# Certificate problems with keycloak

**URL:** <https://forums.suse.com/t/certificate-problems-with-keycloak/36071>\
**Category:** SUSE Rancher Prime\
**Created:** [November 3, 2021, 10:42am UTC](https://forums.suse.com/t/certificate-problems-with-keycloak/36071 "2021-11-03T10:42:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![krickler](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/krickler/32/8221_2.png) [@krickler](https://forums.suse.com/u/krickler)\
**Post date:** [November 3, 2021, 10:42am UTC](https://forums.suse.com/t/certificate-problems-with-keycloak/36071/1 "2021-11-03T10:42:12Z")

</div>

Hello,  
i’m currently testing out a single node Rancher installation in Docker, and when trying to setup Keycloak as an OIDC Provider i get this error message:

` [generic oidc]: server error while authenticating: Get "https://xxx.xxx.xxx/auth/realms/xxx/.well-known/openid-configuration": x509: certificate signed by unknown authority`

The Keycloak server definitely has a valid certificate, so i think it might be an issue with the CA-Certs inside the rancher container, so the things i tried are:

- Setting SSL\_CERT\_DIR to /etc/ssl/certs
- Mounting hosts /etc/ssl/certs to the container
- testing the certificate using `openssl s_client -connect domain.tld:443`, returns Verify return code: 0 (ok)

I could not get it to work, any idea what could cause this?

---

<div class="post-metadata">

**Author:** ![rocky](https://avatars.discourse-cdn.com/v4/letter/r/278dde/32.png) [@rocky](https://forums.suse.com/u/rocky)\
**Post date:** [March 16, 2022, 10:33pm UTC](https://forums.suse.com/t/certificate-problems-with-keycloak/36071/2 "2022-03-16T22:33:13Z")

</div>

I am also getting same issues like above, Does any one have solution for this?

Thanks  
Ragg

---

<div class="post-metadata">

**Author:** ![scenox](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/scenox/32/7069_2.png) [@scenox](https://forums.suse.com/u/scenox)\
**Post date:** [March 17, 2022, 5:42pm UTC](https://forums.suse.com/t/certificate-problems-with-keycloak/36071/3 "2022-03-17T17:42:50Z")

</div>

Did you check if the ca and root certs exist in the truststore? You can add your certs and then mount the extended truststore.

---

<div class="post-metadata">

**Author:** ![Brian\_turner](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/brian_turner/32/6582_2.png) [@Brian\_turner](https://forums.suse.com/u/Brian_turner)\
**Post date:** [April 25, 2022, 4:36pm UTC](https://forums.suse.com/t/certificate-problems-with-keycloak/36071/4 "2022-04-25T16:36:44Z")

</div>

Do you mean the truststore in keycloak? I am having the same issue, and this would make sense.

---

<div class="post-metadata">

**Author:** ![groucho64738](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/groucho64738/32/8989_2.png) [@groucho64738](https://forums.suse.com/u/groucho64738)\
**Post date:** [May 13, 2022, 4:24pm UTC](https://forums.suse.com/t/certificate-problems-with-keycloak/36071/5 "2022-05-13T16:24:23Z")

</div>

I’m having the same issue as well and can’t figure out where to put the certs. I tried creating an additional trust in the rancher config according to the document here: [Rancher Docs: Rancher Helm Chart Options](https://rancher.com/docs/rancher/v2.6/en/installation/install-rancher-on-k8s/chart-options/#additional-trusted-cas)

but that didn’t work either. I saw a connection to the keycloak webserver from the rancher host. I don’t think there’s anything to be done with keycloak in this circumstance, it seems to totally be an issue with Rancher not accepting the certificate.

Did anyone get this working?

---

<div class="post-metadata">

**Author:** ![groucho64738](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/groucho64738/32/8989_2.png) [@groucho64738](https://forums.suse.com/u/groucho64738)\
**Post date:** [May 16, 2022, 10:49am UTC](https://forums.suse.com/t/certificate-problems-with-keycloak/36071/6 "2022-05-16T10:49:52Z")

</div>

I may have spoken a little soon, but I think I might have it working now (if this helps anyone). Instead of just having a cert for the Keycloak server, I created a cert chain with the server cert, intermediate, and root certs all cat’ed together. Rancher then did not seem to have any issues connecting at that point (even though the same root/intermediate cert were configured with Rancher originally)
