# Mender server authorization error: demo.crt is missing in iMX 6UL EVK Yocto build

**URL:** <https://hub.mender.io/t/mender-server-authorization-error-demo-crt-is-missing-in-imx-6ul-evk-yocto-build/1981>\
**Category:** General Discussions\
**Tags:** yocto, demo-server, imx6ul-evk\
**Created:** [May 28, 2020, 2:22pm UTC](https://hub.mender.io/t/mender-server-authorization-error-demo-crt-is-missing-in-imx-6ul-evk-yocto-build/1981 "2020-05-28T14:22:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![danie](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/danie/32/620_2.png) [@danie](https://hub.mender.io/u/danie)\
**Post date:** [May 28, 2020, 2:22pm UTC](https://hub.mender.io/t/mender-server-authorization-error-demo-crt-is-missing-in-imx-6ul-evk-yocto-build/1981/1 "2020-05-28T14:22:17Z")

</div>

I’m using [mender demo server](https://docs.mender.io/2.3/getting-started/on-premise-installation/create-a-test-environment) with iMX 6UL EVK (manually integrated mender). After mender setup, I cannot connect to the demo server.

When I debug the issue I found that `/usr/share/doc/mender-client/examples/demo.crt` is missing. And hence I opted for manual certificate generation but I could not pull it off.

The error is as follows,

```auto
root@imx6ulevk:~# systemctl stop mender; systemctl start mender
root@imx6ulevk:~# journalctl -u mender | tail
May 28 09:14:17 imx6ulevk mender[1877]: time="2020-05-28T09:14:17Z" level=info msg="State transition: authorize [Sync] -> authorize-wait [Idle]" module=mender
May 28 09:14:46 imx6ulevk mender[1877]: time="2020-05-28T09:14:46Z" level=info msg="State transition: authorize-wait [Idle] -> authorize [Sync]" module=mender
May 28 09:14:47 imx6ulevk mender[1877]: time="2020-05-28T09:14:47Z" level=error msg="Failure occurred while executing authorization request: &url.Error{Op:\"Post\", URL:\"https://docker.mender.io/api/devices/v1/authentication/auth_requests\", Err:x509.UnknownAuthorityError{Cert:(*x509.Certificate)(0x18b0000), hintErr:error(nil), hintCert:(*x509.Certificate)(nil)}}" module=client_auth
May 28 09:14:47 imx6ulevk mender[1877]: time="2020-05-28T09:14:47Z" level=error msg="Certificate is signed by unknown authority." module=client_auth
May 28 09:14:47 imx6ulevk mender[1877]: time="2020-05-28T09:14:47Z" level=error msg="If you are using a self-signed certificate, make sure it is available locally to the Mender client in /etc/mender/server.crt and is configured properly in /etc/mender/mender.conf." module=client_auth
May 28 09:14:47 imx6ulevk mender[1877]: time="2020-05-28T09:14:47Z" level=error msg="See https://docs.mender.io/troubleshooting/mender-client#certificate-signed-by-unknown-authority for more information." module=client_auth
May 28 09:14:47 imx6ulevk mender[1877]: time="2020-05-28T09:14:47Z" level=error msg="authorize failed: transient error: authorization request failed: certificate signed by unknown authority: Post https://docker.mender.io/api/devices/v1/authentication/auth_requests: x509: certificate signed by unknown authority" module=state

```

And my `/etc/mender/mender.conf` file is given below:

```auto
{
    "ClientProtocol": "https",
    "ArtifactVerifyKey": "",
    "HttpsClient": {
        "Certificate": "",
        "Key": "",
        "SkipVerify": false
    },
    "RootfsPartA": "/dev/mmcblk1p2",
    "RootfsPartB": "/dev/mmcblk1p3",
    "DeviceTypeFile": "/var/lib/mender/device_type",
    "UpdatePollIntervalSeconds": 5,
    "InventoryPollIntervalSeconds": 5,
    "RetryPollIntervalSeconds": 30,
    "StateScriptTimeoutSeconds": 0,
    "StateScriptRetryTimeoutSeconds": 0,
    "StateScriptRetryIntervalSeconds": 0,
    "ModuleTimeoutSeconds": 0,
    "ServerCertificate": "/usr/share/doc/mender-client/examples/demo.crt",
    "ServerURL": "",
    "UpdateLogPath": "",
    "TenantToken": "",
    "Servers": [
        {
            "ServerURL": "https://docker.mender.io"
        }
    ]
}

```

Full debug log is attached here: [https://github.com/danie007/imx6/blob/master/warrior\_mender\_cert\_error.log.txt](https://github.com/danie007/imx6/blob/master/warrior_mender_cert_error.log.txt)

Any help would be very helpful. Thanks in advance.

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [May 28, 2020, 2:30pm UTC](https://hub.mender.io/t/mender-server-authorization-error-demo-crt-is-missing-in-imx-6ul-evk-yocto-build/1981/2 "2020-05-28T14:30:49Z")

</div>

You should get the demo certificate on the device if you are using, [meta-mender-demo](https://github.com/mendersoftware/meta-mender/tree/master/meta-mender-demo). Might depend on which Yocto version you are using, the path for the cert used to be `/etc/mender/server.crt`

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [May 28, 2020, 2:31pm UTC](https://hub.mender.io/t/mender-server-authorization-error-demo-crt-is-missing-in-imx-6ul-evk-yocto-build/1981/3 "2020-05-28T14:31:39Z")

</div>

Also you can find the cert here, [https://github.com/mendersoftware/mender/blob/master/support/demo.crt](https://github.com/mendersoftware/mender/blob/master/support/demo.crt)

---

<div class="post-metadata">

**Author:** ![danie](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/danie/32/620_2.png) [@danie](https://hub.mender.io/u/danie)\
**Post date:** [May 29, 2020, 10:56am UTC](https://hub.mender.io/t/mender-server-authorization-error-demo-crt-is-missing-in-imx-6ul-evk-yocto-build/1981/4 "2020-05-29T10:56:38Z")

</div>

@mirzak appreciate for your swift reply!!

I got it resolved by **replacing the certificates** in both `server` & `client` following the documentation here: [Certificates and keys | Mender documentation](https://docs.mender.io/2.3/administration/certificates-and-keys#replacing-keys-and-certificates)

By the way,

> [@mirzak](#):
>
> cert here

did not worked for me as I’ve used `meta-mender-core` in Yocto project.
