# Mender client x509: certificate signed by unknown authority issue

**URL:** <https://hub.mender.io/t/mender-client-x509-certificate-signed-by-unknown-authority-issue/1174>\
**Category:** General Discussions\
**Tags:** preauthorization, demo-server\
**Created:** [October 23, 2019, 10:39am UTC](https://hub.mender.io/t/mender-client-x509-certificate-signed-by-unknown-authority-issue/1174 "2019-10-23T10:39:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shrulabh](https://avatars.discourse-cdn.com/v4/letter/s/74df32/32.png) [@Shrulabh](https://hub.mender.io/u/Shrulabh)\
**Post date:** [October 23, 2019, 10:39am UTC](https://hub.mender.io/t/mender-client-x509-certificate-signed-by-unknown-authority-issue/1174/1 "2019-10-23T10:39:00Z")

</div>

Hii everyone I am facing an issue with the preauthorization of raspberry pi3.  
The server.crt file in the server and the raspberryPi3 are the same but still, the device is stuck at the Mender demo server under Preauthorized devices. The identity data sent to the Mender server is the same as generated in the Raspberry Pi. The error generated by the mender is

`>level=error msg="authorize failed: transient error: authorization request failed: certificate signed by unknown authority: Post https://docker.mender.io/api/devices/v1/authentication/auth_requests: x509: certificate signed by unknown authority" module=stat `

What can be the other reasons this error occurs. Please help…!!

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [October 24, 2019, 7:13am UTC](https://hub.mender.io/t/mender-client-x509-certificate-signed-by-unknown-authority-issue/1174/2 "2019-10-24T07:13:47Z")

</div>

> [@Shrulabh](#):
>
> The server.crt file in the server and the raspberryPi3 are the same but still

What do you mean with this? `server.crt` is not supposed to be used for pre-authorization and there is a separate key par intended for this.

Take a look at,

[https://docs.mender.io/2.1/server-integration/preauthorizing-devices](https://docs.mender.io/2.1/server-integration/preauthorizing-devices)
