# Chage zammad.conf - CSRF Token error - default

**URL:** https://community.zammad.org/t/chage-zammad-conf-csrf-token-error-default/6675
**Category:** Technical assistance
**Created:** [April 15, 2021, 3:39pm UTC](https://community.zammad.org/t/chage-zammad-conf-csrf-token-error-default/6675 "2021-04-15T15:39:40Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Tobias](https://community.zammad.org/letter_avatar_proxy/v4/letter/t/c67d28/32.png) [@Tobias](https://community.zammad.org/u/Tobias)
#### Post date: [April 15, 2021, 3:39pm UTC](https://community.zammad.org/t/chage-zammad-conf-csrf-token-error-default/6675/1 "2021-04-15T15:39:40Z")

</div>

- Used Zammad version: 3.6.0-67
- Used Zammad installation type: docker-compose
- Operating system: CentOS 7
- Browser + version: ALL

Error:  
We can not login Error: CSRF token verification failed!

we have been looking for a solution for 2 days.  
and have come across the following page: [CSRF Token error on login since upgrading to 3.2 · Issue #120 · zammad/zammad-docker-compose · GitHub](https://github.com/zammad/zammad-docker-compose/issues/120)

unfortunately, the file /etc/nginx/sites-available/default is changed again after every reboot.

Which zammad.conf do I have to adapt so that it is changed with the correct parameters?

proxy\_set\_header X-Forwarded-Proto https;

see:

> [@Fresh install 3.2.x: CSRF token verification failed](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/17):
>
> I also run an update on Ubuntu from 3.1 to 3.2 and experience the same issue. With nginx adding proxy\_set\_header X-Forwarded-Proto https; in the location / worked out for me.

---

<div class="post-metadata">

### Author: ![MrGeneration](https://community.zammad.org/user_avatar/community.zammad.org/mrgeneration/32/9260_2.png) [@MrGeneration](https://community.zammad.org/u/MrGeneration)
#### Post date: [June 17, 2021, 5:15pm UTC](https://community.zammad.org/t/chage-zammad-conf-csrf-token-error-default/6675/2 "2021-06-17T17:15:38Z")

</div>

The documentation has you covered:  
[https://docs.zammad.org/en/latest/install/docker-compose/environment.html#nginx](https://docs.zammad.org/en/latest/install/docker-compose/environment.html#nginx)

---

<div class="post-metadata">

### Author: ![system](https://community.zammad.org/uploads/default/original/1X/5c5afaea2d23f811dbec33cd4edb02fa29d3262f.png) [@system](https://community.zammad.org/u/system)
#### Post date: [October 15, 2021, 5:16pm UTC](https://community.zammad.org/t/chage-zammad-conf-csrf-token-error-default/6675/3 "2021-10-15T17:16:22Z")

</div>

This topic was automatically closed 120 days after the last reply. New replies are no longer allowed.
