goldwarden icon indicating copy to clipboard operation
goldwarden copied to clipboard

Docs about self-signed certificated

Open ai opened this issue 1 year ago • 10 comments

I have Valutwarden server on passwords.local with self-signed certificate.

I add this certificate to my Fedora 40 system by:

sudo cp sitniks.crt /etc/pki/ca-trust/source/anchors/sitniks.pem
sudo update-ca-trust

curl works:

$ curl https://passwords.local
<!doctype html><html class="theme_light"><head><meta charset="utf-8"/><meta name="viewport" content="width=1010"/><meta name="theme-color" content="#175DDC"/><title page-title>Vaultwarden Web</title>…

But when I try to login in GoldWarden I got Traffic looks unusual after I enter password:

Captura desde 2024-05-09 18-51-04

I assume that GoldWarden doesn’t see my certificate:

  1. What is the right way to add it?
  2. Maybe we should add note to README.md or wiki

ai avatar May 09 '24 16:05 ai

Unusual traffic error is very weird and should only happen on the official instance, not on local vaultwarden instances. Need to figure out what's going on.

quexten avatar May 10 '24 09:05 quexten

Can I collect some debug information? I run Gold Warden in terminal, but output was small without useful any detail.

ai avatar May 10 '24 09:05 ai

This is happening to me too

vinaysb avatar May 10 '24 22:05 vinaysb

How I can collect more debug data? Maybe there is some verbose mode?

ai avatar May 10 '24 22:05 ai

I also tried to set client ID and client secret (from API key), but got the same Unusual Traffic error

ai avatar May 10 '24 23:05 ai

Your self hosted server was never being used, due to a bug in the GUI code, that part should be fixed here: #213 Not sure yet about whether self-signed certs are accepted or not, you can either try the latest flatpak from the CI pipeline or wait for next release.

quexten avatar May 11 '24 01:05 quexten

0.3.2 is out now, should be on FlatHub within a few hours. Please try again there.

quexten avatar May 11 '24 02:05 quexten

Thanks! But now I get Failed to set serverThe server you entered is invalid.

I use https://passwords.local.

This URL works in Firefox and with curl.

ai avatar May 11 '24 10:05 ai

Having similar problem ,when i try to login with cli i am getting tls: failed to verify certificate: x509: certificate signed by unknown authority . I have CA in my /etc/ssl/certs and it works without problems with browser/curl/bitwarden app.

OS is Fedora 40. Have tried both (flatpak and rpm).

K1kc4 avatar May 28 '24 13:05 K1kc4