# How to Preauthorize the device

**URL:** <https://hub.mender.io/t/how-to-preauthorize-the-device/2235>\
**Category:** General Discussions\
**Created:** [July 27, 2020, 5:21am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235 "2020-07-27T05:21:58Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 5:21am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/1 "2020-07-27T05:21:58Z")

</div>

Hi,

I’m following this doc [https://docs.mender.io/hosted/server-integration/preauthorizing-devices](https://docs.mender.io/hosted/server-integration/preauthorizing-devices) , but then again here it uses the device ID to generate the key. In my scenario, the mender client is installed and device isn’t accessed through internet at all, So How do I get the devID.

Is there a way to generate device ID also for preauth

---

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 7:57am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/2 "2020-07-27T07:57:14Z")

</div>

@kacf @drewmoseley

Hi there,  
How is device ID generated, or where is it stored in mender client? It will be super useful to knw this now.

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [July 27, 2020, 8:05am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/3 "2020-07-27T08:05:07Z")

</div>

Hi,

The device’s identity (not to be confused with the Mender generated UUID) can practically be an arbitrary serialized JSON object (with string-type key/value pairs). However, the Mender client typically uses the mac address returned by a script on the device located at `/usr/share/mender/identity/mender-device-identity` by default.  
You can also take a look at the [API docs](https://docs.mender.io/hosted/apis/enterprise/management-apis/device-authentication#devices-post) for a more detailed description of the request parameters.

---

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 8:09am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/4 "2020-07-27T08:09:01Z")

</div>

Hi @alfrunes,

Basically, I want to Preauthorize the device, But according to this [https://docs.mender.io/hosted/server-integration/preauthorizing-devices#the-identity-of-your-device](https://docs.mender.io/hosted/server-integration/preauthorizing-devices#the-identity-of-your-device), Ill need the device ID which is acquired only after Mender-client getting first hit to the server.

But In my case, there won’t be a internet access to the device until it reaches the customers hand, Thats why I was thinking how to get that device ID from mender client, so taht i can use it and then further carry on with [https://docs.mender.io/hosted/server-integration/preauthorizing-devices#the-identity-of-your-device](https://docs.mender.io/hosted/server-integration/preauthorizing-devices#the-identity-of-your-device) preauthorizing it.

I’m talking about this value:  
 ![image](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/1X/af7a331cc741f04e6ca2fc67249d2c7b0f7d2fc1.png)

Or is there any other way to Preauthorize without device id?

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [July 27, 2020, 8:31am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/5 "2020-07-27T08:31:29Z")

</div>

> [@nishad1092](#):
>
> Or is there any other way to Preauthorize without device id?

You do not use the “Device ID” which is showed above for pre-authorization. This is just something that is generated on the server the first time the device connects.

The “Device ID” is generated based on a unique pair of a device identity value(s) + a public key. You can read more about this here,

[https://docs.mender.io/hosted/overview/identity](https://docs.mender.io/hosted/overview/identity)

E.g the default is to use the MAC address of the first network interface as a unique identifier and is what you would input in the pre-authorization fields.

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [July 27, 2020, 8:39am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/6 "2020-07-27T08:39:45Z")

</div>

I can see how this section of the docs can look confusing as it makes the assumption in the prerequisites that the device already has a network connection. For pre-authorizing a device, all you need is the device’s identity (e.g. `{"mac": "00:00:00:00"}`) and the public key, the device ID (UUID) will be generated once the device connects for the first time.  
For example, a pre-auth curl request may look something like:  
`curl https://hosted.mender.io/api/management/v2/devauth/devices -H "Content-Type: application/json" -H "Authorization: Bearer **JWT token returned by /login**" -d '{"identity_data": {"mac": "00:00:00:00"}, "pubkey": " **PUBLIC PEM BYTES GOES HERE**"}'`

---

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 9:07am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/8 "2020-07-27T09:07:24Z")

</div>

What abt the mac address ? Can I give 00:00:00:00 ? Will it be updated after the device is authorized and populated with other details?

---

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 9:29am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/9 "2020-07-27T09:29:47Z")

</div>

Hi @alfrunes,

I tried the pre-curl request u sent here.

But It is giving this :::

404 Not Found
# 404 Not Found

* * *
openresty/1.13.6.2 curl: (3) Port number ended with '"' curl: (6) Could not resolve host: pubkey curl: (3) [globbing] unmatched close brace/bracket in column 573

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [July 27, 2020, 9:40am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/10 "2020-07-27T09:40:54Z")

</div>

I’m sorry, I forgot to enclose the `-d` parameter to curl with single quotes. I updated the comment, could you please try again?

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [July 27, 2020, 9:43am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/11 "2020-07-27T09:43:11Z")

</div>

You need to give the mac of the device you want to pre-authorize. If Mender is installed correctly on the device you can run the script located in `/usr/share/mender/identity/mender-device-identity` to get the mac address for the correct network interface.

---

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 9:50am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/12 "2020-07-27T09:50:31Z")

</div>

Ok sure, So if mac isn’t same as the devices mac, it wont preauth and connect to server?

curl request is giving me issues, so Im following this API instead  
[https://docs.mender.io/2.4/apis/open-source/management-apis/device-authentication](https://docs.mender.io/2.4/apis/open-source/management-apis/device-authentication)

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [July 27, 2020, 9:54am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/13 "2020-07-27T09:54:11Z")

</div>

> [@nishad1092](#):
>
> So if mac isn’t same as the devices mac, it wont preauth and connect to server?

Correct! If the mac (or identity data) does not match, the device will get `401 Unauthorized` response from the server.

---

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 10:05am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/14 "2020-07-27T10:05:05Z")

</div>

OK sure, Ill get on with that.

But then @alfrunes, I’m using that POST method, and it is executed fine, but the device is coming in the GUI as pending request.

Do I need to add public key and key set in the Mender server “preauthorized” section too??

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [July 27, 2020, 10:08am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/15 "2020-07-27T10:08:26Z")

</div>

> [@nishad1092](#):
>
> curl request is giving me issues

I corrected another error in the request body and verified that it works. Sorry - I should’ve done that to begin with.

---

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 10:32am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/16 "2020-07-27T10:32:56Z")

</div>

Hi @alfrunes,

Im still trying, Device gets status: “accepted” from that POST request for Pre-Auth, but for some reason it is getting to pending, I added publickey and key sets to Preauthorized section too,.

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [July 27, 2020, 11:03am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/17 "2020-07-27T11:03:45Z")

</div>

> [@nishad1092](#):
>
> Im still trying, Device gets status: “accepted” from that POST request for Pre-Auth, but for some reason it is getting to pending

Sorry to hear that.  
Is the device appearing both as both pending and pre-authorized? If so, can you check if the Device Identity of the two devices are matching?

---

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 11:15am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/18 "2020-07-27T11:15:44Z")

</div>

Both are different device ID.

FYI::  
Do you it is because of my Post Auth API to refresh the JWT token (POST, /api/management/v1/useradm/auth/login) , Do u think thats the reason? (But I kept this because JWT token expires in 7 days )

I have added this in my Preauth sec too in server,

 ![image](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/1X/5cae4bc65ed54b8ec7f5e063692077dca7209abc.png)

---

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 11:19am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/19 "2020-07-27T11:19:18Z")

</div>

Hi @alfrunes,

I’m using this initial parameter to config to the server:

SERVER\_URL=“[https://mender-server.com](https://mender-server.com)”  
SERVER\_CERT="/usr/share/doc/mender-client/examples/server.crt"  
sudo DEBIAN\_FRONTEND=noninteractive dpkg -i mender-client\_2.2.0-1\_arm64.deb  
sudo mender setup   
–device-type $DEVICE\_TYPE   
–server-url $SERVER\_URL   
–server-cert $SERVER\_CERT   
–inventory-poll 5   
–update-poll 5   
–retry-poll 30"""

Maybe because of this and the preauthorization, it is getting created with twice JWT token? If you think this is the issue, could you tell me how to combine these parameters with the preauth API.

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [July 27, 2020, 11:22am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/20 "2020-07-27T11:22:52Z")

</div>

I suspect that the Device Identity passed in the `identity_data` parameter to the [preauth request](https://docs.mender.io/2.4/apis/open-source/management-apis/device-authentication#devices-post) does not match the `id_data` in the [auth request](https://docs.mender.io/2.4/apis/open-source/device-apis/device-authentication#auth_requests-post) made from the device.  
Can you expand both devices in the UI and compare the Device Identity sections of the pending and pre-authorized devices?

---

<div class="post-metadata">

**Author:** ![nishad1092](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nishad1092](https://hub.mender.io/u/nishad1092)\
**Post date:** [July 27, 2020, 11:49am UTC](https://hub.mender.io/t/how-to-preauthorize-the-device/2235/21 "2020-07-27T11:49:35Z")

</div>

Actually, Now Im not able to check becuase Im having this in my mender status:  
r msg=“authorize failed: transient error: authorization request failed: (request\_id: ): authentication request rejected server error message: dev auth: unauthorized”

1. I tried restarting and reinstalling Mender. Still I guess there are “Mac” id of this device existing in the server.

I always run those parameters, and it connects to server in the “pending” state, Now, when this Pre-Auth process Is also been executed I guess two device ID for same mac id is created.

I think so, Isn’t this causing the issue? How do I combine both, because those parameters r giving me the role of adding server.crt and all.

[Next page](https://hub.mender.io/t/how-to-preauthorize-the-device/2235.md?page=2)
