# Vaultwarden docker logs tls handshake failed

**URL:** <https://vaultwarden.discourse.group/t/vaultwarden-docker-logs-tls-handshake-failed/1864>\
**Category:** Help\
**Created:** [September 8, 2022, 7:46am UTC](https://vaultwarden.discourse.group/t/vaultwarden-docker-logs-tls-handshake-failed/1864 "2022-09-08T07:46:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tom](https://avatars.discourse-cdn.com/v4/letter/t/3d9bf3/32.png) [@tom](https://vaultwarden.discourse.group/u/tom)\
**Post date:** [September 8, 2022, 7:46am UTC](https://vaultwarden.discourse.group/t/vaultwarden-docker-logs-tls-handshake-failed/1864/1 "2022-09-08T07:46:19Z")

</div>

Hey,

when i scroll trough my logs with docker logs i see many tls handshake errors. What do they exactly mean? Are they important? Is someone trying to do something nasty?

```auto
[2022-09-08 02:12:12.580][rustls::msgs::handshake][WARN] Illegal SNI hostname received [57, 53, 46, 49, 49, 52, 46, 49, 48, 52, 46, 49, 54, 52]
[2022-09-08 02:12:12.580][rustls::conn][WARN] Sending fatal alert DecodeError
[2022-09-08 02:12:12.581][rocket_http::tls::listener][WARN] tls handshake with removed_ip::35494 failed: received corrupt message of type Handshake
[2022-09-08 02:18:30.367][rocket_http::tls::listener][WARN] tls handshake with removed_ip:44602 failed: received corrupt message
[2022-09-08 02:18:30.540][rocket_http::tls::listener][WARN] tls handshake with removed_ip:44622 failed: tls handshake eof
[2022-09-08 02:49:04.019][rocket_http::tls::listener][WARN] tls handshake with removed_ip:65133 failed: received corrupt message
[2022-09-08 02:49:04.378][rocket_http::tls::listener][WARN] tls handshake with removed_ip:65165 failed: tls handshake eof
[2022-09-08 03:03:01.920][rocket_http::tls::listener][WARN] tls handshake with removed_ip:43280 failed: received corrupt message
[2022-09-08 03:09:51.840][rocket_http::tls::listener][WARN] tls handshake with removed_ip:45466 failed: received corrupt message
[2022-09-08 03:47:38.720][rocket_http::tls::listener][WARN] tls handshake with removed_ip:53434 failed: received corrupt message
[2022-09-08 03:47:39.018][rocket_http::tls::listener][WARN] tls handshake with removed_ip:53447 failed: tls handshake eof
[2022-09-08 04:19:22.069][rocket_http::tls::listener][WARN] tls handshake with removed_ip:60016 failed: received corrupt message
[2022-09-08 04:19:22.321][rocket_http::tls::listener][WARN] tls handshake with removed_ip:60032 failed: tls handshake eof
[2022-09-08 04:39:22.183][rocket_http::tls::listener][WARN] tls handshake with removed_ip:33078 failed: received corrupt message
[2022-09-08 04:39:22.238][rocket_http::tls::listener][WARN] tls handshake with removed_ip:33085 failed: tls handshake eof
[2022-09-08 05:00:57.800][rocket_http::tls::listener][WARN] tls handshake with removed_ip:45382 failed: received corrupt message
[2022-09-08 05:15:52.381][rocket_http::tls::listener][WARN] tls handshake with removed_ip:38750 failed: received corrupt message
[2022-09-08 05:34:11.700][rocket_http::tls::listener][WARN] tls handshake with removed_ip:56922 failed: received corrupt message

```

the removed ip’s are all different. Im using Lets Encrypt and my Certificate is fine.

Thanks!

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [September 8, 2022, 3:38pm UTC](https://vaultwarden.discourse.group/t/vaultwarden-docker-logs-tls-handshake-failed/1864/2 "2022-09-08T15:38:58Z")

</div>

Looks like drive by hack attempts on your IP address.  
We do suggest to use a reverse proxy in front of Vaultwarden to prevent issues like this. Also, websockets do not work without a reverse proxy unfortunately, so that is probably not working for you right now.

---

<div class="post-metadata">

**Author:** ![tom](https://avatars.discourse-cdn.com/v4/letter/t/3d9bf3/32.png) [@tom](https://vaultwarden.discourse.group/u/tom)\
**Post date:** [September 8, 2022, 4:07pm UTC](https://vaultwarden.discourse.group/t/vaultwarden-docker-logs-tls-handshake-failed/1864/3 "2022-09-08T16:07:21Z")

</div>

What would be the benefit of using a reverse proxy? How does that protect me from these attacks?

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [September 8, 2022, 4:55pm UTC](https://vaultwarden.discourse.group/t/vaultwarden-docker-logs-tls-handshake-failed/1864/4 "2022-09-08T16:55:25Z")

</div>

Well, for one, it will block invalid SNI’s. Has mostly better SSL support or at least more fault tolerance. And, as mentioned before, you are able to enable the websocket support, which isn’t possible without a reverse proxy
