# Ignore Self-Signed Upstream TLS Cert

**URL:** <https://discuss.pomerium.com/t/ignore-self-signed-upstream-tls-cert/300>\
**Category:** Support\
**Tags:** docker\
**Created:** [September 1, 2023, 11:14pm UTC](https://discuss.pomerium.com/t/ignore-self-signed-upstream-tls-cert/300 "2023-09-01T23:14:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![wolveix](https://yyz1.discourse-cdn.com/flex031/user_avatar/discuss.pomerium.com/wolveix/32/153_2.png) [@wolveix](https://discuss.pomerium.com/u/wolveix)\
**Post date:** [September 1, 2023, 11:14pm UTC](https://discuss.pomerium.com/t/ignore-self-signed-upstream-tls-cert/300/1 "2023-09-01T23:14:34Z")

</div>

## What happened?

I’m trying to setup a route through to a service that has a self-signed certificate. Frustratingly, it can’t be disabled, and the cert that Pomerium issues for the subdomain is incompatible with it for whatever reason.

## What did you expect to happen?

I expected there to be some kind of configuration I could set to ignore the upstream TLS cert’s validity.

## How’d it happen?

1. Tried setting `disable_ssl_cert_validation` as was hinted at from this old GitHub issue [Allow proxy for https site running w/ self-signed certificate · Issue #179 · pomerium/pomerium · GitHub](https://github.com/pomerium/pomerium/issues/179) (though it seemed that this isn’t actually implemented)
2. Saw the following error:

```auto
upstream connect error or disconnect/reset before headers. reset reason: connection failure, transport failure reason: TLS error: 268435581:SSL routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED

```

## What’s your environment like?

- Pomerium version (retrieve with `pomerium --version`):  
Latest version

- Server Operating System/Architecture/Cloud:  
Docker, running on:

```auto
VERSION="20230612-1409"
PRETTY_NAME="Debian GNU/Linux 12 (bookworm)"
NAME="Debian GNU/Linux"
VERSION_ID="12"
VERSION="12 (bookworm)"
VERSION_CODENAME=bookworm

```

## What’s your config.yaml?

```auto
# See detailed configuration settings: https://www.pomerium.com/docs/reference/

#####################################################################
# If self-hosting, use the localhost authenticate service URL below #
# and remove the hosted URL. #
#####################################################################
authenticate_service_url: https://REDACTED

####################################################################################
# If self-hosting, you must configure an identity provider. #
# See identity provider settings: https://www.pomerium.com/docs/identity-providers/#
####################################################################################

idp_provider: 'google'
idp_client_id: 'REDACTED.apps.googleusercontent.com'
idp_client_secret: 'REDACTED'
autocert: true

# https://pomerium.com/reference/#routes
routes:
  - from: https://warp.domain.tld
    to: https://warpgate:8888
    pass_identity_headers: true
    policy:
      - allow:
          or:
            - email:
                is: me@domain.tld
  - from: https://verify.domain.tld
    to: http://verify:8000
    pass_identity_headers: true
    policy:
      - allow:
          or:
            - email:
                is: me@domain.tld

```

## Additional context

Apologies if this is documented somewhere, I’ve been searching around for a while and couldn’t find anything. I really appreciate any input or direction you may be able to offer. Thank you!

---

<div class="post-metadata">

**Author:** ![denis](https://avatars.discourse-cdn.com/v4/letter/d/5e9695/32.png) [@denis](https://discuss.pomerium.com/u/denis)\
**Post date:** [September 2, 2023, 4:55pm UTC](https://discuss.pomerium.com/t/ignore-self-signed-upstream-tls-cert/300/2 "2023-09-02T16:55:17Z")

</div>

Hello,

if you do have a certificate authority for the upstream service certificate, you may set its certificate using [`tls_custom_certificate_authority`](https://www.pomerium.com/docs/reference/routes/tls#tls-custom-certificate-authority) option for a **route**.

If the upstream cert is entirely self-signed, and you do not have the cert itself, then you may disable TLS verification using [`tls_skip_verification`](https://www.pomerium.com/docs/reference/routes/tls#tls-skip-verification). like

---

<div class="post-metadata">

**Author:** ![wolveix](https://yyz1.discourse-cdn.com/flex031/user_avatar/discuss.pomerium.com/wolveix/32/153_2.png) [@wolveix](https://discuss.pomerium.com/u/wolveix)\
**Post date:** [September 2, 2023, 5:28pm UTC](https://discuss.pomerium.com/t/ignore-self-signed-upstream-tls-cert/300/3 "2023-09-02T17:28:10Z")

</div>

> [@denis](#):
>
> If the upstream cert is entirely self-signed, and you do not have the cert itself, then you may disable TLS verification using [`tls_skip_verification`](https://www.pomerium.com/docs/reference/routes/tls#tls-skip-verification). like

Excellent, setting `tls_skip_verify: true` worked. Thank you so much!
