# Mender \<\> AWS IoT Core Integration- Private Key issues

**URL:** <https://hub.mender.io/t/mender-aws-iot-core-integration-private-key-issues/7122>\
**Category:** General Discussions\
**Tags:** mender-client, aws-iot-core-integration\
**Created:** [August 20, 2024, 12:12pm UTC](https://hub.mender.io/t/mender-aws-iot-core-integration-private-key-issues/7122 "2024-08-20T12:12:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vimoxshah](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/vimoxshah/32/2406_2.png) [@vimoxshah](https://hub.mender.io/u/vimoxshah)\
**Post date:** [August 20, 2024, 12:12pm UTC](https://hub.mender.io/t/mender-aws-iot-core-integration-private-key-issues/7122/1 "2024-08-20T12:12:55Z")

</div>

I’m testing out AWS IoT Core integration and when I try read the private key that is issued by Mender I am getting errors. The private key I’m testing can be found in the mender-configure area on the device or in the mender web panel under the device variables.  
I found out that the keys provided through mender-configure are ECC 256 bits keys. For some unknown reason, openssl doesn’t like that the header is `-----BEGIN PRIVATE KEY-----` (I suppose it thinks it should be a PKCS#8 key).

Why mender-configure generate ECC 256 bit keys? can we generate the header like `-----BEGIN EC PRIVATE KEY-----` using mender-configure?

---

<div class="post-metadata">

**Author:** ![vimoxshah](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/vimoxshah/32/2406_2.png) [@vimoxshah](https://hub.mender.io/u/vimoxshah)\
**Post date:** [September 2, 2024, 7:41am UTC](https://hub.mender.io/t/mender-aws-iot-core-integration-private-key-issues/7122/2 "2024-09-02T07:41:15Z")

</div>

HI @TheYoctoJester can you please help on this question?

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [September 3, 2024, 7:12am UTC](https://hub.mender.io/t/mender-aws-iot-core-integration-private-key-issues/7122/3 "2024-09-03T07:12:54Z")

</div>

Hello @vimoxshah 👋

I’m sorry, I was handling the issue and forgot to update you about the status. Indeed, what you’re pointing out is [a bug](https://northerntech.atlassian.net/browse/MEN-7478). The key is serialized as SEC 1 (RFC-5915), but it uses PKCS#8 PEM headers. I implemented [a fix](https://github.com/mendersoftware/iot-manager/pull/298) to consistently use PKCS#8 format for the key issued for the device.
