argocd login fails: x509: certificate signed by unknown authority
Routes argocd CLI TLS trust failures. Use when argocd login fails with x509 certificate signed by unknown authority. Not for grpc-web or credential errors.
The Argo CD server presents a self-signed (or private-CA) certificate your machine does not trust - TLS verification fails before any credential is sent. For labs, argocd login --insecure skips verification; for anything real, add the server's CA to the system trust store (or pass the CA properly) instead of training yourself to ignore TLS.
The error
FATA[0000] x509: certificate signed by unknown authorityWhat to do
- Lab-only quick path:
argocd login [server] --insecure --username [user]Expected: Login succeeds with verification skipped.
- Proper fix: fetch the server CA and add it to the OS trust store (Linux: /usr/local/share/ca-certificates + update-ca-certificates; macOS: Keychain).
Expected: System trusts the CA.
- Log in normally:
argocd login [server] --username [user]Expected: Succeeds without --insecure.
When this applies
- the exact x509: certificate signed by unknown authority message
- self-signed Argo CD installs
- private-CA corporate environments
When it does NOT apply
- certificate expired (different x509 message - renew the cert)
- hostname mismatch (cert valid, wrong name - fix DNS or the cert)
Works with
argocd CLI 2.x/3.x
x509: certificate has expired or is not yet valid
Clock skew or an actually expired cert. Check date on both ends, then renew.
Why it happens
argocd-server generates a self-signed cert at install unless you provide one. The CLI verifies TLS like any HTTPS client, and an unknown CA fails the handshake.
Edge cases
- --insecure is stored per context; teammates copying your config inherit the skip - document it.
- Some setups terminate TLS at the ingress with a public cert - then this error means you are hitting the wrong endpoint.
Resolved from
computingforgeeks argocd login guide - https://computingforgeeks.com/argocd-cli-login-authentication/
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.