# Understanding mutual TLS

**URL:** <https://hub.mender.io/t/understanding-mutual-tls/3988>\
**Category:** General Discussions\
**Created:** [August 10, 2021, 6:29am UTC](https://hub.mender.io/t/understanding-mutual-tls/3988 "2021-08-10T06:29:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [August 10, 2021, 6:29am UTC](https://hub.mender.io/t/understanding-mutual-tls/3988/1 "2021-08-10T06:29:20Z")

</div>

Hi Team,

I would like to know what is the main reason of using mutual TLS?  
It is said that, authenticated devices are automatically accepted in the mender server. But in my case I could able to see the device in pending list in mender server, manually I should accept it. Can you please elaborate on this mutual TLS feature?

Background description about my mutual TLS testing:

1. Generated CA, client and server certificates as per the mender documentation
2. Edge proxy is running in the host pc where docker is running
3. Copied the device private key and certificates to rootfs and flashed binaries to the board
4. Device is listed in pending list of hosted server while it is booting
5. Manually accepted the device and tested OTA update

Whether my testing procedure is as expected?  
Can I get some more clarification about advantages of using mutual TLS?

Looking forward for your response.

Thanks & Regards,  
Chaithanya

---

<div class="post-metadata">

**Author:** ![lramirez](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/lramirez/32/1195_2.png) [@lramirez](https://hub.mender.io/u/lramirez)\
**Post date:** [August 11, 2021, 8:39pm UTC](https://hub.mender.io/t/understanding-mutual-tls/3988/2 "2021-08-11T20:39:27Z")

</div>

Hi @chaithanya,

After the mTLS connection was [successful](https://docs.mender.io/development/server-integration/mutual-tls-authentication#verify-that-the-device-is-accepted) you should see your device flagged as accepted and not to wait to accept it manually.

I recommend following some [double-checking process](https://docs.mender.io/development/troubleshoot/mender-server#a-device-shows-up-as-pending-after-preauthorizing-it) we describe for troubleshooting.

mTLS is in particular useful in a mass production as it is a secure way of adding new devices to your account without human interaction.

Checking old interactions, I see there is a whole thread in [here](https://hub.mender.io/t/mutual-tls-with-mender/3263), how different is your current setup to the one described there?

Regards,  
Luis

---

<div class="post-metadata">

**Author:** ![chaithanya](https://avatars.discourse-cdn.com/v4/letter/c/b4bc9f/32.png) [@chaithanya](https://hub.mender.io/u/chaithanya)\
**Post date:** [August 12, 2021, 6:43am UTC](https://hub.mender.io/t/understanding-mutual-tls/3988/3 "2021-08-12T06:43:03Z")

</div>

@lramirez

Thank you for your response.

I have not gone through preauthorizing the device. Do I need to preauthorize the device first and then go for mutual tls?

Regards,  
Chaithanya

---

<div class="post-metadata">

**Author:** ![eystein](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@eystein](https://hub.mender.io/u/eystein)\
**Post date:** [September 2, 2021, 6:14pm UTC](https://hub.mender.io/t/understanding-mutual-tls/3988/4 "2021-09-02T18:14:32Z")

</div>

No need to preauthorize first. mTLS automatically authorizes the device based on device certificate.

---

<div class="post-metadata">

**Author:** ![shaomai](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@shaomai](https://hub.mender.io/u/shaomai)\
**Post date:** [November 17, 2022, 10:24am UTC](https://hub.mender.io/t/understanding-mutual-tls/3988/5 "2022-11-17T10:24:46Z")

</div>

Hi @chaithanya ,

did your device connect to the Edge proxy or to the hosted server?

The device should connect to edge proxy domain name. If the device connects to hosted server, then it will be in the pending list.

Best regards
