# "ServerCertificate" key not set by mender-convert --server-cert

**URL:** <https://hub.mender.io/t/servercertificate-key-not-set-by-mender-convert-server-cert/1030>\
**Category:** General Discussions\
**Tags:** mender-convert\
**Created:** [September 17, 2019, 10:46am UTC](https://hub.mender.io/t/servercertificate-key-not-set-by-mender-convert-server-cert/1030 "2019-09-17T10:46:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gswebspace](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/gswebspace/32/359_2.png) [@gswebspace](https://hub.mender.io/u/gswebspace)\
**Post date:** [September 17, 2019, 10:46am UTC](https://hub.mender.io/t/servercertificate-key-not-set-by-mender-convert-server-cert/1030/1 "2019-09-17T10:46:47Z")

</div>

Hi,

I have been following [this guide](https://docs.mender.io/2.1/administration/production-installation) to setup the (production equivalent of ) mender server.

All went well and I had used freshly prepared self signed certificates for the server (as mentioned in the docs) and also prepared a RPi 3B device by converting 2019-04-08-raspbian-stretch-lite.img via mender-convert 1.1.1 branch.

Command used -

> ./docker-mender-convert from-raw-disk-image   
> –raw-disk-image $RAW\_DISK\_IMAGE   
> –mender-disk-image $MENDER\_DISK\_IMAGE   
> –device-type $DEVICE\_TYPE   
> –artifact-name $ARTIFACT\_NAME   
> –bootloader-toolchain arm-buildroot-linux-gnueabihf   
> –server-url $SERVER\_URL   
> –server-cert $SERVER\_CERT

Although the option --server-cert successfully copied the generated server.crt file to the final sdimg, the “/etc/mender/mender.conf” did not contain the “ServerCertificate” key, and thus the copied certificate was not being used while the client tried to communicate to the server.

Ofcourse, I had no idea why I was still getting SSL errors (via journalctl -u mender) as the following documentations did not provide any hint that the mender.conf had to be updated with “ServerCertificate” key -

> **[Production installation | Mender documentation](https://docs.mender.io/2.1/administration/production-installation)**

> [@Raspberry Pi 3 Model B/B+ Raspbian](https://hub.mender.io/t/raspberry-pi-3-model-b-b-raspbian/140):
>
> Board description The Raspberry Pi 3 Model B/B+ is a popular single board computer based on Broadcom SoCs. It is the most powerful board within the Raspberry Pi family and probably the most popular with “makers”. [770A5842-462x322] URL: [https://www.raspberrypi.org/products/raspberry-pi-3-model-b-plus](https://www.raspberrypi.org/products/raspberry-pi-3-model-b-plus?target=_blank) URL: [https://www.raspberrypi.org/products/raspberry-pi-3-model-b](https://www.raspberrypi.org/products/raspberry-pi-3-model-b?target=_blank) Wiki: [https://elinux.org/RPi\_Hub](https://elinux.org/RPi_Hub?target=_blank)Test results The Raspberry Pi OS releases in the table below have been tested by the Mender c…

Only when I found out the Installation note [here](https://github.com/mendersoftware/mender/blob/master/README.md) the client finally worked.

Note: A lot of time was wasted, even after following the guide.

So here are my two humble requests -

A) Can the mender-convert utility also add the “ServerCertificate” key to “/etc/mender/mender.conf” when “–server-cert” is specified as a command line option ?

B) Can the documentation be updated to point out that “ServerCertificate” needs to be set in the client in case of self-signed certificates.

This will help people who are new to mender to easily try out mender. Thanks!

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [September 17, 2019, 10:52am UTC](https://hub.mender.io/t/servercertificate-key-not-set-by-mender-convert-server-cert/1030/2 "2019-09-17T10:52:27Z")

</div>

Thank you for your feedback @gswebspace.

> A) Can the mender-convert utility also add the “ServerCertificate” key to “/etc/mender/mender.conf” when “–server-cert” is specified as a command line option ?

This was actually a bug. The `--server-cert` should add the file and add the entry to `/etc/mender/mender.conf. But this should have been resolved already. I will investigate why you came across this using the linked tutorial.

> B) Can the documentation be updated to point out that “ServerCertificate” needs to be set in the client in case of self-signed certificates.

So in the `mender-convert` case, this should have been handled already by tool. But will look in to this

---

<div class="post-metadata">

**Author:** ![gswebspace](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/gswebspace/32/359_2.png) [@gswebspace](https://hub.mender.io/u/gswebspace)\
**Post date:** [September 17, 2019, 11:04am UTC](https://hub.mender.io/t/servercertificate-key-not-set-by-mender-convert-server-cert/1030/3 "2019-09-17T11:04:42Z")

</div>

Looking at the 1.1.1 code for mender-convert, it seems jq\_inplace was never called [here](https://github.com/mendersoftware/mender-convert/blob/6e42157727e86566e32b9bfaf047f24fe6cbb1e6/convert-stage-4.sh#L191).

Hope this helps ! Thanks for your quick reply!

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [September 17, 2019, 11:07am UTC](https://hub.mender.io/t/servercertificate-key-not-set-by-mender-convert-server-cert/1030/4 "2019-09-17T11:07:50Z")

</div>

But the linked tutorial,

> [@Raspberry Pi 3 Model B/B+ Raspbian](https://hub.mender.io/t/raspberry-pi-3-model-b-b-raspbian/140):
>
> Board description The Raspberry Pi 3 Model B/B+ is a popular single board computer based on Broadcom SoCs. It is the most powerful board within the Raspberry Pi family and probably the most popular with “makers”. [770A5842-462x322] URL: [https://www.raspberrypi.org/products/raspberry-pi-3-model-b-plus](https://www.raspberrypi.org/products/raspberry-pi-3-model-b-plus?target=_blank) URL: [https://www.raspberrypi.org/products/raspberry-pi-3-model-b](https://www.raspberrypi.org/products/raspberry-pi-3-model-b?target=_blank) Wiki: [https://elinux.org/RPi\_Hub](https://elinux.org/RPi_Hub?target=_blank)Test results The Raspberry Pi OS releases in the table below have been tested by the Mender c…

is using `1.2.x` branch. So that explains the problems you where having if you are using `1.1.1`, where this bug was present.

I would recommend you to update to 1.2.x

Edit: 1.1.x should also work as it contains the [fix](https://github.com/mendersoftware/mender-convert/commit/260062ea1b29f12fd1c473f62323c60babc50733)

---

<div class="post-metadata">

**Author:** ![gswebspace](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/gswebspace/32/359_2.png) [@gswebspace](https://hub.mender.io/u/gswebspace)\
**Post date:** [September 17, 2019, 11:22am UTC](https://hub.mender.io/t/servercertificate-key-not-set-by-mender-convert-server-cert/1030/5 "2019-09-17T11:22:13Z")

</div>

I had to switch to 1.1.1 because I was facing (the known) HDMI yellow overlay issue while using the buster-lite image and then stretch-lite image with probably unsupported changes to the Rpi system.

I’ll try again with stretch-lite and 1.2.x. Will update this thread if I get stuck.

Thanks!

---

<div class="post-metadata">

**Author:** ![gswebspace](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/gswebspace/32/359_2.png) [@gswebspace](https://hub.mender.io/u/gswebspace)\
**Post date:** [September 18, 2019, 5:13am UTC](https://hub.mender.io/t/servercertificate-key-not-set-by-mender-convert-server-cert/1030/6 "2019-09-18T05:13:01Z")

</div>

mender-convert branch 1.2.x worked with raspbian stretch lite 👍
