# Host validation error on deployment step

**URL:** <https://hub.mender.io/t/host-validation-error-on-deployment-step/3590>\
**Category:** General Discussions\
**Created:** [May 3, 2021, 9:13pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590 "2021-05-03T21:13:16Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![hancerli](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/hancerli/32/1185_2.png) [@hancerli](https://hub.mender.io/u/hancerli)\
**Post date:** [May 3, 2021, 9:13pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/1 "2021-05-03T21:13:16Z")

</div>

Hi there,

I successfully connect a custom device to a self-hosting Mender server but cannot deploy an update.

I already created the artifact by using mender-artifact and uploaded it to the server. After that, I started a deployment but the Mender client fires “Host validation error” when pulling the new update.

Here’s the full error code:

```
{"level":"error","message":"Update fetch failed: update fetch request failed: Get \"https://s3.docker.mender.io/mender-artifact-storage/ec1d9949-b5c2-4cd8-bb80-7c117cae3e2a?X-Amz-Algorithm=AWS4-HMAC-SHA256\u0026X-Amz-Credential=mender-deployments%2F20210503%2Fus-east-1%2Fs3%2Faws4_request\u0026X-Amz-Date=20210503T205359Z\u0026X-Amz-Expires=86400\u0026X-Amz-SignedHeaders=host\u0026response-content-type=application%2Fvnd.mender-artifact\u0026X-Amz-Signature=768fbfb9e80194494cf9283e9902e2fa1af83b9ec895761cb4e2f24dfe9b9abf\": Host validation error","timestamp":"2021-05-04T00:03:00+03:00"}

```

Any ideas?

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [May 4, 2021, 12:18am UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/2 "2021-05-04T00:18:17Z")

</div>

It sounds like a mismatch with server certificates or some such. Can you share the exact steps you took to:

1. Setup the server.
2. Configure the client device to run Mender.
3. Create the artifact.

Drew

---

<div class="post-metadata">

**Author:** ![hancerli](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/hancerli/32/1185_2.png) [@hancerli](https://hub.mender.io/u/hancerli)\
**Post date:** [May 4, 2021, 6:20am UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/3 "2021-05-04T06:20:06Z")

</div>

Hi there,

1. Exactly the same steps are written in the Mender production installation
2. As following

> DEVICE\_TYPE=“DEVTYPE”  
> SERVER\_URL=“[https://menderurl:4430](https://menderurl:4430)”  
> sudo DEBIAN\_FRONTEND=noninteractive dpkg -i mender-client\_2.6.0-1\_armhf.deb  
> sudo mender setup   
> –device-type $DEVICE\_TYPE   
> –server-url $SERVER\_URL   
> –server-cert=“/etc/myapp/inc/ssl/certs/server.crt”   
> –retry-poll 30  
> –update-poll 5   
> –inventory-poll 5

1. mender-artifact write module-image -t DEVTYPE -o FIRMWARE.mender -T FIRMWARE -n FIRMWARE -f FIRMWARE.fw

---

<div class="post-metadata">

**Author:** ![dellgreen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dellgreen/32/85_2.png) [@dellgreen](https://hub.mender.io/u/dellgreen)\
**Post date:** [May 4, 2021, 7:58am UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/4 "2021-05-04T07:58:01Z")

</div>

You mention it’s self hosted, however the storage URL for the artifacts which it’s complaining about is pointing to the [mender.io](http://mender.io) domain. Is this intentional?

---

<div class="post-metadata">

**Author:** ![hancerli](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/hancerli/32/1185_2.png) [@hancerli](https://hub.mender.io/u/hancerli)\
**Post date:** [May 4, 2021, 8:12am UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/5 "2021-05-04T08:12:50Z")

</div>

TBH, that’s the point where I got confused.

I didn’t set that domain (I suppose you’re referring to **[s3.docker.mender.io](http://s3.docker.mender.io)**) on the client device but instead set it when I was deploying the mender server. Here’s the configuration from Mender documentation:

> API\_GATEWAY\_DOMAIN\_NAME=" menderurl" # replace with your server’s public domain name  
> STORAGE\_PROXY\_DOMAIN\_NAME=“[s3.docker.mender.io](http://s3.docker.mender.io)” # change if you are using a different domain name than the default one

So, I believe the artifact URL is pushed from the server to the client when there’s a new deployment.

I also registered “**[s3.docker.mender.io](http://s3.docker.mender.io)**” and “ **menderurl** ” domains with the Mender Server IP in the hosts file of the client.

Plus, the client can resolve both domains without any issues.

Any points that I’m skipping?

---

<div class="post-metadata">

**Author:** ![dellgreen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dellgreen/32/85_2.png) [@dellgreen](https://hub.mender.io/u/dellgreen)\
**Post date:** [May 4, 2021, 8:37am UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/6 "2021-05-04T08:37:58Z")

</div>

That all sounds good so far. Does the server certificate contain both domains in it if you are using a single server with a single certificate?

---

<div class="post-metadata">

**Author:** ![dellgreen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dellgreen/32/85_2.png) [@dellgreen](https://hub.mender.io/u/dellgreen)\
**Post date:** [May 4, 2021, 8:44am UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/7 "2021-05-04T08:44:49Z")

</div>

At this point I would normally use openssl s\_client command line tool option to verify the entire certificate of trust chain for each domain.

[https://docs.pingidentity.com/bundle/solution-guides/page/iqs1569423823079.html](https://docs.pingidentity.com/bundle/solution-guides/page/iqs1569423823079.html)

---

<div class="post-metadata">

**Author:** ![hancerli](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/hancerli/32/1185_2.png) [@hancerli](https://hub.mender.io/u/hancerli)\
**Post date:** [May 4, 2021, 11:54am UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/8 "2021-05-04T11:54:46Z")

</div>

Hmm, I’m a bit new to those SSL sutff, but AFAIUI seems like only Mender server domain is included in the server-side certificate, but not **[s3.docker.mender.io](http://s3.docker.mender.io)**  
 ![image](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/2X/2/27f602ec343a745bf00b7c465d3547e1ab57922e.png)

So how to recreate that certificate on the server-side including minio domain?

– Edit –  
Should I use same domain name if minio and Mender instances are served on the same host? If that’ll decrease the complexity I can reinstall the Mender server.

---

<div class="post-metadata">

**Author:** ![hancerli](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/hancerli/32/1185_2.png) [@hancerli](https://hub.mender.io/u/hancerli)\
**Post date:** [May 4, 2021, 1:42pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/9 "2021-05-04T13:42:59Z")

</div>

I couldn’t wait and gave it a try :]

Got a backup of current SSL certificate folder and recreate the new ones by using:

```
CERT_API_CN=mender.myurl.com.foo CERT_STORAGE_CN=mender.myurl.com.foo ../keygen

```

And also updated prod conf file:

```
ALLOWED_HOSTS: mender.myurl.com.foo
DEPLOYMENTS_AWS_URI: https://mender.myurl.com.foo

```

Then copied related certificates to the client, decommissioned, and re-authorized it back again. However, now I’m getting another error on the client side;

> time=“2021-05-04T16:40:47+03:00” level=error msg=“Update check  
> failed: transient error: (request\_id: ): Invalid response received from server server error message: fai  
> led to parse server response: json: cannot unmarshal object into Go struct field .error of type string”

P.S.  
Client can successfully send inventory info.

---

<div class="post-metadata">

**Author:** ![dellgreen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dellgreen/32/85_2.png) [@dellgreen](https://hub.mender.io/u/dellgreen)\
**Post date:** [May 4, 2021, 1:44pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/10 "2021-05-04T13:44:12Z")

</div>

On my first deployment if i recall for simplicity I created a single certificate that had multiple domains in it and configured the mender server apt-gateway and storage-proxy to use the same certificate.

That was a few years ago now. In newer deployments i use separate certificates for both now and I am also my own certificate authority for issuing certificates to my servers. This affords greater flexibility at the cost of complexity.

Are you currently using a self-signed certificate then? if so when you create it you should be able to add multiple “Subject Alt names” for all the domains you use

---

<div class="post-metadata">

**Author:** ![hancerli](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/hancerli/32/1185_2.png) [@hancerli](https://hub.mender.io/u/hancerli)\
**Post date:** [May 4, 2021, 1:46pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/11 "2021-05-04T13:46:09Z")

</div>

Yes I’m self signing the certs (I suppose keygen app is self-signing the certs :)) ) and deploying them manually since the system is working in a closed network.

---

<div class="post-metadata">

**Author:** ![dellgreen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dellgreen/32/85_2.png) [@dellgreen](https://hub.mender.io/u/dellgreen)\
**Post date:** [May 4, 2021, 1:49pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/12 "2021-05-04T13:49:50Z")

</div>

Have you also updated the storage-proxy aliases section?

As for the client GO error, i wouldn’t move on to that problem until you can confirm on your mender client device passes openssl s\_client testing with your domains certificates trust chain

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [May 4, 2021, 1:55pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/13 "2021-05-04T13:55:37Z")

</div>

Using _[s3.docker.mender.io](http://s3.docker.mender.io)_ does seem strange to me. In [previous versions](https://docs.mender.io/2.6/server-installation/production-installation#certificates-and-keys) of the docs, that was specified as:

> STORAGE\_PROXY\_DOMAIN\_NAME=“$API\_GATEWAY\_DOMAIN\_NAME”

but in the 2.7 version it is specified literally:

> STORAGE\_PROXY\_DOMAIN\_NAME=“[s3.docker.mender.io](http://s3.docker.mender.io)”

I suspect we have an error in our automation setup for the docs. @oleorhagen, @mzedel, @kacf, can you guys comment on this?

Drew

---

<div class="post-metadata">

**Author:** ![hancerli](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/hancerli/32/1185_2.png) [@hancerli](https://hub.mender.io/u/hancerli)\
**Post date:** [May 4, 2021, 2:02pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/14 "2021-05-04T14:02:10Z")

</div>

> Have you also updated the storage-proxy aliases section?

Yes, it’s updated.

> As for the client GO error, i wouldn’t move on to that problem until you can confirm on your mender client device passes openssl s\_client testing with your domains certificates trust chain

Is that the result of test that you’re seeking for? (this is from the client-side)

 ![image](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/2X/1/1ce3c35e7e4ddfb968c5a84629aa262e691433d5.png)

And this is the cert I deployed to the client:  
 ![image](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/2X/b/bc58559d447d4181921646b452ec56b200cd56b0.png)

And this is a test curl command:

 ![image](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/2X/2/26ccc787e28401c0e0b7c91830cbad3300e65df1.png)

---

<div class="post-metadata">

**Author:** ![dellgreen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dellgreen/32/85_2.png) [@dellgreen](https://hub.mender.io/u/dellgreen)\
**Post date:** [May 4, 2021, 3:31pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/15 "2021-05-04T15:31:59Z")

</div>

looks ok so far. what about when you run openssl s\_client against your storage proxy domain?

---

<div class="post-metadata">

**Author:** ![hancerli](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/hancerli/32/1185_2.png) [@hancerli](https://hub.mender.io/u/hancerli)\
**Post date:** [May 4, 2021, 3:43pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/16 "2021-05-04T15:43:02Z")

</div>

api and sotorage domains are same right now, which is **mender.myurl.com.foo**

Here’s the prod conf I’m using:

> version: ‘2.1’  
> services:

```
mender-workflows-server:
    command: server --automigrate

mender-workflows-worker:
    command: worker --automigrate --excluded-workflows generate_artifact

mender-create-artifact-worker:
    command: --automigrate

mender-useradm:
    command: server --automigrate
    volumes:
        - ./production/keys-generated/keys/useradm/private.key:/etc/useradm/rsa/private.pem:ro
    logging:
        options:
            max-file: "10"
            max-size: "50m"

mender-device-auth:
    command: server --automigrate
    volumes:
        - ./production/keys-generated/keys/deviceauth/private.key:/etc/deviceauth/rsa/private.pem:ro
    logging:
        options:
            max-file: "10"
            max-size: "50m"

mender-inventory:
    command: server --automigrate
    logging:
        options:
            max-file: "10"
            max-size: "50m"

mender-api-gateway:
    ports:
        # list of ports API gateway is made available on
        - "4430:443"
    networks:
        mender:
            aliases:
                # mender-api-gateway is a proxy to storage
                # and has to use exactly the same name as devices
                # and the deployments service will;
                #
                # if devices and deployments will access storage
                # using https://s3.acme.org:9000, then
                # set this to https://s3.acme.org:9000
                - https://mender.myurl.com.foo
    command:
        - --accesslog=true
        - --providers.file.filename=/config/tls.toml
        - --providers.docker=true
        - --providers.docker.exposedbydefault=false
        - --entrypoints.http.address=:80
        - --entrypoints.https.address=:443
        - --entryPoints.https.transport.respondingTimeouts.idleTimeout=7200
        - --entryPoints.https.transport.respondingTimeouts.readTimeout=7200
        - --entryPoints.https.transport.respondingTimeouts.writeTimeout=7200
        - --entrypoints.http.http.redirections.entryPoint.to=https
        - --entrypoints.http.http.redirections.entryPoint.scheme=https
    volumes:
        - ./tls.toml:/config/tls.toml
        - ./production/keys-generated/certs/api-gateway/cert.crt:/certs/cert.crt:ro
        - ./production/keys-generated/certs/api-gateway/private.key:/certs/private.key:ro
        - ./production/keys-generated/certs/storage-proxy/cert.crt:/certs/s3.docker.mender.io.crt
        - ./production/keys-generated/certs/storage-proxy/private.key:/certs/s3.docker.mender.io.key
    logging:
        options:
            max-file: "10"
            max-size: "50m"
    environment:
        ALLOWED_HOSTS: mender.myurl.com.foo

mender-deployments:
    command: server --automigrate
    volumes:
        - ./production/keys-generated/certs/storage-proxy/cert.crt:/etc/ssl/certs/s3.docker.mender.io.crt:ro
    environment:
        STORAGE_BACKEND_CERT: /etc/ssl/certs/s3.docker.mender.io.crt
        # access key, the same value as MINIO_ACCESS_KEY
        DEPLOYMENTS_AWS_AUTH_KEY: mender-deployments
        # secret, the same valie as MINIO_SECRET_KEY
        DEPLOYMENTS_AWS_AUTH_SECRET: Kaengi3iel8thoh2

        # deployments service uses signed URLs, hence it needs to access
        # storage-proxy using exactly the same name as devices will; if
        # devices will access storage using https://s3.acme.org:9000, then
        # set this to https://s3.acme.org:9000
        DEPLOYMENTS_AWS_URI: https://mender.myurl.com.foo
    logging:
        options:
            max-file: "10"
            max-size: "50m"

minio:
    environment:
        # access key
        MINIO_ACCESS_KEY: mender-deployments
        # secret
        MINIO_SECRET_KEY: Kaengi3iel8thoh2
    volumes:
        # mounts a docker volume named `mender-artifacts` as /export directory
        - mender-artifacts:/export:rw

mender-mongo:
    volumes:
        - mender-db:/data/db:rw

volumes:
# mender artifacts storage
 mender-artifacts:
  external:
      # use external volume created manually
      name: mender-artifacts
# mongo service database
mender-db:
  external:
      # use external volume created manually
      name: mender-db

```

---

<div class="post-metadata">

**Author:** ![dellgreen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dellgreen/32/85_2.png) [@dellgreen](https://hub.mender.io/u/dellgreen)\
**Post date:** [May 4, 2021, 4:42pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/17 "2021-05-04T16:42:10Z")

</div>

In 2.7x branch it looks like the mender-api-gateway and storage-proxy nodes have merged into as single mender-api-gateway config. Its not immediately obvious to me how this new config works as i’m running a slightly older version of the server which has a separate storage-proxy config node running on a different port. I’ll have to defer this to @drewmoseley who probably knows why this config has changed in 2.7x and how its supposed to work now.

> <https://github.com/mendersoftware/integration/blob/master/production/config/prod.yml.template>

> <https://github.com/mendersoftware/integration/blob/2.6.x/production/config/prod.yml.template>

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [May 4, 2021, 5:11pm UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/18 "2021-05-04T17:11:28Z")

</div>

Hopefully @tranchitella can provide some insight here.

---

<div class="post-metadata">

**Author:** ![hancerli](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/hancerli/32/1185_2.png) [@hancerli](https://hub.mender.io/u/hancerli)\
**Post date:** [May 5, 2021, 6:59am UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/19 "2021-05-05T06:59:57Z")

</div>

I just found that the mender-deployment service is also throwing error messages.

> mender-deployments\_1 | time=“2021-05-05T06:54:59Z” level=error msg=“error reaching artifact storage service: SerializationError: failed to decode REST XML response\n\tstatus code: 200, request id: \ncaused by: XML syntax error on line 8: element closed by ” file=response\_helpers.go func=rest\_utils.restErrWithLogMsg line=110 request\_id=94914e75-a1b1-4a5b-8640-c335ed931174

---

<div class="post-metadata">

**Author:** ![hancerli](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/hancerli/32/1185_2.png) [@hancerli](https://hub.mender.io/u/hancerli)\
**Post date:** [May 5, 2021, 8:27am UTC](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590/20 "2021-05-05T08:27:27Z")

</div>

Found another odd behavior. When I send the following request;

> curl --cacert /path\_to\_cert/mender-server.crt [https://mender.myurl.com.tr:4430/api/devices/v1/deployments/device/deployments/next](https://mender.myurl.com.tr:4430/api/devices/v1/deployments/device/deployments/next)

The server sometimes replies with a proper response (for less then %10 of requests):

> {“error”:“no authorization header”,“request\_id”:“e3516fea-7ee1-4064-bd9a-b3eea0f4aa19”}

But sometimes the response is broken:

 ![image](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/2X/0/01d7dd78ea382685ea1f1fb57454acb5a6337892.png)

[Next page](https://hub.mender.io/t/host-validation-error-on-deployment-step/3590.md?page=2)
