# Use ECC keys for authentication between Mender client server

**URL:** <https://hub.mender.io/t/use-ecc-keys-for-authentication-between-mender-client-server/2431>\
**Category:** General Discussions\
**Created:** [June 22, 2020, 8:03pm UTC](https://hub.mender.io/t/use-ecc-keys-for-authentication-between-mender-client-server/2431 "2020-06-22T20:03:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![msaenger](https://avatars.discourse-cdn.com/v4/letter/m/4da419/32.png) [@msaenger](https://hub.mender.io/u/msaenger)\
**Post date:** [June 22, 2020, 8:03pm UTC](https://hub.mender.io/t/use-ecc-keys-for-authentication-between-mender-client-server/2431/1 "2020-06-22T20:03:00Z")

</div>

Thanks for this! Very helpful guide.

I got all of this working just fine but would like to use ECC instead of RSA. I followed this guide and generated the ECC keys using the following:

```
openssl ecparam -genkey -name prime256v1 -out private-and-params.key
openssl ec -in private-and-params.key -out private.key
openssl ec -in private-and-params.key -pubout -out public.key

```

Then I use the same method to generate a signature

```
X_MEN_SIGNATURE=$(echo -n "${REQUEST_BODY}" | openssl dgst -sha256 -sign private.key | openssl base64 -A)

```

But when I go to send the authorization request I get an error about not being able to decode the public key. Any suggestions? Am I generating the keys correctly?

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [June 22, 2020, 8:48pm UTC](https://hub.mender.io/t/use-ecc-keys-for-authentication-between-mender-client-server/2431/2 "2020-06-22T20:48:16Z")

</div>

Hi @msaenger, glad you found the guide useful.

Regarding ECC, unfortunately this is a limitation in the backend and it only accepts RSA. It is something that we are looking at, but nothing committed yet.

---

<div class="post-metadata">

**Author:** ![msaenger](https://avatars.discourse-cdn.com/v4/letter/m/4da419/32.png) [@msaenger](https://hub.mender.io/u/msaenger)\
**Post date:** [June 22, 2020, 9:24pm UTC](https://hub.mender.io/t/use-ecc-keys-for-authentication-between-mender-client-server/2431/3 "2020-06-22T21:24:56Z")

</div>

Ah okay. Thanks for the quick response.

---

<div class="post-metadata">

**Author:** ![bunniesfield](https://avatars.discourse-cdn.com/v4/letter/b/0ea827/32.png) [@bunniesfield](https://hub.mender.io/u/bunniesfield)\
**Post date:** [April 22, 2022, 9:06am UTC](https://hub.mender.io/t/use-ecc-keys-for-authentication-between-mender-client-server/2431/4 "2022-04-22T09:06:57Z")

</div>

Hello.

I think the client side key-pair will be generated by keygen-client script. At this point this script only generates key pair using RSA algorithm for master branch or 3.2.x branch.

> <https://github.com/mendersoftware/mender/blob/3.2.x/support/keygen-client>

But now, the server side release note states there added ED25519 and ECDSA support.

> add support for ED25519 and ECDSA public keys in auth requests ([MEN-3728])

[https://docs.mender.io/3.2/release-information/release-notes-changelog/mender-server#deviceauth-2-4-0](https://docs.mender.io/3.2/release-information/release-notes-changelog/mender-server#deviceauth-2-4-0)

So how we can use ED25519 / ECDSA keys for client connection? Is it possible now?

---

<div class="post-metadata">

**Author:** ![dellgreen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dellgreen/32/85_2.png) [@dellgreen](https://hub.mender.io/u/dellgreen)\
**Post date:** [April 22, 2022, 10:12am UTC](https://hub.mender.io/t/use-ecc-keys-for-authentication-between-mender-client-server/2431/5 "2022-04-22T10:12:54Z")

</div>

If it helps, I have been using ECDSA secp384r1 with my mender 2.4.1 server for a year and a half now, albeit I manage the keys/certs myself rather than using the scripts. So there is support in the server for it now.

---

<div class="post-metadata">

**Author:** ![bunniesfield](https://avatars.discourse-cdn.com/v4/letter/b/0ea827/32.png) [@bunniesfield](https://hub.mender.io/u/bunniesfield)\
**Post date:** [April 24, 2022, 10:39am UTC](https://hub.mender.io/t/use-ecc-keys-for-authentication-between-mender-client-server/2431/6 "2022-04-24T10:39:39Z")

</div>

Oh that information is very helpful.  
Now I will try using ED25529 or ECDSA in keygen script and try confirming it is now working.
