# Download\_Error script is not run if artifact signature is invalid

**URL:** <https://hub.mender.io/t/download-error-script-is-not-run-if-artifact-signature-is-invalid/5684>\
**Category:** General Discussions\
**Created:** [March 15, 2023, 12:27pm UTC](https://hub.mender.io/t/download-error-script-is-not-run-if-artifact-signature-is-invalid/5684 "2023-03-15T12:27:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fdub](https://avatars.discourse-cdn.com/v4/letter/f/8dc957/32.png) [@fdub](https://hub.mender.io/u/fdub)\
**Post date:** [March 15, 2023, 12:27pm UTC](https://hub.mender.io/t/download-error-script-is-not-run-if-artifact-signature-is-invalid/5684/1 "2023-03-15T12:27:40Z")

</div>

Hi there,

In our product, we track the progress of Mender updates using state scripts that notify our software about a state change. In one situation, however, this approach does not work. If the artifact has an invalid signature (not verifiable with artifact-verify-key), Mender client does not run the Download\_Error script but changes to Idle immediately.

```auto
time="2023-03-10T16:33:03Z" level=info msg="State transition: update-check [Sync] -> update-fetch [Download_Enter]"
time="2023-03-10T16:33:03Z" level=info msg="Executing script: Download_Enter_10_Report"
time="2023-03-10T16:33:03Z" level=info msg="Running Mender client version: 3.1.0"
time="2023-03-10T16:33:03Z" level=info msg="State transition: update-fetch [Download_Enter] -> update-store [Download_Enter]"
time="2023-03-10T16:33:03Z" level=error msg="Fetching Artifact headers failed: installer: failed to read Artifact: readHeaderV3: reader: invalid signature: crypto/rsa: verification error"
time="2023-03-10T16:33:03Z" level=info msg="State transition: update-store [Download_Enter] -> update-status-report [none]"
time="2023-03-10T16:33:03Z" level=info msg="State transition: update-status-report [none] -> idle [Idle]"

```

Is it a bug in Mender client or is this behavior intended? Is there a way for our software to be notified of such a condition?

We are using Mender client 3.1.0 (it seems that this behavior has not changed since).

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![Alan](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@Alan](https://hub.mender.io/u/Alan)\
**Post date:** [March 16, 2023, 8:57am UTC](https://hub.mender.io/t/download-error-script-is-not-run-if-artifact-signature-is-invalid/5684/2 "2023-03-16T08:57:04Z")

</div>

Hi,  
I have to reproduce it but if this turns to be the case it does look like a bug.  
Do please note that `3.1` is not supported and I will be testing this on an [LTS](https://docs.mender.io/release-information/release-schedule) instead.

Cheers

---

<div class="post-metadata">

**Author:** ![Alan](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@Alan](https://hub.mender.io/u/Alan)\
**Post date:** [March 20, 2023, 1:21pm UTC](https://hub.mender.io/t/download-error-script-is-not-run-if-artifact-signature-is-invalid/5684/3 "2023-03-20T13:21:50Z")

</div>

Hi,  
I’ve reproduced the issue and created a ticket about it.  
You can track the progress here: [[MEN-6402] - Mender and CFEngine (by Northern.tech) Jira](https://northerntech.atlassian.net/browse/MEN-6402)

Regards,
