# Recovering/Reauthorizing Decommissioned Device on Hosted Mender

**URL:** <https://hub.mender.io/t/recovering-reauthorizing-decommissioned-device-on-hosted-mender/2692>\
**Category:** General Discussions\
**Tags:** beaglebone-black, hosted\
**Created:** [October 20, 2020, 4:03am UTC](https://hub.mender.io/t/recovering-reauthorizing-decommissioned-device-on-hosted-mender/2692 "2020-10-20T04:03:27Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![poursteady](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@poursteady](https://hub.mender.io/u/poursteady)\
**Post date:** [October 20, 2020, 4:03am UTC](https://hub.mender.io/t/recovering-reauthorizing-decommissioned-device-on-hosted-mender/2692/1 "2020-10-20T04:03:27Z")

</div>

Is there a way to see a list of decommissioned devices within the [hosted.mender.io](http://hosted.mender.io) interface? Or a setting that would allow a device that was accidentally decommissioned to appear again? I’ve restarted the device a few times with no luck.

```auto
ps157:~$ sudo journalctl -f -u mender
-- Logs begin at Sat 2000-01-01 00:00:03 UTC. --
Oct 20 03:40:08 ps157 mender[207]: time="2020-10-20T03:40:08Z" level=info msg="State transition: authorize [Sync] -> authorize-wait [Idle]" module=mender
Oct 20 03:45:07 ps157 mender[207]: time="2020-10-20T03:45:07Z" level=info msg="State transition: authorize-wait [Idle] -> authorize [Sync]" module=mender
Oct 20 03:45:08 ps157 mender[207]: time="2020-10-20T03:45:08Z" level=error msg="authorize failed: transient error: authorization request failed: (request_id: ): authentication request rejected server error message: dev auth: unauthorized" module=state
Oct 20 03:45:08 ps157 mender[207]: time="2020-10-20T03:45:08Z" level=info msg="State transition: authorize [Sync] -> authorize-wait [Idle]" module=mender
Oct 20 03:50:07 ps157 mender[207]: time="2020-10-20T03:50:07Z" level=info msg="State transition: authorize-wait [Idle] -> authorize [Sync]" module=mender
Oct 20 03:50:09 ps157 mender[207]: time="2020-10-20T03:50:09Z" level=error msg="authorize failed: transient error: authorization request failed: (request_id: ): authentication request rejected server error message: dev auth: unauthorized" module=state
Oct 20 03:50:09 ps157 mender[207]: time="2020-10-20T03:50:09Z" level=info msg="State transition: authorize [Sync] -> authorize-wait [Idle]" module=mender
Oct 20 03:55:07 ps157 mender[207]: time="2020-10-20T03:55:07Z" level=info msg="State transition: authorize-wait [Idle] -> authorize [Sync]" module=mender
Oct 20 03:55:08 ps157 mender[207]: time="2020-10-20T03:55:08Z" level=error msg="authorize failed: transient error: authorization request failed: (request_id: ): authentication request rejected server error message: dev auth: unauthorized" module=state
Oct 20 03:55:08 ps157 mender[207]: time="2020-10-20T03:55:08Z" level=info msg="State transition: authorize [Sync] -> authorize-wait [Idle]" module=mender

```

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [October 20, 2020, 6:48am UTC](https://hub.mender.io/t/recovering-reauthorizing-decommissioned-device-on-hosted-mender/2692/2 "2020-10-20T06:48:21Z")

</div>

> [@poursteady](#):
>
> Is there a way to see a list of decommissioned devices within the [hosted.mender.io](http://hosted.mender.io) interface?

Do not think so. The idea of decommissioning is to remove any trace of that device (or actually an authorization set).

> Or a setting that would allow a device that was accidentally decommissioned to appear again?

A device which has been decommissioned should always come back in “Pending” state, should it try to connect again.

So the message you are seeing is correct,

```auto
Oct 20 03:45:08 ps157 mender[207]: time="2020-10-20T03:45:08Z" level=error msg="authorize failed: transient error: authorization request failed: (request_id: ): authentication request rejected server error message: dev auth: unauthorized" module=state

```

This should mean that you have an “Pending” authorization set on the server. It can be in two places, either under the “Pending” tab, or it could actually also be under “Devices” tab, as a new authorization set for an existing device. This is typically indicated by a small warning icon on the device.

---

<div class="post-metadata">

**Author:** ![poursteady](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@poursteady](https://hub.mender.io/u/poursteady)\
**Post date:** [October 20, 2020, 10:49am UTC](https://hub.mender.io/t/recovering-reauthorizing-decommissioned-device-on-hosted-mender/2692/3 "2020-10-20T10:49:15Z")

</div>

Got it. That makes sense @mirzak

Unfortunately it’s not showing up in the pending tab and when I try to filter, there’s no devices that match the BBB’s MAC address with a new auth set.

Does it take a while to re-appear in Pending? Anything else that could be happening?

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [October 20, 2020, 11:04am UTC](https://hub.mender.io/t/recovering-reauthorizing-decommissioned-device-on-hosted-mender/2692/4 "2020-10-20T11:04:50Z")

</div>

> [@poursteady](#):
>
> Does it take a while to re-appear in Pending?

As soon as a device checks in and is not authorized (which is indicated by the client log), it should end up in “Pending” state.

> Anything else that could be happening?

Maybe check that it is not in rejected state? This could prevent it from ending up in Pending.

[https://hosted.mender.io/ui/#/devices/rejected](https://hosted.mender.io/ui/#/devices/rejected)

---

<div class="post-metadata">

**Author:** ![poursteady](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@poursteady](https://hub.mender.io/u/poursteady)\
**Post date:** [October 20, 2020, 1:58pm UTC](https://hub.mender.io/t/recovering-reauthorizing-decommissioned-device-on-hosted-mender/2692/5 "2020-10-20T13:58:51Z")

</div>

I think it’s back up! But a weird thing happened where there was a device with a similar (or the same HWAddress) but a different hostname that was receiving the new auth set requests. Is it possible for two BBB’s to have the same Mac Address?

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [October 20, 2020, 2:51pm UTC](https://hub.mender.io/t/recovering-reauthorizing-decommissioned-device-on-hosted-mender/2692/6 "2020-10-20T14:51:12Z")

</div>

> Is it possible for two BBB’s to have the same Mac Address?

No, this is not allowed if the MAC is used as [device identity](https://docs.mender.io/client-installation/identity).

If two devices have the same device identifier, the Mender server would just see them as the same device but with different authorization sets (different keys). Which matches I believe what you saw.

---

<div class="post-metadata">

**Author:** ![PJK](https://avatars.discourse-cdn.com/v4/letter/p/bc79bd/32.png) [@PJK](https://hub.mender.io/u/PJK)\
**Post date:** [October 22, 2020, 7:18am UTC](https://hub.mender.io/t/recovering-reauthorizing-decommissioned-device-on-hosted-mender/2692/7 "2020-10-22T07:18:22Z")

</div>

We had this happen as well a few weeks ago on our self hosted Mender server. A device was decommissioned and did not show up in the Pending list, even after a couple of reboots of the device and a restart of the Server (just to make sure that there wasn’t a blocking issue). We then decommissioned another device and that also didn’t show up in the Pending list.

After we switched on an Accepted device and that was detected by the Server, all of a sudden both decommissioned devices showed up in the Pending list.

Not sure if there is an issue in the Server where it will not see decommissioned devices some of the time (in the past, before server 2.4 we never saw this issue) or it was a fluke. We tested network connectivity on both decom devices when they were not recognized, but that worked fine. They could even see and ping the Server IP.

---

<div class="post-metadata">

**Author:** ![dellgreen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dellgreen/32/85_2.png) [@dellgreen](https://hub.mender.io/u/dellgreen)\
**Post date:** [October 22, 2020, 8:11am UTC](https://hub.mender.io/t/recovering-reauthorizing-decommissioned-device-on-hosted-mender/2692/8 "2020-10-22T08:11:05Z")

</div>

I’ve had similar issues, and had to run the following to get it working for me again after decommissioning.

docker-compose exec mender-device-auth /usr/bin/deviceauth maintenance --decommissioning-cleanup

or

docker exec menderproduction\_mender-device-auth\_1 /usr/bin/deviceauth maintenance --decommissioning-cleanup
