# Latest

**URL:** https://discuss.pomerium.com/latest.md?page=1

[Latest](https://discuss.pomerium.com/latest.md) · [Categories](https://discuss.pomerium.com/categories.md) · [Tags](https://discuss.pomerium.com/tags.md)

**Page:** 2

---

## [Unable to access Zero console due to certificate failure](https://discuss.pomerium.com/t/unable-to-access-zero-console-due-to-certificate-failure/433)

<div class="topic-metadata">

**Author:** [@singram](https://discuss.pomerium.com/u/singram)\
**Replies:** 5\
**Last updated:** [November 30, 2024, 7:28pm UTC](https://discuss.pomerium.com/t/unable-to-access-zero-console-due-to-certificate-failure/433 "2024-11-30T19:28:40Z")

</div>

I tried to login to Pomerium Zero site by clicking Login on the home page and also just entering https://console.pomerium.app in the browser. I expected to see the login form and be able to login to my account, but recei…

---

## [MY application and IDP can work together, but I want to add them to the pomerium](https://discuss.pomerium.com/t/my-application-and-idp-can-work-together-but-i-want-to-add-them-to-the-pomerium/431)

<div class="topic-metadata">

**Author:** [@oznfc](https://discuss.pomerium.com/u/oznfc)\
**Replies:** 2\
**Last updated:** [November 25, 2024, 1:25pm UTC](https://discuss.pomerium.com/t/my-application-and-idp-can-work-together-but-i-want-to-add-them-to-the-pomerium/431 "2024-11-25T13:25:02Z")

</div>

I want to use my application running at localhost:3000 in pomerium with my IDP. The application and IDP can work together, but I want to add them to the pomerium.I’m using console.pomerium…app with my docker. it’s doc…

---

## [TLS Certificate verification failed](https://discuss.pomerium.com/t/tls-certificate-verification-failed/425)

<div class="topic-metadata">

**Author:** [@Sidhant](https://discuss.pomerium.com/u/Sidhant)\
**Replies:** 2\
**Last updated:** [November 13, 2024, 5:12pm UTC](https://discuss.pomerium.com/t/tls-certificate-verification-failed/425 "2024-11-13T17:12:15Z")

</div>

TLS certificate verification failed when verifying the JWT: x509: certificate is valid for \*, not pomerium How do i resolve this error

---

## [Envoy hangs with ext\_authz\_error](https://discuss.pomerium.com/t/envoy-hangs-with-ext-authz-error/421)

<div class="topic-metadata">

**Author:** [@ms1111](https://discuss.pomerium.com/u/ms1111)\
**Replies:** 6\
**Last updated:** [November 13, 2024, 4:30pm UTC](https://discuss.pomerium.com/t/envoy-hangs-with-ext-authz-error/421 "2024-11-13T16:30:47Z")

</div>

Hi, We’ve been using Pomerium for a couple of years with Azure AD as the IDP. Up until recently we were running Pomerium 0.25.2 on Ubuntu 20.04. We recently updated to 0.27.2, and then replaced the VM with Ubuntu 24.04. …

---

## [Integrating pomerium with keycloak](https://discuss.pomerium.com/t/integrating-pomerium-with-keycloak/418)

<div class="topic-metadata">

**Author:** [@Sidhant](https://discuss.pomerium.com/u/Sidhant)\
**Replies:** 2\
**Last updated:** [October 24, 2024, 10:12am UTC](https://discuss.pomerium.com/t/integrating-pomerium-with-keycloak/418 "2024-10-24T10:12:58Z")

</div>

What happened? I am getting a error 404 trying to access the service , What did you expect to happen? I am using pomerium as a reverse proxy in my minor project to demonstrate Zero Trust Architecture . i want to integra…

---

## [Request for \`--no-browser\` option for \`pomerium-cli\`](https://discuss.pomerium.com/t/request-for-no-browser-option-for-pomerium-cli/416)

<div class="topic-metadata">

**Author:** [@rajivr](https://discuss.pomerium.com/u/rajivr)\
**Replies:** 1\
**Last updated:** [October 7, 2024, 3:41pm UTC](https://discuss.pomerium.com/t/request-for-no-browser-option-for-pomerium-cli/416 "2024-10-07T15:41:45Z")

</div>

What happened? I am new to Pomerium. Firstly, thank you for making Pomerium and making Pomerium Core freely available. Currently when using pomerium-cli, it automatically launches a browser when a connection needs to be…

---

## [Serving with the wrong certificate](https://discuss.pomerium.com/t/serving-with-the-wrong-certificate/415)

<div class="topic-metadata">

**Author:** [@julianbadillo](https://discuss.pomerium.com/u/julianbadillo)\
**Replies:** 2\
**Last updated:** [October 4, 2024, 4:49pm UTC](https://discuss.pomerium.com/t/serving-with-the-wrong-certificate/415 "2024-10-04T16:49:45Z")

</div>

What happened? A handful of our routes got net::ERR\_CERT\_COMMON\_NAME\_INVALID errors from the browsers (not all of them). If I click on the security details on the browser, the wrong certificate is being presented. The c…

---

## [Security is Usability — Examining Cybersecurity Erosion](https://discuss.pomerium.com/t/security-is-usability-examining-cybersecurity-erosion/413)

<div class="topic-metadata">

**Author:** [@CMo](https://discuss.pomerium.com/u/CMo)\
**Replies:** 0\
**Last updated:** [October 2, 2024, 11:27pm UTC](https://discuss.pomerium.com/t/security-is-usability-examining-cybersecurity-erosion/413 "2024-10-02T23:27:46Z")

</div>

It’s often said that humans are the weakest link in security and social engineering is easier than hacking. This is true — but there’s another facet that isn’t discussed enough: when the security design causes friction…

---

## [Announcing Pomerium v0.27.1](https://discuss.pomerium.com/t/announcing-pomerium-v0-27-1/411)

<div class="topic-metadata">

**Author:** [@CMo](https://discuss.pomerium.com/u/CMo)\
**Replies:** 0\
**Last updated:** [October 1, 2024, 10:30pm UTC](https://discuss.pomerium.com/t/announcing-pomerium-v0-27-1/411 "2024-10-01T22:30:34Z")

</div>

Pomerium v0.27.1 is here! This patch fixes a security vulnerability and adds more user information on the user information dashboard. Downloads are immediately available on Github, CloudSmith, and Docker Hub for all sup…

---

## [Announcing Pomerium v0.27](https://discuss.pomerium.com/t/announcing-pomerium-v0-27/410)

<div class="topic-metadata">

**Author:** [@CMo](https://discuss.pomerium.com/u/CMo)\
**Replies:** 0\
**Last updated:** [October 1, 2024, 3:44pm UTC](https://discuss.pomerium.com/t/announcing-pomerium-v0-27/410 "2024-10-01T15:44:43Z")

</div>

Watch our quick Youtube overview of this upgrade! Pomerium v0.27 is here! This update brings new features to Enterprise and Core, in addition to officially announcing Pomerium Zero with its own updates. We’ve also mad…

---

## [Adding an external URL to an existing Pomerium Configuration](https://discuss.pomerium.com/t/adding-an-external-url-to-an-existing-pomerium-configuration/402)

<div class="topic-metadata">

**Author:** [@matswillemsen](https://discuss.pomerium.com/u/matswillemsen)\
**Replies:** 1\
**Last updated:** [September 15, 2024, 10:20pm UTC](https://discuss.pomerium.com/t/adding-an-external-url-to-an-existing-pomerium-configuration/402 "2024-09-15T22:20:50Z")

</div>

We currently are exposing internal domains through an internal endpoint, with also the Pomerium Authenticate URL set to this internal endpoint (authenticate.xxx.internal.ah.nl) Now, we want to expose this authenticate e…

---

## [How to test config before restarting service?](https://discuss.pomerium.com/t/how-to-test-config-before-restarting-service/216)

<div class="topic-metadata">

**Author:** [@torch](https://discuss.pomerium.com/u/torch)\
**Replies:** 14\
**Last updated:** [September 13, 2024, 12:37pm UTC](https://discuss.pomerium.com/t/how-to-test-config-before-restarting-service/216 "2024-09-13T12:37:35Z")

</div>

What happened? I see no (apparent) way to test a changed configuration before restarting pomerium. I tried running a second instance of the service on a different port, to see if it would start without errors. Existing…

---

## [Accessing upstream services that require sso](https://discuss.pomerium.com/t/accessing-upstream-services-that-require-sso/398)

<div class="topic-metadata">

**Author:** [@Arzar](https://discuss.pomerium.com/u/Arzar)\
**Replies:** 5\
**Last updated:** [September 11, 2024, 4:09pm UTC](https://discuss.pomerium.com/t/accessing-upstream-services-that-require-sso/398 "2024-09-11T16:09:47Z")

</div>

We want to try Pomerium with our internal services, but many of our upstream applications use SAML for SSO authentication. We haven’t found a good way to get the SAML authentication working through the Pomerium proxy. Is…

---

## [How to deal with absolute path and cross orgin](https://discuss.pomerium.com/t/how-to-deal-with-absolute-path-and-cross-orgin/397)

<div class="topic-metadata">

**Author:** [@Arzar](https://discuss.pomerium.com/u/Arzar)\
**Replies:** 2\
**Last updated:** [September 5, 2024, 11:03am UTC](https://discuss.pomerium.com/t/how-to-deal-with-absolute-path-and-cross-orgin/397 "2024-09-05T11:03:11Z")

</div>

We tried to set up Pomerium to provide access to some of our internal resources. Most of these resources are legacy systems that we cannot modify. However, we encountered some issues. We are getting redirected out of Po…

---

## [Connecting OICD server](https://discuss.pomerium.com/t/connecting-oicd-server/390)

<div class="topic-metadata">

**Author:** [@misha](https://discuss.pomerium.com/u/misha)\
**Replies:** 3\
**Last updated:** [August 12, 2024, 9:26pm UTC](https://discuss.pomerium.com/t/connecting-oicd-server/390 "2024-08-12T21:26:48Z")

</div>

What happened? Pomerium v0.25.0 deployed on GKE. On the server side, the setup as described in(https://openid.net/) includes https://example.com/.well-known/openid-configuration endpoint First, I am reaching authorizat…

---

## [The Real Lessons from the Snowflake Breach](https://discuss.pomerium.com/t/the-real-lessons-from-the-snowflake-breach/393)

<div class="topic-metadata">

**Author:** [@CMo](https://discuss.pomerium.com/u/CMo)\
**Replies:** 0\
**Last updated:** [August 8, 2024, 7:29pm UTC](https://discuss.pomerium.com/t/the-real-lessons-from-the-snowflake-breach/393 "2024-08-08T19:29:37Z")

</div>

The Snowflake breach has more lessons than just “apply MFA”. From third-party risks to the Perimeter Problem, there’s more to consider about how these breaches affect companies.

---

## [CrowdStrike is a Harsh Reminder of the Danger of Third-Party Clients](https://discuss.pomerium.com/t/crowdstrike-is-a-harsh-reminder-of-the-danger-of-third-party-clients/389)

<div class="topic-metadata">

**Author:** [@CMo](https://discuss.pomerium.com/u/CMo)\
**Replies:** 0\
**Last updated:** [August 5, 2024, 5:29pm UTC](https://discuss.pomerium.com/t/crowdstrike-is-a-harsh-reminder-of-the-danger-of-third-party-clients/389 "2024-08-05T17:29:43Z")

</div>

Clients suck to maintain and are unreliable Auto-updates risk another incident Closed-source software does not allow for verification

---

## [Network-centric vs Application-centric Approach](https://discuss.pomerium.com/t/network-centric-vs-application-centric-approach/391)

<div class="topic-metadata">

**Author:** [@CMo](https://discuss.pomerium.com/u/CMo)\
**Replies:** 0\
**Last updated:** [August 7, 2024, 10:35pm UTC](https://discuss.pomerium.com/t/network-centric-vs-application-centric-approach/391 "2024-08-07T22:35:54Z")

</div>

Network-centric and application-centric approaches: which is better for safeguarding your infrastructure in today’s evolving threat landscape? Why does the NSA say: “Traditional perimeter-based network defenses with mu…

---

## [Cross-Origin Configuration](https://discuss.pomerium.com/t/cross-origin-configuration/384)

<div class="topic-metadata">

**Author:** [@sorin.flueras](https://discuss.pomerium.com/u/sorin.flueras)\
**Replies:** 1\
**Last updated:** [July 1, 2024, 5:17pm UTC](https://discuss.pomerium.com/t/cross-origin-configuration/384 "2024-07-01T17:17:02Z")

</div>

There are three solutions provided at Cross-Origin Configuration | Pomerium for fixing the 401 error related to cross-origin configuration. However, all three require changes to the application code. What can I do if I c…

---

## [Introducing Pomerium Zero](https://discuss.pomerium.com/t/introducing-pomerium-zero/382)

<div class="topic-metadata">

**Author:** [@CMo](https://discuss.pomerium.com/u/CMo)\
**Replies:** 0\
**Last updated:** [June 20, 2024, 3:57pm UTC](https://discuss.pomerium.com/t/introducing-pomerium-zero/382 "2024-06-20T15:57:04Z")

</div>

Today, we’re excited to announce the introduction of Pomerium Zero, our NextGen Access Platform! Please read the full announcement here!

---

## [Notice of upcoming changes for Pomerium's Hosted Authenticate service](https://discuss.pomerium.com/t/notice-of-upcoming-changes-for-pomeriums-hosted-authenticate-service/380)

<div class="topic-metadata">

**Author:** [@CMo](https://discuss.pomerium.com/u/CMo)\
**Replies:** 0\
**Last updated:** [June 10, 2024, 4:29pm UTC](https://discuss.pomerium.com/t/notice-of-upcoming-changes-for-pomeriums-hosted-authenticate-service/380 "2024-06-10T16:29:41Z")

</div>

Pomerium is making changes to our Hosted Authenticate service, which will affect any existing Pomerium instances and users currently relying on the service. This is a preliminary notice before the change is expected to …

---

## [Skip the SSO tax with Pomerium](https://discuss.pomerium.com/t/skip-the-sso-tax-with-pomerium/379)

<div class="topic-metadata">

**Author:** [@CMo](https://discuss.pomerium.com/u/CMo)\
**Replies:** 0\
**Last updated:** [May 30, 2024, 6:39pm UTC](https://discuss.pomerium.com/t/skip-the-sso-tax-with-pomerium/379 "2024-05-30T18:39:35Z")

</div>

We cover what the SSO tax is, why it’s such a problem, and how we’re doing our part in making SSO available for all. Pomerium is purpose-built to enable adding SSO to any self-hosted app, including legacy apps without …

---

## [Programatic Access JWT expires too early](https://discuss.pomerium.com/t/programatic-access-jwt-expires-too-early/198)

<div class="topic-metadata">

**Author:** [@mchaines](https://discuss.pomerium.com/u/mchaines)\
**Replies:** 8\
**Last updated:** [May 17, 2024, 8:37am UTC](https://discuss.pomerium.com/t/programatic-access-jwt-expires-too-early/198 "2024-05-17T08:37:56Z")

</div>

I’ve implemented a programmatic access workflow as described here. After receiving the session callback, I capture the JWT from the URL and add it to subsequent API requests in an auth header like Authorization: Pomerium…

---

## [Modify the token type towards argo-workflow](https://discuss.pomerium.com/t/modify-the-token-type-towards-argo-workflow/367)

<div class="topic-metadata">

**Author:** [@daniel.caldararu](https://discuss.pomerium.com/u/daniel.caldararu)\
**Replies:** 4\
**Last updated:** [May 16, 2024, 9:29am UTC](https://discuss.pomerium.com/t/modify-the-token-type-towards-argo-workflow/367 "2024-05-16T09:29:01Z")

</div>

What happened? I’m trying to use Pomerium in order to redirect the token once I authenticate through my issuer, towards to argo-workflow UI which supports Token authentication and SSO login. Unfortunately doesn’t work be…

---

## [service":"autocert","error":"no OCSP stapling for \[www.hyprpg.net\]: no OCSP server specified in certificate](https://discuss.pomerium.com/t/service-autocert-error-no-ocsp-stapling-for-www-hyprpg-net-no-ocsp-server-specified-in-certificate/375)

<div class="topic-metadata">

**Author:** [@Rajni](https://discuss.pomerium.com/u/Rajni)\
**Replies:** 1\
**Last updated:** [May 15, 2024, 3:51pm UTC](https://discuss.pomerium.com/t/service-autocert-error-no-ocsp-stapling-for-www-hyprpg-net-no-ocsp-server-specified-in-certificate/375 "2024-05-15T15:51:09Z")

</div>

What happened? service":“autocert”,“error”:“no OCSP stapling for \[www.hyprpg.net\]: no OCSP server specified in certificate” What did you expect to happen? How’d it happen? Ran x Clicked y Saw error z What’s your envir…

---

## [Pomerium OSS + LogTo in k3s (Traefik)](https://discuss.pomerium.com/t/pomerium-oss-logto-in-k3s-traefik/372)

<div class="topic-metadata">

**Author:** [@IngwiePhoenix](https://discuss.pomerium.com/u/IngwiePhoenix)\
**Replies:** 3\
**Last updated:** [May 9, 2024, 6:34pm UTC](https://discuss.pomerium.com/t/pomerium-oss-logto-in-k3s-traefik/372 "2024-05-09T18:34:12Z")

</div>

What happened? I have recently installed LogTo into my cluster and configured a few basics. Right now, my k3s cluster is not exposed to the public - I want to figure out authentication and authorization beforehand. The …

---

## [Generate Pomerium-Desktop config by reading pomerium core config](https://discuss.pomerium.com/t/generate-pomerium-desktop-config-by-reading-pomerium-core-config/369)

<div class="topic-metadata">

**Author:** [@pomerian](https://discuss.pomerium.com/u/pomerian)\
**Replies:** 3\
**Last updated:** [April 29, 2024, 5:20pm UTC](https://discuss.pomerium.com/t/generate-pomerium-desktop-config-by-reading-pomerium-core-config/369 "2024-04-29T17:20:42Z")

</div>

Generate Pomerium-Desktop config by reading pomerium core config Description: I have many many TCP routes configured in pomerium. And to be honest, I do not know any individual being happy to copy those by hand. I wrote…

---

## [No support for Google Cloud Serverless authentication in Kubernetes?](https://discuss.pomerium.com/t/no-support-for-google-cloud-serverless-authentication-in-kubernetes/370)

<div class="topic-metadata">

**Author:** [@0anton](https://discuss.pomerium.com/u/0anton)\
**Replies:** 1\
**Last updated:** [April 27, 2024, 8:31am UTC](https://discuss.pomerium.com/t/no-support-for-google-cloud-serverless-authentication-in-kubernetes/370 "2024-04-27T08:31:29Z")

</div>

We came to a surprising statement in the documentation reading the configuration option enable\_google\_cloud\_serverless\_authentication that Kubernetes does not support Enable Google Cloud Serverless Authentication. Why i…

---

## [ERR\_TOO\_MANY\_REDIRECTS after authenticating (Pomerium + IDP (Okta, Github or Azure AD)](https://discuss.pomerium.com/t/err-too-many-redirects-after-authenticating-pomerium-idp-okta-github-or-azure-ad/363)

<div class="topic-metadata">

**Author:** [@robmonct](https://discuss.pomerium.com/u/robmonct)\
**Replies:** 2\
**Last updated:** [April 22, 2024, 7:07pm UTC](https://discuss.pomerium.com/t/err-too-many-redirects-after-authenticating-pomerium-idp-okta-github-or-azure-ad/363 "2024-04-22T19:07:29Z")

</div>

Dear team, I’m trying to use Pomerium to work as a Identity-Aware Proxy in Azure AKS. I followed the Pomerium Kubernetes Quickstart (Kubernetes Quickstart | Pomerium) and worked fine. After that, I followed the installa…

---

## [Pomerium loops re-reading configuration from CloudRun mounted Secret](https://discuss.pomerium.com/t/pomerium-loops-re-reading-configuration-from-cloudrun-mounted-secret/361)

<div class="topic-metadata">

**Author:** [@0anton](https://discuss.pomerium.com/u/0anton)\
**Replies:** 1\
**Last updated:** [April 22, 2024, 5:07pm UTC](https://discuss.pomerium.com/t/pomerium-loops-re-reading-configuration-from-cloudrun-mounted-secret/361 "2024-04-22T17:07:20Z")

</div>

Dear team, I’m observing Pomerium (using latest image from pomerium/pomerium:latest, should be v0.25.2) is looping in the fileutil/watcher permanently rebuilding/re-reading its config.yaml: { "jsonPayload": { "le…

[Previous page](https://discuss.pomerium.com/latest.md)

[Next page](https://discuss.pomerium.com/latest.md?page=2)
