# Pydia Cells docker + traefik : bad certificate

**URL:** <https://forum.pydio.com/t/pydia-cells-docker-traefik-bad-certificate/4704>\
**Category:** Pydio Cells\
**Created:** [September 25, 2022, 2:15pm UTC](https://forum.pydio.com/t/pydia-cells-docker-traefik-bad-certificate/4704 "2022-09-25T14:15:50Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![MathieuMoalic](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/mathieumoalic/32/1877_2.png) [@MathieuMoalic](https://forum.pydio.com/u/MathieuMoalic)\
**Post date:** [September 25, 2022, 2:15pm UTC](https://forum.pydio.com/t/pydia-cells-docker-traefik-bad-certificate/4704/1 "2022-09-25T14:15:50Z")

</div>

The exact error is

```auto
2022-09-25T13:52:38.829Z DEBUG http: TLS handshake error from 172.28.0.2:47478: remote error: tls: bad certificate

```

The docker-compose.yml :

```yaml
version: "3.7"
services:
  mysql:
    image: mysql:8
    container_name: mysql
    restart: unless-stopped
    volumes:
      - ./mysql_data:/var/lib/mysql
    environment:
      - MYSQL_ROOT_PASSWORD=${MYSQL_ROOT_PASSWORD}
      - MYSQL_DATABASE=cells
      - MYSQL_USER=${MYSQL_USER_LOGIN}
      - MYSQL_PASSWORD=${MYSQL_USER_PWD}
    command:
      - mysqld
      - --character-set-server=utf8mb4
      - --collation-server=utf8mb4_unicode_ci

  cells:
    image: pydio/cells:latest
    container_name: cells
    restart: unless-stopped
    expose:
      - 443
    volumes:
      - ./cache:/var/cells
      - ./data:/data
      - ./install-conf.yml:/pydio/config/install.yml:ro
    environment:
      - CELLS_INSTALL_YAML=/pydio/config/install.yml
      - CELLS_LOG=debug
      - CELLS_WORKING_DIR=/var/cells
      - CELLS_DATA=/data
      - CELLS_BIND=0.0.0.0:443
      - CELLS_EXTERNAL=https://${FQDN}
      - CELLS_ENABLE_METRICS=false
      - CELLS_ADMIN_PWD=${CELLS_ADMIN_PWD}
      - MYSQL_USER_LOGIN=${MYSQL_USER_LOGIN}
      - MYSQL_USER_PWD=${MYSQL_USER_PWD}
    labels:
      - traefik.enable=true
      - traefik.http.services.cells.loadbalancer.server.scheme=https
      - traefik.http.routers.cells.rule=Host(`${FQDN}`)
      - traefik.http.routers.cells.entrypoints=websecure
      - traefik.http.routers.cells.tls=true
      - traefik.http.routers.cells.tls.certresolver=production
    depends_on:
      - mysql

networks:
  default:
    external: true
    name: proxy

```

pydio cells logs (I replaced my domain name with FQDN):  
[https://pastebin.com/raw/XFV4T4RU](https://pastebin.com/raw/XFV4T4RU)

So when I start up the docker-compose, [https://FQDN](https://FQDN) gives me ‘Internal Server Error’

The logs tell me it’s a certificate issue. I know for a fact that it’s not a problem with the certificate that Treafik uses, I have ~15 other services running just fine with it.  
I don’t really know what to do now.  
Any suggestion on making this certificate work ?

---

<div class="post-metadata">

**Author:** ![bsinou](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/bsinou/32/476_2.png) [@bsinou](https://forum.pydio.com/u/bsinou)\
**Post date:** [September 26, 2022, 2:03pm UTC](https://forum.pydio.com/t/pydia-cells-docker-traefik-bad-certificate/4704/2 "2022-09-26T14:03:14Z")

</div>

Hello and welcome to the forum.

Problem is that the self-signed generated by Cells for the traffic between Traefik and cells is not accepted by Traefik

You have 3 choices:

- you skip validation of the Cells cert in Traefik
- you perform TLS termination in TRaefik and use plain http between Cells and Traefik
- you provide Cells with a cert that is accepted by traefik

---

<div class="post-metadata">

**Author:** ![MathieuMoalic](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/mathieumoalic/32/1877_2.png) [@MathieuMoalic](https://forum.pydio.com/u/MathieuMoalic)\
**Post date:** [September 26, 2022, 8:32pm UTC](https://forum.pydio.com/t/pydia-cells-docker-traefik-bad-certificate/4704/3 "2022-09-26T20:32:51Z")

</div>

so if I understand correctly, this certificate is only used for TLS within the internal network behind traefik?  
I think I could go without it. How could I modify my configuration to fix it ?

---

<div class="post-metadata">

**Author:** ![bsinou](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/bsinou/32/476_2.png) [@bsinou](https://forum.pydio.com/u/bsinou)\
**Post date:** [September 27, 2022, 6:48am UTC](https://forum.pydio.com/t/pydia-cells-docker-traefik-bad-certificate/4704/4 "2022-09-27T06:48:22Z")

</div>

> so if I understand correctly, this certificate is only used for TLS within the internal network behind traefik?

Yes, TLS for the “outside world” is provided by traefik. You only need TLS from you reverse proxy to Cells if you use the Cells Sync Client.

> I think I could go without it. How could I modify my configuration to fix it ?

What about reading the doc 🙂 ?

> **[Running a Cells container behind a Traefik reverse proxy](https://pydio.com/en/docs/kb/deployment/running-cells-container-behind-traefik-reverse-proxy)**
>
> This article shows how to run Pydio Cells container with a Traefik reverse proxy.

let us know if something is not clear enough or outdated.

Happy file sharing

---

<div class="post-metadata">

**Author:** ![MathieuMoalic](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/mathieumoalic/32/1877_2.png) [@MathieuMoalic](https://forum.pydio.com/u/MathieuMoalic)\
**Post date:** [September 27, 2022, 4:52pm UTC](https://forum.pydio.com/t/pydia-cells-docker-traefik-bad-certificate/4704/5 "2022-09-27T16:52:51Z")

</div>

Thank you for your help. I have to tell you that I am well aware of this documentation and you can be sure that I have read several times every single forum thread here about traefik and I have also seen every bit of documentation available.  
Because the docker-compose.yml at that link does not work, I went a step further and found a more recent version of it on [github](https://github.com/pydio/cells/tree/main/tools/docker/compose/behind-traefik). You will find that the github version is slightly different, specifically the part with:

```
  - CELLS_INSTALL_YAML=/pydio/config/install.yml
  - CELLS_BIND=0.0.0.0:443

```

Now, neither docker-compose.yml works for me: I get the same certificate error. I forgot that the internal TLS certificate is necessary for the sync function, in that case I need to make it work.  
It’s hard for me to say if something is out-of-dated but it feels to me like I’m missing a small piece of the puzzle.  
Which steps would you take to provide Cells with a certificate that is accepted by traefik ?  
I didn’t find documentation on it, only about the certificate from traefik to the internet

---

<div class="post-metadata">

**Author:** ![bsinou](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/bsinou/32/476_2.png) [@bsinou](https://forum.pydio.com/u/bsinou)\
**Post date:** [September 30, 2022, 8:14am UTC](https://forum.pydio.com/t/pydia-cells-docker-traefik-bad-certificate/4704/6 "2022-09-30T08:14:25Z")

</div>

Hello

> [@MathieuMoalic](#):
>
> I have to tell you that I am well aware of this documentation and you can be sure that I have read several times every single forum thread here about traefik and I have also seen every bit of documentation available.

And we thank you for this :), it’s good to hear

> [@MathieuMoalic](#):
>
> The logs tell me it’s a certificate issue. I know for a fact that it’s not a problem with the certificate that Treafik uses, I have ~15 other services running just fine with it.

Have you tried to skip verification of **Cells** certificate at the Traefik server level, typically by adding

```auto
 - --serverstransport.insecureskipverify=true

```

in the `commands` section of the **traefik** container ?

This tells Traefik to **not** try to validate the certificate that is exposed by the Cells service (in the config you’ve shown, cells is exposing a self-signed dynamically generated cert).  
This is OK if your services (Traefik, Cells, your other servers communicate via a reasonably secured private network).

---

<div class="post-metadata">

**Author:** ![MathieuMoalic](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/mathieumoalic/32/1877_2.png) [@MathieuMoalic](https://forum.pydio.com/u/MathieuMoalic)\
**Post date:** [September 30, 2022, 10:17am UTC](https://forum.pydio.com/t/pydia-cells-docker-traefik-bad-certificate/4704/7 "2022-09-30T10:17:06Z")

</div>

ah thanks, that works for me. I incorrectly assumed that `insecureskipverify=true` would make the connections insecure but if you tell me that it’s only in the docker bridge network shared by Treafik and Cells then it’s acceptable. I’m usually very reluctant to changing the Traefik config as it could affect my other services.  
Thank you very much for your patience and help.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex032/uploads/pydio/original/2X/6/61f19fa52ec15fd4250db51aea351adba0e831fd.png) [@system](https://forum.pydio.com/u/system)\
**Post date:** [May 16, 2023, 10:30am UTC](https://forum.pydio.com/t/pydia-cells-docker-traefik-bad-certificate/4704/8 "2023-05-16T10:30:07Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
