# Ziti edge enrol identity not inserting CA bundle

**URL:** <https://openziti.discourse.group/t/ziti-edge-enrol-identity-not-inserting-ca-bundle/814>\
**Category:** Ziti Overlay\
**Created:** [October 16, 2022, 8:04am UTC](https://openziti.discourse.group/t/ziti-edge-enrol-identity-not-inserting-ca-bundle/814 "2022-10-16T08:04:59Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [November 1, 2022, 7:33am UTC](https://openziti.discourse.group/t/ziti-edge-enrol-identity-not-inserting-ca-bundle/814/4 "2022-11-01T07:33:49Z")

</div>

Sorry for the delayed response.. I got side tracked

After doing some digging... I believe the cause is somehow related to the following commands.. which is what I used to rebuild the server certificate.

```auto

"${ZITI_BIN_DIR}/ziti" pki create server \
  --pki-root="${ZITI_PKI_OS_SPECIFIC}" \
  --ca-name ${ZITI_CONTROLLER_INTERMEDIATE_NAME} \
  --key-file "${ZITI_CONTROLLER_HOSTNAME}-server" \
  --server-file "${new_ctrl_cert_name}-server" \
  --dns "${pki_allow_list_dns}" --ip "${pki_allow_list_ip}" \
  --server-name "${new_ctrl_cert_name} server certificate"
 

# generated a new server cert for the edge controller by running:

"${ZITI_BIN_DIR}/ziti" pki create server \
  --pki-root="${ZITI_PKI_OS_SPECIFIC}" \
  --ca-name ${ZITI_EDGE_CONTROLLER_INTERMEDIATE_NAME} \
  --key-file "${ZITI_EDGE_CONTROLLER_HOSTNAME}-server" \
  --server-file "${new_edge_ctrl_cert_name}-server" \
  --dns "${pki_allow_list_dns}" --ip "${pki_allow_list_ip}" \
  --server-name "${new_edge_ctrl_cert_name} server certificate"

```

This goes back a bit to the following

> [@Creating certs for a remote private router](https://openziti.discourse.group/t/creating-certs-for-a-remote-private-router/694/13):
>
> Ok. I got to the bottom of the issue. It comes down to a few things but mainly it’s because the command I provided to @markamind on his other post was ever so slightly incorrect and that caused a lot of confusion! frowning I’ll update that post after this one. @arslane gave me access to his OCI instance saving me a bit of time making an OCI machine. I wanted to use it anyway, to save you the time and so you’ll have your own instance that’s configured correctly as reference. Here’s what I ne…

The issue I believe relates to the edge router.. as when I look at it now... I only updated the controller yaml file..

I am going to redo this.. and will keep you posted

---

_[View the full topic](https://openziti.discourse.group/t/ziti-edge-enrol-identity-not-inserting-ca-bundle/814)._
