# Device not decommissioned when all auth sets are dismissed

**URL:** <https://hub.mender.io/t/device-not-decommissioned-when-all-auth-sets-are-dismissed/2856>\
**Category:** General Discussions\
**Created:** [November 19, 2020, 1:48am UTC](https://hub.mender.io/t/device-not-decommissioned-when-all-auth-sets-are-dismissed/2856 "2020-11-19T01:48:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![msaenger](https://avatars.discourse-cdn.com/v4/letter/m/4da419/32.png) [@msaenger](https://hub.mender.io/u/msaenger)\
**Post date:** [November 19, 2020, 1:48am UTC](https://hub.mender.io/t/device-not-decommissioned-when-all-auth-sets-are-dismissed/2856/1 "2020-11-19T01:48:59Z")

</div>

I entered a strange state while experimenting with preauthorization and was hoping someone could confirm if this is intended behavior.

I had an already authorized device with one auth set and instead of decommissioning the device, I dismissed the one auth set which then removed the device from the device list. I just assumed that the device was automatically decommissioned since there were no more auth sets left, but I was wrong…

When I tried to preauthorize the device again I kept getting errors saying the device was already authed (409 return codes) but I couldn’t find any mention of it anywhere. Finally I thought maybe I should do an auth request to get it to pending state, accept it, then explicitly decommission it which did the trick and actually removed all device data from the server.

If this isn’t a bug, then at least there should be some reference to a device that still is tracked on the server even if it has no auth sets anymore.

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [November 19, 2020, 9:29am UTC](https://hub.mender.io/t/device-not-decommissioned-when-all-auth-sets-are-dismissed/2856/2 "2020-11-19T09:29:42Z")

</div>

Which server version are you running?

I know that there have been some bugs which might be related to this. @mzedel @tranchitella probably know more.

---

<div class="post-metadata">

**Author:** ![msaenger](https://avatars.discourse-cdn.com/v4/letter/m/4da419/32.png) [@msaenger](https://hub.mender.io/u/msaenger)\
**Post date:** [November 19, 2020, 4:57pm UTC](https://hub.mender.io/t/device-not-decommissioned-when-all-auth-sets-are-dismissed/2856/3 "2020-11-19T16:57:28Z")

</div>

I’m using the hosted version, so I assume the latest?

If I get into a buggy state, what’s the best way to get things back to normal? Through the REST API?

---

<div class="post-metadata">

**Author:** ![msaenger](https://avatars.discourse-cdn.com/v4/letter/m/4da419/32.png) [@msaenger](https://hub.mender.io/u/msaenger)\
**Post date:** [November 19, 2020, 5:08pm UTC](https://hub.mender.io/t/device-not-decommissioned-when-all-auth-sets-are-dismissed/2856/4 "2020-11-19T17:08:05Z")

</div>

Also related question, I somehow got some of my pending devices into a status of `Noauth` and whenever I click on the device I get an immediate error on the server. So, I can’t remove them. I’m going to see if I can remove with the API but any advice?

---

<div class="post-metadata">

**Author:** ![msaenger](https://avatars.discourse-cdn.com/v4/letter/m/4da419/32.png) [@msaenger](https://hub.mender.io/u/msaenger)\
**Post date:** [November 19, 2020, 5:27pm UTC](https://hub.mender.io/t/device-not-decommissioned-when-all-auth-sets-are-dismissed/2856/5 "2020-11-19T17:27:15Z")

</div>

Answering my own question. I was able to see the `noauth` devices using the REST API and removed them that way.

Last remaining weird thing is I’m seeing an incorrect number of deployments in the dashboard tab. It shows 107 active and pending deployments but in reality there are zero of each.

---

<div class="post-metadata">

**Author:** ![mzedel](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mzedel/32/261_2.png) [@mzedel](https://hub.mender.io/u/mzedel)\
**Post date:** [November 19, 2020, 10:12pm UTC](https://hub.mender.io/t/device-not-decommissioned-when-all-auth-sets-are-dismissed/2856/6 "2020-11-19T22:12:58Z")

</div>

Hello @msaenger,  
the `noauth` state is rather interesting and I would agree that this should be easier to see/ solve… we’ll find a way to surface these or prevent them from being possible altogether. Thanks to your description that should be easily reproducible and thus easier to fix :).

The faulty deployment number is unfortunately an unwanted side effect of our latest rollout and [the corresponding fix](https://github.com/mendersoftware/gui/pull/1069) should land in production shortly.

---

<div class="post-metadata">

**Author:** ![msaenger](https://avatars.discourse-cdn.com/v4/letter/m/4da419/32.png) [@msaenger](https://hub.mender.io/u/msaenger)\
**Post date:** [November 20, 2020, 1:50am UTC](https://hub.mender.io/t/device-not-decommissioned-when-all-auth-sets-are-dismissed/2856/7 "2020-11-20T01:50:39Z")

</div>

Thanks for the update, @mzedel!

I’m not quite sure exactly how I got into a `noauth` state, but I was doing a lot of experimenting with preauthorization and using different types of identity data. One further piece of information for you if it helps: the server showed two `noauth` devices but when I went to list the devices with the API there were 4 or 5 in that state.
