# Mender with helm chart: deployments service fails to start due to certificate issue

**URL:** <https://hub.mender.io/t/mender-with-helm-chart-deployments-service-fails-to-start-due-to-certificate-issue/5582>\
**Category:** General Discussions\
**Tags:** k8s, helm, enterprise\
**Created:** [February 1, 2023, 1:37pm UTC](https://hub.mender.io/t/mender-with-helm-chart-deployments-service-fails-to-start-due-to-certificate-issue/5582 "2023-02-01T13:37:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rhirsh](https://avatars.discourse-cdn.com/v4/letter/r/5daacb/32.png) [@rhirsh](https://hub.mender.io/u/rhirsh)\
**Post date:** [February 1, 2023, 1:37pm UTC](https://hub.mender.io/t/mender-with-helm-chart-deployments-service-fails-to-start-due-to-certificate-issue/5582/1 "2023-02-01T13:37:55Z")

</div>

Hi all,

I’m using the v3.4.0 helm chart obtained [GitHub - mendersoftware/mender-helm at 3.4.0](https://github.com/mendersoftware/mender-helm/tree/3.4.0)

I used all the recommended settings, and generated self signed certificates as specified on the page,  
but it seems that the cert/key generated for the `api-gateway` are not supported by the underlying Golang version validating the cert.

The deployment service has the following error:  
`caused by: Put "https://mydomain.com/mender-artifact-storage": x509: certificate relies on legacy Common Name field, use SANs instead`

I tried generating the crt and key like this guide [Create self-signed SSL certificate with SubjectAltName(SAN) · GitHub](https://gist.github.com/KeithYeh/bb07cadd23645a6a62509b1ec8986bbc)

And now deployments service is failing with:  
`caused by: Put "https://mydomain.com/mender-artifact-storage": x509: certificate signed by unknown authority`

Anyone has any idea how to work around this?

EDIT:  
I realize this is similar to [“menderproduction\_mender-deployments\_1” keeps restarting on self-hosted mender server](https://hub.mender.io/t/menderproduction-mender-deployments-1-keeps-restarting-on-self-hosted-mender-server/4273)

---

<div class="post-metadata">

**Author:** ![rhirsh](https://avatars.discourse-cdn.com/v4/letter/r/5daacb/32.png) [@rhirsh](https://hub.mender.io/u/rhirsh)\
**Post date:** [February 6, 2023, 2:42pm UTC](https://hub.mender.io/t/mender-with-helm-chart-deployments-service-fails-to-start-due-to-certificate-issue/5582/2 "2023-02-06T14:42:13Z")

</div>

tl;dr what I’m looking for is a flag that will make `deployments` service ignore ssl certificate errors, since the certificate is self-signed (like the helm-chart guide suggests)
