# Re-registering rancher-agent with HTTPS?

**URL:** <https://forums.suse.com/t/re-registering-rancher-agent-with-https/4825>\
**Category:** Rancher 1.x\
**Created:** [December 7, 2016, 2:45am UTC](https://forums.suse.com/t/re-registering-rancher-agent-with-https/4825 "2016-12-07T02:45:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stefan\_Lasiewski](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/stefan_lasiewski/32/1801_2.png) [@Stefan\_Lasiewski](https://forums.suse.com/u/Stefan_Lasiewski)\
**Post date:** [December 7, 2016, 2:45am UTC](https://forums.suse.com/t/re-registering-rancher-agent-with-https/4825/1 "2016-12-07T02:45:52Z")

</div>

Hello all,

I’m upgrading our Rancher Server to use TLS/SSL, and will eventually have a HA Proxy with SSL Termination.

Our old command to register custom hosts used http:

```
docker run -d --privileged -v /var/run/docker.sock:/var/run/docker.sock -v /var/lib/rancher:/var/lib/rancher rancher/agent:v1.1.0 http://node1.example.org:8080/v1/scripts/abcdef:12345

```

I’m trying to convert this to use TLS/SSL and https://

```
docker run -d --privileged -v /var/run/docker.sock:/var/run/docker.sock -v /var/lib/rancher:/var/lib/rancher rancher/agent:v1.1.0 https://node1.example.org/v1/scripts/abcdef:12345

```

But I need to mount the TLS certificates, and possibly the CA cert. How can I do this from the agent?

Without the Certs, the Rancher Agent fails to connect to the https url. The logs say:

```
INFO: Running Agent Registration Process, CATTLE_URL=https://node1.example.org/v1
INFO: Attempting to connect to: https://node1.example.org/v1
ERROR: https://node1.example.org/v1 is not accessible
ERROR: https://node1.example.org/v1 is not accessible
ERROR: https://node1.example.org/v1 is not accessible
```

---

<div class="post-metadata">

**Author:** ![ltutar](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@ltutar](https://forums.suse.com/u/ltutar)\
**Post date:** [July 12, 2017, 8:36am UTC](https://forums.suse.com/t/re-registering-rancher-agent-with-https/4825/2 "2017-07-12T08:36:32Z")

</div>

Any progress on this issue? I have the same problem.

---

<div class="post-metadata">

**Author:** ![cjellick](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/cjellick/32/2876_2.png) [@cjellick](https://forums.suse.com/u/cjellick)\
**Post date:** [July 12, 2017, 2:00pm UTC](https://forums.suse.com/t/re-registering-rancher-agent-with-https/4825/3 "2017-07-12T14:00:09Z")

</div>

Is this what you’re looking for?  
[http://rancher.com/docs/rancher/v1.6/en/installing-rancher/installing-server/basic-ssl-config/#using-self-signed-certs-beta](http://rancher.com/docs/rancher/v1.6/en/installing-rancher/installing-server/basic-ssl-config/#using-self-signed-certs-beta)

---

<div class="post-metadata">

**Author:** ![Stefan\_Lasiewski](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/stefan_lasiewski/32/1801_2.png) [@Stefan\_Lasiewski](https://forums.suse.com/u/Stefan_Lasiewski)\
**Post date:** [July 13, 2017, 12:39am UTC](https://forums.suse.com/t/re-registering-rancher-agent-with-https/4825/4 "2017-07-13T00:39:44Z")

</div>

Adding my CA Cert to /var/lib/rancher/etc/ssl/ca.crt did work. In fact, I used this just last week.

The documentation says “Self signed certificates”, and these are actually not self-signed certs but are certs from GoDaddy, and should be included in the CA certificate store on most major OSes.

In December, I had actually loaded the CA into the container through a different path under /etc/ssl and it worked. However, I forget the details. ☹

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [July 13, 2017, 4:17am UTC](https://forums.suse.com/t/re-registering-rancher-agent-with-https/4825/5 "2017-07-13T04:17:14Z")

</div>

GoDaddy’s root, but not intermediates (GD or sf\_bundle…), are in typical distro ca-certificates. Needing to put it in the agent suggests your ssl termination device is not offering it up like it should be.
