# Raspberry Pi 4 - Hosted Mender / TLS Certificate warning?

**URL:** <https://hub.mender.io/t/raspberry-pi-4-hosted-mender-tls-certificate-warning/3727>\
**Category:** General Discussions\
**Created:** [June 9, 2021, 5:32pm UTC](https://hub.mender.io/t/raspberry-pi-4-hosted-mender-tls-certificate-warning/3727 "2021-06-09T17:32:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AlexC](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@AlexC](https://hub.mender.io/u/AlexC)\
**Post date:** [June 9, 2021, 5:32pm UTC](https://hub.mender.io/t/raspberry-pi-4-hosted-mender-tls-certificate-warning/3727/1 "2021-06-09T17:32:35Z")

</div>

Hello,

We’re investigating Mender as a management system for Raspberry Pi 4’s

We’ve been through the documentation and set a couple up with the provided image, and all looks to be working they come through on the hosted dashboard and we’ve been pushing updates to them successfully

I was SSH’d into one of the units today and decided to check the system logs on a whim and noticed a bunch of errors from mender-client about TLS certificates

```auto
Jun 09 18:16:45 gateway mender[887]: time="2021-06-09T18:16:45+01:00" level=error msg="Failed to Load the Server certificate. Err SSL errors: "
Jun 09 18:16:45 gateway mender[887]: time="2021-06-09T18:16:45+01:00" level=warning msg="Failed to load the server TLS certificate settings: SSL errors: "

```

Is there anything we can do to resolve these errors?

We’ve made no modifications to the base image outside of removing the pi user and adding a few of our own scripts / applications.

Our mender config is as follows which is the default production .conf, the same messages are seen on the demo .conf too:

```auto
    "ClientProtocol": "https",
    "ArtifactVerifyKey": "",
    "HttpsClient": {
        "Certificate": "",
        "Key": "",
        "SSLEngine": ""
    },
    "Security": {
        "AuthPrivateKey": "",
        "SSLEngine": ""
    },
    "RootfsPartA": "/dev/mmcblk0p2",
    "RootfsPartB": "/dev/mmcblk0p3",
    "DeviceTypeFile": "/var/lib/mender/device_type",
    "DBus": {
        "Enabled": true
    },
    "UpdatePollIntervalSeconds": 1800,
    "InventoryPollIntervalSeconds": 28800,
    "SkipVerify": false,
    "RetryPollIntervalSeconds": 300,
    "StateScriptTimeoutSeconds": 0,
    "StateScriptRetryTimeoutSeconds": 0,
    "StateScriptRetryIntervalSeconds": 0,
    "ModuleTimeoutSeconds": 0,
    "ServerCertificate": "",
    "ServerURL": "",
    "UpdateLogPath": "",
    "TenantToken": "<snip>",
    "Servers": [
        {
            "ServerURL": "https://hosted.mender.io"
        }
    ]
}

```

Any assistance would be appreciated  
Thanks

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [June 9, 2021, 7:27pm UTC](https://hub.mender.io/t/raspberry-pi-4-hosted-mender-tls-certificate-warning/3727/2 "2021-06-09T19:27:17Z")

</div>

Hi @AlexC

I’m not sure what specifically would cause those errors in the prebuilt images but you should be aware that those images are not intended as starting points for your design but rather just a quick way to start working with Mender to understand the workflow. Once you are past that point you should investigate using your own customized image and running it through our mender-convert tool: [System updates: Debian family | Mender documentation](https://docs.mender.io/system-updates-debian-family)

As for the cert errors, perhaps @oleorhagen or @lluiscampos know more.

Drew

---

<div class="post-metadata">

**Author:** ![AlexC](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@AlexC](https://hub.mender.io/u/AlexC)\
**Post date:** [June 9, 2021, 9:47pm UTC](https://hub.mender.io/t/raspberry-pi-4-hosted-mender-tls-certificate-warning/3727/3 "2021-06-09T21:47:03Z")

</div>

Thanks for the reply,

I was under the impression that the provided mender image was just a stock raspi-os lite image that had been converted to mender?

Will have a read up on mender-convert, can always convert raspi-os lite myself if needed

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [June 10, 2021, 8:19am UTC](https://hub.mender.io/t/raspberry-pi-4-hosted-mender-tls-certificate-warning/3727/4 "2021-06-10T08:19:19Z")

</div>

Hi @AlexC

The error is a little misleading. The errors stems from an empty Server certificate in the config, `ServerCertificate: ""`.

The client works however, since it falls back to the system `ca-certs`, in which the server certificate is now installed.
