# Websocket: bad handshake

**URL:** <https://forums.suse.com/t/websocket-bad-handshake/14330>\
**Category:** SUSE Rancher Prime\
**Created:** [May 20, 2019, 3:32pm UTC](https://forums.suse.com/t/websocket-bad-handshake/14330 "2019-05-20T15:32:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Madic](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/madic/32/5222_2.png) [@Madic](https://forums.suse.com/u/Madic)\
**Post date:** [May 20, 2019, 3:32pm UTC](https://forums.suse.com/t/websocket-bad-handshake/14330/1 "2019-05-20T15:32:04Z")

</div>

When I try to register a rancher-agent v2.2.3 against a rancher-server v2.2.3 the rancher-agent can’t register and gives the following error:

> time=“2019-05-20T15:19:00Z” level=info msg=“Connecting to proxy” url=“wss://rancher._._/v3/connect/register”  
> time=“2019-05-20T15:19:00Z” level=error msg=“Failed to connect to proxy” error=“websocket: bad handshake”  
> time=“2019-05-20T15:19:00Z” level=error msg=“Failed to connect to proxy” error=“websocket: bad handshake”

Have tried that with rancher-server behind traefik as reverse proxy and rancher-server with exposed ports from docker. Certificate is a valid lets encrypt wildcard certificate.  
Any idea how I can debug that?

---

<div class="post-metadata">

**Author:** ![Madic](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/madic/32/5222_2.png) [@Madic](https://forums.suse.com/u/Madic)\
**Post date:** [May 20, 2019, 8:16pm UTC](https://forums.suse.com/t/websocket-bad-handshake/14330/2 "2019-05-20T20:16:40Z")

</div>

My docker-compose file:

```
version: '3.3'

services:

rancher-server:
  hostname: rancher
  domainname: example.tld
  container_name: rancher-server
  restart: always
  ports:
    - "192.168.1.42:80:80"
    - "192.168.1.42:443:443"
  image: rancher/rancher:latest
  command:
    - --no-cacerts
    - --log-format=simple
  volumes:
    - /vol_raidz1/docker/persistend/rancher:/var/lib/rancher:rw
    - /vol_raidz1/docker/persistend/traefik/certs/example.tld.key:/etc/rancher/ssl/key.pem:ro
    - /vol_raidz1/docker/persistend/traefik/certs/example.tld.crt:/etc/rancher/ssl/cert.pem:ro
  labels:
    - "traefik.enable=true"
    - "traefik.backend=rancher"
    - "traefik.port=443"
    - "traefik.frontend.rule=Host:rancher.example.tld"
    - "traefik.passHostHeader=true"
    - "traefik.protocol=https"
    - "com.centurylinklabs.watchtower.enable=true"
  networks:
    traefik_proxy:
      aliases:
        - rancher
      ipv4_address: 172.19.0.34

networks:
  traefik_proxy:
    external: true

```

With this method I can point the FQDN rancher.example.tld either to 192.168.1.42 or the traefik ip address. It’s for testing purposes. I would prefer to only expose traefik

---

<div class="post-metadata">

**Author:** ![firebert](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/firebert/32/5446_2.png) [@firebert](https://forums.suse.com/u/firebert)\
**Post date:** [August 2, 2019, 12:22pm UTC](https://forums.suse.com/t/websocket-bad-handshake/14330/3 "2019-08-02T12:22:37Z")

</div>

Did you have any luck with this configuration? I’m having a similar issue. I have Rancher behind a traefik instance, configured per the [docs](https://rancher.com/docs/rancher/v2.x/en/installation/ha/rke-add-on/layer-7-lb/), but logs are filled with `Error dialing \"<rancher_url>\": websocket: bad handshake with resp: 200 200 OK"`. I can access the GUI just fine through the same traefik instance, including viewing logs.

---

<div class="post-metadata">

**Author:** ![Madic](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/madic/32/5222_2.png) [@Madic](https://forums.suse.com/u/Madic)\
**Post date:** [August 2, 2019, 8:09pm UTC](https://forums.suse.com/t/websocket-bad-handshake/14330/4 "2019-08-02T20:09:57Z")

</div>

The problem “magically” disappeared at some point. Running rancher(-agent) 2.2.6 at the moment. But got another problem:

> [@Let's encrypt certificate on rancher-server: unable to get local issuer certificate](http://forums.suse.com/t/lets-encrypt-certificate-on-rancher-server-unable-to-get-local-issuer-certificate/14865):
>
> Hello, I try to register a rancher-agent, running on RancherOS, against a rancher-server with a certificate from let’s encrypt but the agent fails with the error: “Failed to connect to proxy” error=“x509: certificate has expired or is not yet valid” The problem occurs behind traefik as reverse proxy and beeing directly exposed. My docker-compose file for rancher-server: version: '3.3' services: rancher-server: hostname: rancher domainname: example.tld container\_name: rancher-serve…

I do not have a working environment since…forever because of these problems.  
And nobody is responding with some help… ☹

---

<div class="post-metadata">

**Author:** ![wei.dai](https://avatars.discourse-cdn.com/v4/letter/w/47e85d/32.png) [@wei.dai](https://forums.suse.com/u/wei.dai)\
**Post date:** [October 26, 2021, 3:43am UTC](https://forums.suse.com/t/websocket-bad-handshake/14330/5 "2021-10-26T03:43:35Z")

</div>

这个问题现在有解决方法吗，我集群中的cattle-cluster-agent目前在报这个错误，pod一直起不来，情况紧急

---

<div class="post-metadata">

**Author:** ![wcoateRR](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/wcoaterr/32/8144_2.png) [@wcoateRR](https://forums.suse.com/u/wcoateRR)\
**Post date:** [October 26, 2021, 2:02pm UTC](https://forums.suse.com/t/websocket-bad-handshake/14330/6 "2021-10-26T14:02:35Z")

</div>

The way I finally got some help on another issue was when I found something new/odd happening that gave a different symptom I tossed the question over in their Slack and eventually I hit on an odd enough error message and found it.

Granted, I found the solution to one error that’s going to bite me later, so I’ll still be trying that cycle at least one more time to get things fully working.
