# Fresh install 3.2.x: CSRF token verification failed

**URL:** https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080
**Category:** Technical assistance
**Created:** [September 11, 2019, 7:53am UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080 "2019-09-11T07:53:15Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![thommierother](https://community.zammad.org/user_avatar/community.zammad.org/thommierother/32/1776_2.png) [@thommierother](https://community.zammad.org/u/thommierother)
#### Post date: [September 11, 2019, 7:53am UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/1 "2019-09-11T07:53:15Z")

</div>

Hi,  
on a fresh install of Zammad 3.2.x (source installation on ubuntu 18.04 lts) I get

“CSRF token verification failed!”

on all logins after the initial configuration step (initial setup of an admin user was successful). I can not find any documentation/FAQ with infos on this and the logfile is also not very informative.

Any ideas how to debug?  
Thx, Thommie

---

<div class="post-metadata">

### Author: ![MrGeneration](https://community.zammad.org/user_avatar/community.zammad.org/mrgeneration/32/9260_2.png) [@MrGeneration](https://community.zammad.org/u/MrGeneration)
#### Post date: [September 11, 2019, 1:09pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/2 "2019-09-11T13:09:08Z")

</div>

Note beforehand: Zammad 3.2 is the development state of Zammad and thus for testing only.  
Supporting this is very limited.

Please also provide the used Browser.  
Did you try reloading the page and simply to try again?

Did all migrations run through cleanly?

---

<div class="post-metadata">

### Author: ![thommierother](https://community.zammad.org/user_avatar/community.zammad.org/thommierother/32/1776_2.png) [@thommierother](https://community.zammad.org/u/thommierother)
#### Post date: [September 11, 2019, 1:48pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/3 "2019-09-11T13:48:27Z")

</div>

Oh, sorry, I thought this is a productive version. The VERSION and CHANGELOG files did not contain infos about the dev status 😉

Browser is latest Firefox, but the same issue appears with Chromium/Chrome, also after refresh and bypassing browser cache.

As this is a empty installation right now, what would be best: re- install a stable version or continue with 3.2 and debug it? If it is ore or less “alpha” I would prefer an older version but if its more “beta” or close to release we can do some debugging on it …

Bye., Thommie

---

<div class="post-metadata">

### Author: ![MrGeneration](https://community.zammad.org/user_avatar/community.zammad.org/mrgeneration/32/9260_2.png) [@MrGeneration](https://community.zammad.org/u/MrGeneration)
#### Post date: [September 13, 2019, 4:10pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/4 "2019-09-13T16:10:39Z")

</div>

Honestly, I’d prefer a stable instance on your end without any betaing ;D

However, I do run 3.2 instances which are working without any trouble, so if you’re using any specific addons, those might be at fault as well. Also ensure that your migrations are fine ( `rake db:migrate` ) .

---

<div class="post-metadata">

### Author: ![bc1000](https://community.zammad.org/letter_avatar_proxy/v4/letter/b/2bfe46/32.png) [@bc1000](https://community.zammad.org/u/bc1000)
#### Post date: [December 3, 2019, 1:40pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/5 "2019-12-03T13:40:46Z")

</div>

same problem here. Now 3.2 is a stable release:  
I did a upgrade from 3.1 CentOS Linux release 7.7.1908 (Core)

- LDAP user sync. no special addons

After yum upgrade to zammad 3.2:  
Name : zammad  
Architektur : x86\_64  
Version : 3.2.0  
Ausgabe : 1575357814.e0ff35cb.centos7  
Größe : 655 M  
Quelle : installed

I cannot login anymore. No agent and also local zammadadmin user. Same response:

I, [2019-12-03T14:40:06.502395 #25840-47147295467000] INFO – : Scheduler started.  
I, [2019-12-03T14:40:06.513684 #25840-47147295467000] INFO – : Cleanup of left over locked delayed jobs 2019-12-03 13:40:06 UTC started.  
I, [2019-12-03T14:40:06.518793 #25840-47147295467000] INFO – : Cleanup of left over locked delayed jobs 2019-12-03 13:40:06 UTC finished.  
I, [2019-12-03T14:40:06.518834 #25840-47147295467000] INFO – : Cleanup of left over import jobs 2019-12-03 13:40:06 UTC started.  
I, [2019-12-03T14:40:06.528833 #25840-47147295467000] INFO – : Cleanup of left over import jobs 2019-12-03 13:40:06 UTC finished.  
I, [2019-12-03T14:40:06.528952 #25840-47147295467000] INFO – : Scheduler running…  
I, [2019-12-03T14:40:06.548211 #25840-47147349406500] INFO – : execute Channel.fetch (try\_count 0)…  
I, [2019-12-03T14:40:06.550661 #25840-47147349406500] INFO – : fetching pop3 ( port=995,ssl=true)  
I, [2019-12-03T14:40:06.706351 #25843-47443369821680] INFO – : Setting.set(‘models\_searchable’, [“Chat::Session”, “User”, “Organization”, “Ticket”, “KnowledgeBase::Answer::Translation”])  
I, [2019-12-03T14:40:07.311882 #25838-47295364613620] INFO – : Setting.set(‘models\_searchable’, [“Chat::Session”, “User”, “Organization”, “Ticket”, “KnowledgeBase::Answer::Translation”])  
I, [2019-12-03T14:40:10.554218 #25840-47147350265320] INFO – : Starting worker thread Delayed::Backend::ActiveRecord::Job  
I, [2019-12-03T14:40:11.695242 #25840-47147349406500] INFO – : - no message  
I, [2019-12-03T14:40:11.695458 #25840-47147349406500] INFO – : done  
I, [2019-12-03T14:40:11.720314 #25840-47147349406500] INFO – : fetching pop3 ( port=995,ssl=true)  
I, [2019-12-03T14:40:11.856433 #25840-47147349406500] INFO – : - no message  
I, [2019-12-03T14:40:11.856575 #25840-47147349406500] INFO – : done  
I, [2019-12-03T14:40:11.879031 #25840-47147349406500] INFO – : ended Channel.fetch took: 5.343160165 seconds.  
I, [2019-12-03T14:40:12.132327 #25843-47443387556740] INFO – : Started POST “/api/v1/message\_send” for 192.168.1.3 at 2019-12-03 14:40:12 +0100  
I, [2019-12-03T14:40:12.163808 #25843-47443387556740] INFO – : Processing by LongPollingController#message\_send as JSON  
I, [2019-12-03T14:40:12.163884 #25843-47443387556740] INFO – : Parameters: {“data”=\>{“event”=\>“login”}}  
I, [2019-12-03T14:40:12.164378 #25843-47443387556740] INFO – : CSRF token verification failed

---

<div class="post-metadata">

### Author: ![bc1000](https://community.zammad.org/letter_avatar_proxy/v4/letter/b/2bfe46/32.png) [@bc1000](https://community.zammad.org/u/bc1000)
#### Post date: [December 3, 2019, 3:27pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/6 "2019-12-03T15:27:19Z")

</div>

also checked: rake db:migrate.

I can login successfully, if i use a seperate proxy/firewall and no direct-connection to the zammad server.

---

<div class="post-metadata">

### Author: ![MathiasVolkmer](https://community.zammad.org/user_avatar/community.zammad.org/mathiasvolkmer/32/2162_2.png) [@MathiasVolkmer](https://community.zammad.org/u/MathiasVolkmer)
#### Post date: [December 3, 2019, 3:37pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/7 "2019-12-03T15:37:03Z")

</div>

I got the same Problem here. Did you find a way to login?  
I’m close to panic right now 🙂

---

<div class="post-metadata">

### Author: ![astrastudio](https://community.zammad.org/user_avatar/community.zammad.org/astrastudio/32/2160_2.png) [@astrastudio](https://community.zammad.org/u/astrastudio)
#### Post date: [December 3, 2019, 4:30pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/8 "2019-12-03T16:30:28Z")

</div>

Same problem here on debian after update to 3.2.  
My Zammad is behind an apache reverse proxy which does ssl handling.  
Quickfix: I downgraded back to 3.1

The relevant parts I have in my apache2 zammad.conf:

```
ProxyRequests Off
ProxyPreserveHost On
ProxyPass /ws ws://localhost:6042/
ProxyPass / http://localhost:3001/
<Proxy localhost:3001>
    Require local
</Proxy>

```

Did I miss something for the update?

---

<div class="post-metadata">

### Author: ![MathiasVolkmer](https://community.zammad.org/user_avatar/community.zammad.org/mathiasvolkmer/32/2162_2.png) [@MathiasVolkmer](https://community.zammad.org/u/MathiasVolkmer)
#### Post date: [December 3, 2019, 4:37pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/9 "2019-12-03T16:37:25Z")

</div>

Hello astrastudio  
please don’t laugh, because I ask this. But how I can downgrade back to 3.1?  
Is it possible to install back to 3.1 with Debian?  
I’m also running Zammad on Debian with Apache server and postgreSQL database.

Thanks a lot in advance!

---

<div class="post-metadata">

### Author: ![astrastudio](https://community.zammad.org/user_avatar/community.zammad.org/astrastudio/32/2160_2.png) [@astrastudio](https://community.zammad.org/u/astrastudio)
#### Post date: [December 3, 2019, 4:54pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/10 "2019-12-03T16:54:07Z")

</div>

You can use:

```
apt-cache showpkg zammad

```

to see all available package versions.  
Then use the most recent 3.1 version available and complete the command with the version in it:

```
apt-get install zammad=3.1.0-complete-version-string-here

```

Good luck!

---

<div class="post-metadata">

### Author: ![MrGeneration](https://community.zammad.org/user_avatar/community.zammad.org/mrgeneration/32/9260_2.png) [@MrGeneration](https://community.zammad.org/u/MrGeneration)
#### Post date: [December 3, 2019, 4:54pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/11 "2019-12-03T16:54:58Z")

</div>

I wouldn’t suggest downgrading, because the database schemes might no longer be fitting. So it’s a bit… well… risky. 😃

Safest way to downgrade is always having a snapshot / backup.

Anyway, I can’t reproduce this issue.  
Please try cleaning your cache and reloading the login page.

If the issue persists, run `/opt/zammad/contrib/packager.io/postinstall.sh` just for safety.  
Again, reload the WebApp.

If it still does not work, let me know. This normally should fix it, if it appears.

---

<div class="post-metadata">

### Author: ![astrastudio](https://community.zammad.org/user_avatar/community.zammad.org/astrastudio/32/2160_2.png) [@astrastudio](https://community.zammad.org/u/astrastudio)
#### Post date: [December 3, 2019, 5:21pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/12 "2019-12-03T17:21:20Z")

</div>

Cleared the complete browser cache, did run postinstall.sh script again.  
The problem persists. Back on 3.1 again.

How did CSRF validation change from 3.1 to 3.2.?

---

<div class="post-metadata">

### Author: ![MrGeneration](https://community.zammad.org/user_avatar/community.zammad.org/mrgeneration/32/9260_2.png) [@MrGeneration](https://community.zammad.org/u/MrGeneration)
#### Post date: [December 3, 2019, 5:30pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/13 "2019-12-03T17:30:47Z")

</div>

As far as I’m aware it didn’t.  
This issue appears from time to time after an upgrade, however, above described steps always fixed it (normally ^^")

---

<div class="post-metadata">

### Author: ![astrastudio](https://community.zammad.org/user_avatar/community.zammad.org/astrastudio/32/2160_2.png) [@astrastudio](https://community.zammad.org/u/astrastudio)
#### Post date: [December 3, 2019, 5:34pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/14 "2019-12-03T17:34:52Z")

</div>

I just cloned the VM and did 2 upgrades and downgrades in a row.  
3.2 throws a “CSRF token verification failed” while trying to logon. 3.1 does not. Everything else did not change during the upgrade.

---

<div class="post-metadata">

### Author: ![herzkerl](https://community.zammad.org/user_avatar/community.zammad.org/herzkerl/32/8167_2.png) [@herzkerl](https://community.zammad.org/u/herzkerl)
#### Post date: [December 3, 2019, 5:55pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/15 "2019-12-03T17:55:25Z")

</div>

Ditto. We’re using nginx as proxy on Plesk (current version).

---

<div class="post-metadata">

### Author: ![MrGeneration](https://community.zammad.org/user_avatar/community.zammad.org/mrgeneration/32/9260_2.png) [@MrGeneration](https://community.zammad.org/u/MrGeneration)
#### Post date: [December 3, 2019, 6:51pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/16 "2019-12-03T18:51:24Z")

</div>

One of my two systems striked me with this error as well.  
Both systems are apache based, I added the following two lines to my vHost configuration of Zammad:

```auto
RequestHeader set X_FORWARDED_PROTO 'https' 
RequestHeader set X-Forwarded-Ssl on

```

Followed by  
`a2enmod headers`  
and  
`systemctl restart apache2`

* * *

This post helped me here: [Office Integration · Issue #2758 · zammad/zammad · GitHub](https://github.com/zammad/zammad/issues/2758#issuecomment-536465142)

* * *

Friendly reload of the WebApp and try again.  
Can’t speak for the nginx users right now ☹

---

<div class="post-metadata">

### Author: ![cornelinux](https://community.zammad.org/user_avatar/community.zammad.org/cornelinux/32/451_2.png) [@cornelinux](https://community.zammad.org/u/cornelinux)
#### Post date: [December 3, 2019, 9:44pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/17 "2019-12-03T21:44:24Z")

</div>

I also run an update on Ubuntu from 3.1 to 3.2 and experience the same issue.  
With nginx adding

```
        proxy_set_header X-Forwarded-Proto https;

```

in the `location /` worked out for me.

---

<div class="post-metadata">

### Author: ![herzkerl](https://community.zammad.org/user_avatar/community.zammad.org/herzkerl/32/8167_2.png) [@herzkerl](https://community.zammad.org/u/herzkerl)
#### Post date: [December 3, 2019, 10:06pm UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/18 "2019-12-03T22:06:10Z")

</div>

Thank you very much—that worked for me as well.

I have changed

```
proxy_set_header X-Forwarded-Proto $scheme;

```

to

```
proxy_set_header X-Forwarded-Proto https;

```

and that did it. Also, I wanted to share with the community the nginx config from the Plesk host (which is used only to forward the hostname/subdomain to the internal/NAT ip)—maybe it’ll be of any help for someone else…

```
location ~ ^/(?!(.well-known)) {
	proxy_pass http://<ip>:80;
	proxy_set_header Host $http_host;
	proxy_set_header CLIENT_IP $remote_addr;
	proxy_set_header X-Real-IP $remote_addr;
	proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
```

---

<div class="post-metadata">

### Author: ![YosefAdPro](https://community.zammad.org/user_avatar/community.zammad.org/yosefadpro/32/1670_2.png) [@YosefAdPro](https://community.zammad.org/u/YosefAdPro)
#### Post date: [December 4, 2019, 2:09am UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/19 "2019-12-04T02:09:43Z")

</div>

Hi,

i have same problem on my Centos 7 + NGINX after update from 3.1 to 3.2.  
CSRF token verification failed.  
🧐

---

<div class="post-metadata">

### Author: ![MrGeneration](https://community.zammad.org/user_avatar/community.zammad.org/mrgeneration/32/9260_2.png) [@MrGeneration](https://community.zammad.org/u/MrGeneration)
#### Post date: [December 4, 2019, 7:43am UTC](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080/20 "2019-12-04T07:43:11Z")

</div>

> [@YosefAdPro](#):
>
> i have same problem on my Centos 7 + NGINX after update from 3.1 to 3.2.  
> CSRF token verification failed.

Please have a look at the above commends from other users with nginx. 🙂

> [@cornelinux](#):
>
> I also run an update on Ubuntu from 3.1 to 3.2 and experience the same issue.  
> With nginx adding
> 
> ```auto
> proxy_set_header X-Forwarded-Proto https;
> 
> ```
> 
> in the `location /` worked out for me.

> [@herzkerl](#):
>
> Thank you very much—that worked for me as well.
> 
> I have changed
> 
> ```auto
> proxy_set_header X-Forwarded-Proto $scheme;
> 
> ```
> 
> to
> 
> ```auto
> proxy_set_header X-Forwarded-Proto https;
> 
> ```
> 
> and that did it. Also, I wanted to share with the community the nginx config from the Plesk host (which is used only to forward the hostname/subdomain to the internal/NAT ip)—maybe it’ll be of any help for someone else…
> 
> ```auto
> location ~ ^/(?!(.well-known)) {
> proxy_pass http://<ip>:80;
> proxy_set_header Host $http_host;
> proxy_set_header CLIENT_IP $remote_addr;
> proxy_set_header X-Real-IP $remote_addr;
> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
> }
> 
> ```

[Next page](https://community.zammad.org/t/fresh-install-3-2-x-csrf-token-verification-failed/3080.md?page=2)
