# Device Auth API Post Help

**URL:** <https://hub.mender.io/t/device-auth-api-post-help/1486>\
**Category:** General Discussions\
**Tags:** api\
**Created:** [January 30, 2020, 11:55pm UTC](https://hub.mender.io/t/device-auth-api-post-help/1486 "2020-01-30T23:55:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ikkysleepy](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ikkysleepy/32/156_2.png) [@ikkysleepy](https://hub.mender.io/u/ikkysleepy)\
**Post date:** [January 30, 2020, 11:55pm UTC](https://hub.mender.io/t/device-auth-api-post-help/1486/1 "2020-01-30T23:55:27Z")

</div>

I am using this guide,[Device authentication | Mender documentation](https://docs.mender.io/1.3/apis/device-apis/device-authentication#auth_requests-post), to get this to work but I am having difficulty.

I am able to get the X-MEN-signature by following these steps:

1. Generate Public key from deviceauth, openssl rsa -in private.key -pubout -out pubkey.pem
2. Sign and output to SHA256, openssl dgst -sha256 -sign private.key -out request.sha256 request.txt
3. Use Base64 to output the results, openssl base64 -in request.sha256 -out request.signature.sha256

I call the request via a ARC chrome add on and I get the following message:

> {
> 
> “error”: “signature verification failed”,
> 
> “request\_id”: “3ae482d5-e25f-4b53-a8e2-d78c72c8be8d”
> 
> }

The documentation says to use the The device’s public key, generated by the device or pre-provisioned by the vendor, but I am not sure what private / public key pair to use. Also, the documentation has the json object malformatted, which is odd.

Thanks,  
– Jorge

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [January 31, 2020, 9:20am UTC](https://hub.mender.io/t/device-auth-api-post-help/1486/2 "2020-01-31T09:20:34Z")

</div>

This tutorial might be helpful,

> [@How to write a custom client interfacing a Mender server](https://hub.mender.io/t/how-to-write-a-custom-client-interfacing-a-mender-server/1353):
>
> Introduction Mender is an end-to-end OTA solution and both the Mender [client](https://github.com/mendersoftware/mender) and [server](https://github.com/mendersoftware/integration) are provided as open-source, additional we provide reference board integrations that bind it all together. But Mender was designed with interchangeability in mind, especially for the client part of the solution. We provide [documentation](https://docs.mender.io/api/#device-apis) for the device facing API’s of the server which are implemented by the Mender client, but it is also a reference for implementing or integrating thirdparty clients. These re…

---

<div class="post-metadata">

**Author:** ![ikkysleepy](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ikkysleepy/32/156_2.png) [@ikkysleepy](https://hub.mender.io/u/ikkysleepy)\
**Post date:** [February 13, 2020, 9:26pm UTC](https://hub.mender.io/t/device-auth-api-post-help/1486/3 "2020-02-13T21:26:28Z")

</div>

Thanks for the help. I was able to get the custom fields working. I can’t filter by custom fields but maybe that will be fixed in the UI later? I also see now that I have two Authorization public keys and only one of them can be active at a time. So yes, I can update and add custom field names but I can not update the firmware unless I switch back to the previous Authorization public key set. Is this being addressed in the future or just something that we have to be aware of? Is there anyway we can update the device custom fields from an administrator account? I tried to use the API for getting the devices but I get a 404 Not found for “api/management/v1/admission/devices”.

```
 curl -k -H "Content-Type: application/json" -H "Authorization: Bearer $JWT" ${MENDER_SERVER_URL}/api/management/v1/admission/devices
<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>openresty/1.13.6.2</center>
</body>

```

Also using the JWT I get the following 401 error:  
curl -k -H "Authorization: Bearer {JWT}" {MENDER\_SERVER\_URL}/api/management/v1/inventory/devices  
  
401 Authorization Required

# 401 Authorization Required
  

* * *
openresty/1.13.6.2  
  

I could use the JWT token to update the curl-client device so the token is working. I’ll try and update the docker UI, as it’s in 2.2.1 , to see if it helps.

Thanks,  
– Jorge

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [February 14, 2020, 8:56am UTC](https://hub.mender.io/t/device-auth-api-post-help/1486/4 "2020-02-14T08:56:40Z")

</div>

> [@ikkysleepy](#):
>
> So yes, I can update and add custom field names but I can not update the firmware unless I switch back to the previous Authorization public key set. Is this being addressed in the future or just something that we have to be aware of?

You should be able manage the authentication sets of the device under the “Device” tab in the GUI.

 ![Screenshot_2020-02-14_09-54-15](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/1X/6509ae652e2ec7e3cc1f15a4c78295a364f94219.png)

> I tried to use the API for getting the devices but I get a 404 Not found for “api/management/v1/admission/devices”.

This does not seem to be a valid endpoint, can you try with /api/management/v2/devauth/devices ?

---

<div class="post-metadata">

**Author:** ![ikkysleepy](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ikkysleepy/32/156_2.png) [@ikkysleepy](https://hub.mender.io/u/ikkysleepy)\
**Post date:** [February 14, 2020, 7:20pm UTC](https://hub.mender.io/t/device-auth-api-post-help/1486/5 "2020-02-14T19:20:17Z")

</div>

> [@mirzak](#):
>
> You should be able manage the authentication sets of the device under the “Device” tab in the GUI.

I see both sets, the question is why can’t the device download the firmware when the device auth set is being used? Is that just as designed or is this going to change in the future?

> [@mirzak](#):
>
> This does not seem to be a valid endpoint, can you try with /api/management/v2/devauth/devices ?

I still get the same error, this url works:  
/api/devices/v1/deployments/device/deployments/next?artifact\_name=2020.02.13&device\_type=raspberrypi4

but not the one you pointed me to, I still get 401 Authorization Required.

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [February 17, 2020, 8:17am UTC](https://hub.mender.io/t/device-auth-api-post-help/1486/6 "2020-02-17T08:17:01Z")

</div>

> [@ikkysleepy](#):
>
> I see both sets, the question is why can’t the device download the firmware when the device auth set is being used? Is that just as designed or is this going to change in the future?

It is by design, only one authset can be valid at any given time and if your device has two authsets, you probably need to authorize the “new” set and “discard” the old one to give the device access.

Typically the authset of a device should not change trough out the lifecycle, unless you rotate the keys on the device.

> /api/management/v2/devauth/devices

This is a management API and there is a different authorization workflow for this, compared to the /api/devices/…

To access the managment API you need to login, using [https://docs.mender.io/2.2/apis/open-source/management-apis/user-administration-and-authentication#auth-login-post](https://docs.mender.io/2.2/apis/open-source/management-apis/user-administration-and-authentication#auth-login-post).

But accessing the management API is typically not something that you would do from a device, and instead is instead for 3rd-party services on the server side of things.

---

<div class="post-metadata">

**Author:** ![ikkysleepy](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ikkysleepy/32/156_2.png) [@ikkysleepy](https://hub.mender.io/u/ikkysleepy)\
**Post date:** [February 18, 2020, 1:15am UTC](https://hub.mender.io/t/device-auth-api-post-help/1486/7 "2020-02-18T01:15:18Z")

</div>

> [@mirzak](#):
>
> It is by design, only one authset can be valid at any given time and if your device has two authsets, you probably need to authorize the “new” set and “discard” the old one to give the device access.

Ok, so I found the mender-agent private key, which was located in `/data/mender/mender-agent.pem` and I am using that. That seems to work as expected. Here is the summary:

Using New Auth Set from Device

- Can Change Fields
- Can not Update firmware

Using Mender-Agent Auth Set

- Can Change Fields
- Can Update firmware

Based on the link you gave me I thought I had to create my own device auth set, in this case I do not want to do this. Using the mender-agent auth set will work to get the JWT and to add the new fields.

> [@mirzak](#):
>
> To access the managment API you need to login, using [https://docs.mender.io/2.2/apis/open-source/management-apis/user-administration-and-authentication#auth-login-post](https://docs.mender.io/2.2/apis/open-source/management-apis/user-administration-and-authentication#auth-login-post).

I was able to login using basic authb but I did not find any PUT methods that I could update the device attributes. It seems that the only way to update the device attributes is using the device attribute put method, is that correct?

Thanks for your help.
