mirror of
https://github.com/netbirdio/netbird.git
synced 2026-07-28 08:52:37 -04:00
error: failed while getting Management Service public key #925
Closed
opened 2025-11-20 05:20:00 -05:00 by saavagebueno
·
22 comments
No Branch/Tag Specified
main
feature/changeset
worktree-dns-route-qtype-fallthrough
fix/ui-dependencies
mdm_integration
install-script-ui-dependencies
reverse-proxy-crowdsec-appsec
android/gui-integration
dependabot/go_modules/aws-sdk-8f849ebaed
dependabot/github_actions/actions-a940c7c866
dependabot/go_modules/gorm-2271c8195b
dependabot/go_modules/pion-5f703e1eca
dependabot/go_modules/otel-e34c790afd
dependabot/go_modules/wireguard-dbd6b95108
dependabot/go_modules/testcontainers-de325c0dd6
fix/unify-route-selection
feature/android-peer-detail
revert/component-types
mlsmaycon-patch-2
feat-post_quantum_ml_kem
feature/android-rename-profile
reverse-proxy-allow-match-or
feat/agent-network-ollama
dependabot/go_modules/google.golang.org/grpc-1.82.1
proxy-tunnel-cache-ttl-env
coderabbitai/utg/1e5b0a5
fix/add-ui-prod-buld-tag
grpc-acl
test/battery-drain
claude/model-cost-calculation-bug-9hic1n
components-impl-drop-indexes-use-xids-no-resource-policy-map
fix/nmap-relevant-groups
fix/ios-common-tunnel-notifier
e2e-guardrail-blocks-unselected-model
fix/lazyconn-cold-start-allowed-ips
vertex-guardrails-model-access-e2e
add-atomic-cache-ops
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.106.0
refactor/relay-foreign-cache
ci/trigger-release-tests
claude/netbird-pr-6767-comments-c0qkci
feature/kimi-3-agent-networks-dns-warmup
feature/dns-lazy-conn-warmup
daemon-ipc-acl
feature/ui-translation-key-parity-check
refactor/relay-foreign-cache-tests
claude/kimi-3-agent-networks-3rpqnv
fix/remove-math-rand
fix/lazyconn-idle-keep-wg-peer
dmitri-propagate-auth-grant-types-on-combined
0.74.7-branch
diagnose-empty-vs-corrupt-state
windows-sleep-detector
fix/cli-up-wait-for-daemon
lazy-conn-rosenpass
lazy-conn-per-peer
rp_key_persistency
feature/native-grpc
client-local-metrics
fix-ssh-authorized-users-multi-rule
0.74.6-branch
0.74.6-branch-sync
0.74.5-branch-sync
0.74.4-branch
fix/remove-stale-peers-removal
fix/remove-stale-proxy-logic
embedded-vnc
fix/nsis-preserve-autostart-on-upgrade
refactor/peer-event-bus
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3
dependabot/go_modules/github.com/pkg/sftp-1.13.10
components-impl-drop-indexes
fix-reset-aggregation-window-flake
dependabot/go_modules/github.com/pion/dtls/v3-3.1.5
peer-acl-multi-source
0.74.x
fix/relay-states-lock
update-process-pkg
update-gopsutil-v4
fix/relay_states_lock
increase-sysinfo-timeout
dependabot/npm_and_yarn/client/ui/frontend/npm_and_yarn-88714b13d0
dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
dependabot/go_modules/github.com/eko/gocache/store/redis/v4-4.2.6
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.3
fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
0.74.3-branch
fix/routeselector-atomic-exit-node
netmap_progressive_alignment
nmap/components-impl
dependabot/go_modules/github.com/jackc/pgx/v5-5.9.2
dependabot/go_modules/github.com/oapi-codegen/runtime-1.4.2
dependabot/go_modules/github.com/gopacket/gopacket-1.6.1
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0
dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0
fix/signal-watchdog-sync-stop
docs/agent-network
feature/ios-ssh
test/affected-logic
fix/revert-ice-filter
refactor/simplify-affected-peers
pascal-filter-policies-by-direction
claude/lock-contention-peer-connect-g8t6au
dmitri-filter-policies-by-direction
refactor/migrate-profiles-to-go
profile-bindings-ios
fix/skip-restart-unchanged-route
fix/mgmt-cache-async-resolve
refactor/wails-update-105
client_lifetime_serialization_refactor
fix/browser-ssh-2
fix/ipv6-and-netstack-accept-loop
fix/browser-ssh
profile-id-name-test
refactor/mgmt-bootstrap
feat/getting-started-unified-wizard
socket-grpc-permissions
fix/mysql-index-migration
windows-dns-firewall
tests/enable-race-on-tests
ui-refactor-gtk3
feature/affected-peers-grpc
profile-id
lazyconn-first-packet-fix-v2
claude/focused-gates-VMTgb
ui-tray-linux-leftclick
fix/ctx-enrichment
daemon-owner
feature/android-client-ssh
worktree-accept-ra-forwarding
nmap/combined-deploy
task/align_protobuff_toolset
feature/session-extend
add-json-yaml-flags
refactor/ephemeral-cleanup
claude/webtransport-relay-wasm-mUjY9
claude/vnc-udp-feasibility-6KB1U
fix/wgport-config
e2e-windows-dns-combined
fix/login-cmd-root-flags
feat/reseller-openapi-spec
github-issue-resolver
add-steamos-support
fix-darwin-uninstaller
flutter-test
ci/freebsd-pkg-bootstrap
cached-serial-check-on-sync
fix-mgmt-cache-bypass-overlay
revert-easyjson-5938
revert-ice-5820
revert-firewalld-5928
refactor/permissions-manager
revert-dns-5935-systemd-resolved
revert-dns-5935-5945
revert-dns-5945-mgmt-cache
feature/log-most-busy-peers
prototype/ui-wails
coderabbitai/utg/8ae8f20
feature/use-peer-fqdn-on-https
release/0.68.3
add-slack-channel
claude/rdp-token-passthrough-eNcqW
transparent-proxy
fix/macos-stale-route-eexist
crowdsec-selfhosted
fix/remove-otel-units
entire/checkpoints/v1
fix/getting-started
feat/static-connectors-combined-server
feature/use-local-keys-embedded
feature/fleetdm
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.75.1
v0.75.0
v0.74.7
v0.74.6
v0.74.5
v0.75.0-rc.6
v0.74.4
v0.74.3
v0.75.0-rc.5
v0.74.2
v0.74.1
v0.75.0-rc.4
v0.74.0
v0.74.0-rc.2
v0.74.0-rc.1
v0.73.2
v0.75.0-rc.3
v0.75.0-rc.2
v0.73.1
v0.75.0-rc.1
v0.73.0
v0.72.4
v0.72.3
v0.72.2
v0.72.1
v0.72.0
v0.71.4
v0.71.3
v0.71.2
v0.71.1
v0.71.0
v0.70.5
v0.70.4
v0.70.3
v0.70.2
v0.70.1
v0.70.0
v0.69.0
v0.68.3
v0.68.2
v0.68.1
v0.68.0
v0.67.4
v0.67.3
v0.67.2
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2022 Q1
2022 Q1
accessibility
acl
agent
agent
Android
Android
api
authentik
automation
azure
battery-usage
bug
cache
client
client-ui
cloud
cloud-only
cloudflare
community
compatibility
config-idp
config-issue
connection
contribution
coturn
cross-vpn
dashboard
data-usage
distribution
dns
docker
documentation
duplicate
enhancement
enhancement
event-stream
feature-request
freebsd
getting-started
go
good first issue
gui
help wanted
home-assistant
idp
inconsistency
integration
integrations
ios
ipv6
jwt
k8s
keycloak
linux
login
macos
management-service
missing-docs
mobile
moved-internal
needs-review
netbird-ui
networking
new-platform
nginx
notification
okta
openwrt
packaging
peer-management
peer-management
peer-management
performance
postgres
posture-checks
psk
pull-request
question
refactor
relay
release
rfc
routes
security
security-related
self-hosting
server
signal
sleep-issue
ssh
ssl
status
store
synology
system-compatibility-issue
test-suite
third-party-integration
triage
triage-needed
troubleshooting
UX
waiting-feedback
windows
wontfix
zitadel
Mirrored from GitHub Pull Request
No Label
triage-needed
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
saavagebueno
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: SVI/netbird#925
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @LuizFelipeAlvesMaia on GitHub (May 23, 2024).
Describe the problem
The error message you are encountering, "rpc error: code = Unknown desc = getting device authorization flow info failed with error: failed while getting Management Service public key," indicates that the Netbird agent is unable to retrieve the public key from the Management Service. This public key is essential for establishing a secure communication channel between the agent and the management service. The failure could be due to several reasons, such as network connectivity issues, misconfiguration of the management service, or problems with the service's key management or distribution.
To Reproduce
Steps to reproduce the behavior:
Follow all the steps in the Self-Hosted guide, using Google Workspace IDP.
Attempt to connect a Windows agent to https://netbird.mydomain.com:443.
Expected behavior:
The agent should successfully connect to the Netbird self-hosted instance, retrieving the Management Service public key and completing the authorization process without errors.
Are you using NetBird Cloud?
No, I am self-hosting NetBird's control plane.
NetBird version: 0.27.9
If applicable, add screenshots to help explain your problem.
@LuizFelipeAlvesMaia commented on GitHub (May 24, 2024):
UPDATE: Now I have an error when trying to connect my Netbird agent. My management container has the following log:
management-1 | 2024-05-24T21:17:55Z WARN management/server/grpcserver.go:371: failed logging in peer@Amplificator commented on GitHub (Jun 3, 2024):
I have the same error as you initially did - how did you fix it?
@LuizFelipeAlvesMaia commented on GitHub (Jul 31, 2024):
I'm still encountering the same error. I had to take a break from trying to fix it, but now I'm attempting to resolve it again. My peers still can't connect to the server.
@biggreywave commented on GitHub (Aug 4, 2024):
sane error here
@maslyankov commented on GitHub (Aug 6, 2024):
Anyone who solved this?
@BrianGrug commented on GitHub (Sep 3, 2024):
I'm having the same issue as well. Using Authentik as SSO
@juniormarangao commented on GitHub (Sep 16, 2024):
Hi!
I am facing this issue, I can't connect any client.
I've installed using Advanced guide, with Authentik and Nginx Proxy Manager.
I can login, shows peers page, I can create management Keys, but I cannot connect.
When I debbug with
sudo netbird up -F -l debug -m https://myvpn.example.com:443shows this belowThe setup is 3 VMs:
All behind one Public IP, but same internal network, all reachable between each.
In NPM with host pointing to netbird vm, is the ports
80,443, and33073in configuration, with gRPC, etc...The other ports required, is forwarding directly to the netbird VM.
There are something that I missed?
@Christophe-Foyer commented on GitHub (Sep 24, 2024):
Any updates on this issue? I'm also having the same problem. Here's the exact error I'm seeing when setting up the peer:
Regarding my setup, I can access the ui at
https://subdomain.domain.example/, keycloak is athttps://othersubdomain.domain.example/with the admin url set to a localhttp://192.168.X.X:port/reflecting the VM ip and keycloak port. Logging in seems to work fine.I also only have ports 80 and 443 forwarded to NPM which then forwards it to the VM that hosts netbird (where SSL is off etc).
My Nginx Proxy Manager is setup as described in this reddit comment. Custom locations:
/api
Scheme: http Forward Hostname / IP : netbird-management-1 Forward Port: 443
/management.ManagementService/
Advanced:
grpc_pass grpc://192.168.X.X:33073; # matches exposed management port in docker compose
#grpc_ssl_verify off;
grpc_read_timeout 1d;
grpc_send_timeout 1d;
grpc_socket_keepalive on;
/signalexchange.SignalExchange/
Advanced:
grpc_pass grpc://192.168.X.X:10000; # matches exposed signal port in docker compose
#grpc_ssl_verify off;
grpc_read_timeout 1d;
grpc_send_timeout 1d;
grpc_socket_keepalive on;
Happy to share more about my setup, this is seen as advanced use from my understanding so not too surprising if I got things wrong when setting it up for the first time.
@juniormarangao commented on GitHub (Sep 24, 2024):
I had a little progress I think.
Instead
/apiset to IP:443, I changed to IP:33073With this I could partially add peers.
On the client side (linux) I used the command
netbird up -m https://domain.nameand generated the URL for authenticate, I can authenticate, but the page goes blank, and in terminal stays forever without end to establish the connection...Checking management logs, shows
Peer need to loginWhen I cancel the command in client side and type
netbird statusit shows connected, but Signal disconnected.In Dashboard page the peer shows there, but offline.
Now I am trying hard to figure out how to fix that too, and until now nothing.
@185504a9 commented on GitHub (Sep 24, 2024):
This is pretty specific so I dunno if this can help you guys but I "solved" this problem after remembering that I'm using Cloudflare as DNS so I had to disable the proxying of requests to my netbird's subdomain
@Christophe-Foyer commented on GitHub (Sep 24, 2024):
Not a solution and not sure if this gives any more info but I can't even get it to a point where it complains that the peer needs to log in.
I had a typo above and it was already redirecting the API calls to the correct address. Can't get it to reach your peer need to login issue yet.
Cloudflare proxying is already off.
This is a slightly more verbose version of the error above when running
GRPC_GO_LOG_VERBOSITY_LEVEL=99 GRPC_GO_LOG_SEVERITY_LEVEL=info netbird up -F -l debug:Still digging into this, would be nice to get it working some day.
EDIT:
Seems like
{KEYCLOAK_URL}/admin/realms/netbirddoesn't slead anywhere, I thought it was meant to be a rest api or something?@Christophe-Foyer commented on GitHub (Sep 24, 2024):
Figured out my issue. Just had to move the grpc directives to the advanced tab in nginx proxy manager.
Not sure it's the same as the rest of you though but going to post my config just in case.
Edit: though now I'm having issues with peers not seeing relay servers so... fun new isues to solve!
@BrianGrug commented on GitHub (Sep 25, 2024):
I ended up getting a cheap VPS and hosting it on there. No issues after that. Even tried using the same reverse proxy instance, that it worked. Have no idea what was causing the issue, guessing a firewall misconfiguration, or maybe a port missing from documentation?
@juniormarangao commented on GitHub (Sep 25, 2024):
I have it installed in other location, in a residential place with a common residential internet with dynamic public IP, but with quick install, all Default, and it is working great.
But this way I lost my port 80 and 443 to work only netbird.
I am almost to take a cheap VPS too, and use quick install... This is really annoying me... The documentation is missing a lot of things.
@collse commented on GitHub (Sep 30, 2024):
damn this was a tricky one but I finally got it to work.
edit: 02-10-2024 - had to do some minor changes
My setup is as follows:

my docker compose differs as below:
adjust your management.json to:
my nginx proxy manager configuration:
main domain eg:
nb.your.dom.com
scheme: http forward: ip.address.of.docker.host forward_port:80
advanced:
custom locations:
/api
scheme: http forward: ip.address.of.docker.host forward_port:33073
advanced
/management.ManagementService/
scheme: http forward: ip.address.of.docker.host forward_port:33073
advanced:
/signalexchange.SignalExchange/
scheme: http forward: ip.address.of.docker.host forward_port:10000
advanced:
/relay/
scheme: http forward: ip.address.of.docker.host forward_port:33080
NPM version: v2.11.3 © 2024 jc21.com.
you will still need to forward the ports for tun on your firewall: UDP 3478, and range of ports, UDP 49152-65535 for dynamic relay connections or as changed from the defaults
@juniormarangao commented on GitHub (Oct 16, 2024):
Maybe it not be considering close yet.
I've checked my configuration, most was like yours @collse, so I did the changes following your guide, and I am still facing issues...
Well, let's say I got some progress even before this adjustments...
My case now is: I am able to access dashboard page, I can navigate to other pages, like Setup Keys and create keys, Access Control,, Network Routes, etc.
But when I try to add some peer, in the client the things stay forever without finish the command
netbird up -m https://domainIt generates a url, that ask me to login, after the login the page is blank and nothing happens, when I use a Key
netbird up -m https://domain -k key-valueits just stays forever without finish the command, the peer shows in dashboard but as offline, in management logs keeps showing "Peer needs login".Honestly, I don't know nothing more I can do, I already have started it again from scratch a couple of times, and always I got stuck in this situation
Update: I am getting this error on client side
And in status show Signal as disconnected
@collse commented on GitHub (Oct 16, 2024):
seems like your signalling is trying to reach port: 10000 instead of using 443 and then being handled ... my setup only exposes 80 and 443 externally no other ports on NPM, the remaining ports are handled in NPM or forwarded by my firewall directly
try the following:
netbird up -m https://domain:443 -k key-value@juniormarangao commented on GitHub (Oct 20, 2024):
Same thing!
Could it be some misconfiguration on signal in Nginx Proxy Manager?
I did the configuration like in your previous post
/signalexchange.SignalExchange/
scheme: http forward: ip.address.of.docker.host forward_port:10000
advanced:
@collse commented on GitHub (Oct 20, 2024):
based on your previous message it is attempting to make the call to port 10000 instead of 443 not sure what prompts it to do that, check your configuration again, against mine - I know it works as it has been working like that since - unfortunately no other advice that I can give apart from also checking your npm logs but the attempt to :10000 is explicit enough what happens there
@VitorNilson commented on GitHub (Nov 1, 2024):
Hey everyone, I getting an error that looks like yours. Have you ever seen that?
Important: I'm using cloudlflare with cloudflare proxy.
I've enabled gRPC:

I don't know what can I do now to fix that... do you guys have any idea?
EDIT:
Guys, removing cloudflare's proxy this is what i get now:
@mhartmann-jaconi commented on GitHub (May 3, 2025):
Even though this issue is closed, I wanted to share my findings regarding this issue. I ran netbird in a GKE cluster with a managed nginx ingress in front. When capturing traffic, I noticed that the requests, which should be grpc calls, were sent as HTTP/1.1 requests.
So adding an annotation
nginx.ingress.kubernetes.io/backend-protocol: GRPCto the ingress resource solved the issue for me, as now the requests reach the server as real grpc calls.@liuyishengaaa commented on GitHub (Jun 12, 2025):
My issue was about joining a Netbird private network using a Debian 11 server without a graphical interface. When I ran the command "netbird up --management-url https://xxxxxx.net --admin-url https://xxxxxx.net --setup-key xxxxx-xxx-xxxx", I got an error saying "error: failed while getting Management Service public key". Fortunately, by referring to your question and using the command "sudo netbird up -F -l debug -m https://myvpn.example.com:443", I found a solution. This command will print a login link at the end, which can be copied and executed in another browser for authorization and login.