# Mender artifact signing issue - no key for verification provided

**URL:** <https://hub.mender.io/t/mender-artifact-signing-issue-no-key-for-verification-provided/6335>\
**Category:** General Discussions\
**Tags:** mender-artifact, signature-artifacts\
**Created:** [November 14, 2023, 10:01am UTC](https://hub.mender.io/t/mender-artifact-signing-issue-no-key-for-verification-provided/6335 "2023-11-14T10:01:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmitrijsan](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dmitrijsan/32/1942_2.png) [@dmitrijsan](https://hub.mender.io/u/dmitrijsan)\
**Post date:** [November 14, 2023, 10:01am UTC](https://hub.mender.io/t/mender-artifact-signing-issue-no-key-for-verification-provided/6335/1 "2023-11-14T10:01:41Z")

</div>

Hello guys,

As per one of my previous issues, I have decided to use `mender-configure` addon via generating artifacts for the update module manually ([link](https://hub.mender.io/t/adding-state-scripts-to-mender-configure-artifacts-generated-via-gui/6305/2)). This allowed me to enable artifact signing.

I have managed to successfully generate public/private key pair. However, I am a bit confused with the output I am seeing after running `mender-artifact` and specifying the key path (I used output form [this topics message](https://hub.mender.io/t/problem-with-the-signature-of-medner-artifact/1052/5) as the source of truth). I am seeing the following:

```auto
Mender artifact:
  Name: artifact_name
  Format: mender
  Version: 3
  Signature: signed but no key for verification provided; please use `-k` option for providing verification key
  Compatible devices: '[raspberrypi3]'
  Provides group: 
  Depends on one of artifact(s): []
  Depends on one of group(s): []
  State scripts:

Updates:
    0:
    Type: mender-configure
    Provides:
	data-partition.mender-configure.version: v4.0.0
    Depends: Nothing
    Clears Provides: ["data-partition.mender-configure.*"]
    Metadata:
	{
	  "test": "a"
	}
    Files: None

```

I am a bit worried about following line:  
`Signature: signed but no key for verification provided; please use `-k` option for providing verification key`

The command I run was:

```auto
mender-artifact write module-image \
    -T mender-configure \
    --artifact-name "artifact_name" \
    --device-type raspberrypi3 \
    --output-path artifact.mender \
    --software-filesystem data-partition \
    --software-version "v4.0.0" \
    --meta-data test.json \
    --key private_v1.key

```

I have tried validating the artifact as per the docs, using `mender-artifact validate` and am getting following output:

```auto
Artifact file 'artifact.mender' validated successfully

```

However, this still does not fix the signature issue. I have tried overwriting the signature with `mender-artifact sign` and setting `-f` flag - results are still the same. Afterwards, I have tried generating an artifact without a signature and then signing it separately, but it leads to the same notice about absent signature verification. Moreover, I have tried various update modules and all of them lead to the same issue of non-existing signature verification.

I have exhausted options to try and cannot seem to find the cause of the issue. Do I need to worry about the issue I am seeing? If so, any ideas on the way to fix it?

PS mender-artifact version - 3.10.1

---

<div class="post-metadata">

**Author:** ![kacf](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/kacf/32/146_2.png) [@kacf](https://hub.mender.io/u/kacf)\
**Post date:** [November 14, 2023, 11:34am UTC](https://hub.mender.io/t/mender-artifact-signing-issue-no-key-for-verification-provided/6335/2 "2023-11-14T11:34:46Z")

</div>

It looks signed correctly. You need a different key when verifying the artifact. Use `mender-artifact read -k <PATH>` and specify the public key. This should be the same key that you install on the device.

---

<div class="post-metadata">

**Author:** ![dmitrijsan](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dmitrijsan/32/1942_2.png) [@dmitrijsan](https://hub.mender.io/u/dmitrijsan)\
**Post date:** [November 14, 2023, 11:46am UTC](https://hub.mender.io/t/mender-artifact-signing-issue-no-key-for-verification-provided/6335/3 "2023-11-14T11:46:23Z")

</div>

Oh… I see, I need to provide it with a public key for it to check against it (aka the key that will be stored on destination devices running mender-client). That makes perfect sense now. I thought it was not happy with me during `mender-artifact write` step. After specifying the public key during `mender-artifact read` step, I am receiving the expected output:

```auto
Mender artifact:
  Name: artifact_name
  Format: mender
  Version: 3
  Signature: signed and verified correctly
  Compatible devices: '[raspberrypi3]'
  Provides group: 
  Depends on one of artifact(s): []
  Depends on one of group(s): []
  State scripts:

Updates:
    0:
    Type: mender-configure
    Provides:
	data-partition.mender-configure.version: v4.0.0
    Depends: Nothing
    Clears Provides: ["data-partition.mender-configure.*"]
    Metadata:
	{
	  "test": "a"
	}
    Files: None

```

So, there is no explicit verification written at this stage. It just verifies whether private and public keys are matching. I think I got it. Thanks for a prompt response. Marking your answer as a solution.

LE

Full command should look like this: `mender-artifact read -k <PATH_TO_PUBLIC_KEY> <PATH_TO_ARTIFACT>`
