# Mutual TLS with mender

**URL:** <https://hub.mender.io/t/mutual-tls-with-mender/3263>\
**Category:** General Discussions\
**Tags:** yocto, zeus\
**Created:** [February 23, 2021, 12:40pm UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263 "2021-02-23T12:40:11Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [February 23, 2021, 12:40pm UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/1 "2021-02-23T12:40:11Z")

</div>

Hi All,

I have mender integrated board i.MX8QM. I would like to test Mutual TLS for Device authentication.  
Can you please tell me what are the steps to be followed ?  
Mender version - 2.4.1  
yocto - zeus

Thanks & Regards,  
Chaithanya

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [February 23, 2021, 1:47pm UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/2 "2021-02-23T13:47:35Z")

</div>

Mutual TLS is available in 2.6 and our hosted platform so you will need to upgrade to one of those versions first and then follow the instructions [here](https://docs.mender.io/2.6/server-integration/mutual-tls-authentication).

Drew

---

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [March 1, 2021, 10:35am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/3 "2021-03-01T10:35:46Z")

</div>

Hi drewmoseley,

Thank you for your response.  
Can you please tell me how keys and certificates are managed in mutual tls?

Regards,  
Chaithanya

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [March 1, 2021, 4:30pm UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/4 "2021-03-01T16:30:58Z")

</div>

What is missing in the documentation that I linked to? Do you have specific questions?

---

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [March 2, 2021, 5:27am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/5 "2021-03-02T05:27:00Z")

</div>

Hi,

When I run docker run to start edge proxy, I get below error:

Unable to find image ‘[registry.mender.io/mendersoftware/mtls-ambassador:mender-2.6.0](http://registry.mender.io/mendersoftware/mtls-ambassador:mender-2.6.0)’ locally  
docker: Error response from daemon: Head [https://registry.mender.io/v2/mendersoftware/mtls-ambassador/manifests/mender-2.6.0:](https://registry.mender.io/v2/mendersoftware/mtls-ambassador/manifests/mender-2.6.0:) no basic auth credentials.  
See ‘docker run --help’.

To use docker enterprise,  
I don’t have Docker EE repository URL associated with my trial account.

How can I get access to Docker Enterprise Edition for Ubuntu?

Looking forward for your response.

Thanks & Regards,  
Chaithanya

---

<div class="post-metadata">

**Author:** ![eystein](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@eystein](https://hub.mender.io/u/eystein)\
**Post date:** [March 2, 2021, 8:50pm UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/6 "2021-03-02T20:50:31Z")

</div>

Hi @chaithanya ,

This is not because of docker licensing, but because you’re trying to use Mender Enterprise and don’t have credentials to download it, it seems.

I think you’ve already figured it out now, but for future reference, simply fill out the Contact form to request credentials: [Contact us | Mender](https://mender.io/contact-us)

---

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [March 17, 2021, 4:45am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/7 "2021-03-17T04:45:05Z")

</div>

Hi eystein,

Thank you for your response.  
To access mender enterprise, I need to get access to docker enterprise is it?  
I have received credentials for mender enterprise, but when I try to run docker run command I get the same issue as I mentioned above.  
Can you please tell me about the requirements and what steps to be followed?

Thanks & Regards,  
Chaithanya

---

<div class="post-metadata">

**Author:** ![eystein](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@eystein](https://hub.mender.io/u/eystein)\
**Post date:** [March 17, 2021, 5:07am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/8 "2021-03-17T05:07:12Z")

</div>

Hello @chaithanya ,

Have you followed the Production installation documentation? [Production installation | Mender documentation](https://docs.mender.io/2.6/server-installation/production-installation)

In particular you’ll need to follow the Enterprise specific steps ([Production installation | Mender documentation](https://docs.mender.io/2.6/server-installation/production-installation#enterprise)), and use “docker login [registry.mender.io](http://registry.mender.io)” with your credentials.

If this is what you did, perhaps you could share the exact steps you carried out, what you expected to happen and what actually happened?

---

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [March 18, 2021, 5:21am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/9 "2021-03-18T05:21:12Z")

</div>

Hi eystein,

I am following below link to test mutual tls,  
[https://docs.mender.io/server-integration/mutual-tls-authentication](https://docs.mender.io/server-integration/mutual-tls-authentication)

I have generated certificates in my host pc as described in above link. I got stuck in “Set up the mTLS edge proxy to authenticate devices using mTLS” section. I am facing issue while starting edge proxy in my host pc where I have generated the certificates.

I am new to mender. Could you please guide me with exact procedure

Thanks & Regards,  
Chaithanya

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [March 18, 2021, 1:21pm UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/10 "2021-03-18T13:21:42Z")

</div>

Hi @chaithanya the docs link should be the correct procedure here. Perhaps it is missing something and needs an update though. Can you provide details of the issue you are having starting the proxy?

Drew

---

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [March 19, 2021, 9:30am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/11 "2021-03-19T09:30:44Z")

</div>

Hi drewmoseley,

What value should be given to the field commonName while generating server-cert.conf. It is said that it should be matching edge proxy’s domain name, where we can find this domain name?  
Once after creating certificates, we can start edge proxy in the same pc where docker is running is it?

Thanks & Regards,  
Chaithanya

---

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [March 19, 2021, 10:50am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/12 "2021-03-19T10:50:18Z")

</div>

Issue faced while starting edge proxy,

```
$ sudo docker run -p 8080:80 -e MTLS_MENDER_USER= *************-e MTLS_MENDER_PASS="****************" -e MTLS_MENDER_BACKEND=https://hosted.mender.io -e MTLS_DEBUG_LOG=true -v $(pwd)/server-cert.pem:/etc/mtls/certs/server/server.crt -v $(pwd)/server-private.key:/etc/mtls/certs/server/server.key -v $(pwd)/ca-cert.pem:/etc/mtls/certs/tenant-ca/tenant.ca.pem registry.mender.io/mendersoftware/mtls-ambassador:mender-2.6.0
-----------------------------------------------------------------------------------------------------------------------------------------
time="2021-03-19T10:21:42Z" level=info msg="starting mtls-ambassador" file=main.go func=main.doMain line=36
time="2021-03-19T10:21:42Z" level=info msg="loading config /etc/mtls/config.yaml" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg="loading config: ok" file=main.go func=main.doMain.func1 line=64
time="2021-03-19T10:21:42Z" level=info msg="config values:" file=main.go func=main.dumpConfig line=194
time="2021-03-19T10:21:42Z" level=info msg=" mender_backend: https://hosted.mender.io" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg=" mender_user: chaithanya.padmashali@iwavesystems.com" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg=" mender_pass: not empty" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg=" server_cert: /etc/mtls/certs/server/server.crt" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg=" server_key: /etc/mtls/certs/server/server.key" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg=" server_key: /etc/mtls/certs/tenant-ca/tenant.ca.pem" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg=" listen: 8080" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg=" debug_log: true" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg=" insecure_skip_verify: false" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg=" blacklist_path: " file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg="validating config" file=main.go func=main.validateConfig line=176
time="2021-03-19T10:21:42Z" level=info msg="validating config: ok" file=main.go func=main.validateConfig line=189
time="2021-03-19T10:21:42Z" level=info msg="creating proxy with url https://hosted.mender.io, insecure skip verify: false" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg="proxy scheme: https, host: hosted.mender.io" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg="creating proxy: ok" file=proxy.go func=http.NewProxy line=77
time="2021-03-19T10:21:42Z" level=info msg="created client with base url https://hosted.mender.io, insecure skip verify: false" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=info msg="logging in with user chaithanya.padmashali@iwavesystems.com" file=entry.go func="logrus.(*Entry).Infof" line=346
time="2021-03-19T10:21:42Z" level=error msg="failed to get request id from context: context request id is not a string, proceeding" file=entry.go func="logrus.(*Entry).Errorf" line=362
time="2021-03-19T10:21:43Z" level=fatal msg=unauthorized file=main.go func=main.cmdServer line=107

```

Used mender provided enterprise credentials in place of MTLS\_MENDER\_USER and MTLS\_MENDER\_PASS

edit: @drewmoseley added formatting

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [March 19, 2021, 1:33pm UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/13 "2021-03-19T13:33:17Z")

</div>

@tranchitella can you help further here?

As for the question about the CN, that is the Common Name used in the certificates. More detail can be found [here](https://knowledge.digicert.com/solution/SO7239.html).

Drew

---

<div class="post-metadata">

**Author:** ![tranchitella](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/tranchitella/32/606_2.png) [@tranchitella](https://hub.mender.io/u/tranchitella)\
**Post date:** [March 22, 2021, 8:44am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/14 "2021-03-22T08:44:25Z")

</div>

@chaithanya

The CN for the service certificate must match the DNS name you are using to connect to the mTLS ambassador from your devices. Regarding the error, it seems the user/password you provided in the MTLS\_MENDER\_USER and MTLS\_MENDER\_PASSWORD env variables are not correct. The mTLS ambassador needs to log in to the Hosted Mender backend in order to perform authorization of devices, thus you have to provide a valid credentials set.

You can create a new user in Hosted Mender dedicated to the mTLS ambassador and use those credentials.

---

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [March 23, 2021, 5:59am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/15 "2021-03-23T05:59:00Z")

</div>

@tranchitella

Thank you for your response.  
I had created new user in Hosted Mender and used those credentials, I could able to start the proxy server.  
But now I am facing issue while copying key and certificate to disk image using mender-artifact tool.  
Attached snapshot of the issue for your reference.

Looking forward to your response.

Regards,  
Chaithanya

 ![mender_artifact_cp_err](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/2X/4/4568ca349817f8ea82ab60f91cec2d98946d0c2d.jpeg)

---

<div class="post-metadata">

**Author:** ![tranchitella](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/tranchitella/32/606_2.png) [@tranchitella](https://hub.mender.io/u/tranchitella)\
**Post date:** [March 23, 2021, 7:41am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/16 "2021-03-23T07:41:10Z")

</div>

@kacf @oleorhagen @lluiscampos any idea?

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [March 23, 2021, 7:55am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/17 "2021-03-23T07:55:56Z")

</div>

@chaithanya which version of `mender-artifact` are you using?

And is this all the text returned? What is the error code you’re getting?

---

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [March 23, 2021, 8:58am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/19 "2021-03-23T08:58:38Z")

</div>

@oleorhagen

mender-artifact version is 3.5.0  
I didn’t get any error code

Thanks & Regards,  
Chaithanya

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [March 23, 2021, 9:06am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/20 "2021-03-23T09:06:05Z")

</div>

@chaithanya can you run:

`fdisk -l <image>` and paste the output here please? 🙂

---

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [March 23, 2021, 9:20am UTC](https://hub.mender.io/t/mutual-tls-with-mender/3263/21 "2021-03-23T09:20:14Z")

</div>

@oleorhagen

Attached required information.

 ![fdisk_image](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/2X/0/0dc44af24a2a31e2a652e6d70dc32926105a27a8.jpeg)

[Next page](https://hub.mender.io/t/mutual-tls-with-mender/3263.md?page=2)
