│ ID │ NAME │ EDGE ROUTER ROLES │ IDENTITY ROLES │
├────────────────────────┼───────────────────────────────┼────────────────────────┼────────────────────────┤
│ 1itbJxZ.b3 │ edge-router-1itbJxZ.b3-system │ @ziti-private-blue │ @ziti-private-blue │
│ 37ltgXiINffISYGPS5Ic05 │ all-endpoints-public-routers │ #public │ #all │
│ 3SrCBVpcAw3q6Vgb1IZG6m │ all-routers-all-identities │ #all │ #all │
│ JnCbJxO.-3 │ edge-router-JnCbJxO.-3-system │ @ziti-edge-router-wss │ @ziti-edge-router-wss │
│ ZoA-YxZX-3 │ edge-router-ZoA-YxZX-3-system │ @ziti-private-red │ @ziti-private-red │
│ nNDbJxO.b3 │ edge-router-nNDbJxO.b3-system │ @ziti-fabric-router-br │ @ziti-fabric-router-br │
│ xJV-JxO.-3 │ edge-router-xJV-JxO.-3-system │ @ziti-edge-router │ @ziti-edge-router │
╰────────────────────────┴───────────────────────────────┴────────────────────────┴────────────────────────╯

```

It appears that at some point in the past, a docker-based update came through that adds the `all-routers-all-identities` policy granting `#all` identities access to `#all` routers.

Delete that policy and you won't see the error:

```auto
ziti edge delete erp all-routers-all-identities 
delete of edge-router-policy with id 3SrCBVpcAw3q6Vgb1IZG6m: OK

```

**however** you don't need to delete the policy if you don't want to . It won't affect anything other than adding a couple of errors in the log. But that's how you clean it up.

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 7, 2026, 4:19pm UTC](https://openziti.discourse.group/t/your-first-service-zero-trust-host-access/2202/19 "2026-04-07T16:19:06Z")

</div>

Oh -- I see that command is actually from the instructions of the first service!

```auto
ziti edge create edge-router-policy "all-routers-all-identities" --edge-router-roles '#all' --identity-roles '#all'

```

Just don't run that and you'll be fine. It needs a similar note that it's not necessary when using the existing compose quickstart
