VectleSkillsargocd login fails: x509: certificate signed by unknown authority

argocd login fails: x509: certificate signed by unknown authority

Export

Routes argocd CLI TLS trust failures. Use when argocd login fails with x509 certificate signed by unknown authority. Not for grpc-web or credential errors.

The Argo CD server presents a self-signed (or private-CA) certificate your machine does not trust - TLS verification fails before any credential is sent. For labs, argocd login --insecure skips verification; for anything real, add the server's CA to the system trust store (or pass the CA properly) instead of training yourself to ignore TLS.

The error

FATA[0000] x509: certificate signed by unknown authority

What to do

  1. Lab-only quick path:
argocd login [server] --insecure --username [user]

Expected: Login succeeds with verification skipped.

  1. Proper fix: fetch the server CA and add it to the OS trust store (Linux: /usr/local/share/ca-certificates + update-ca-certificates; macOS: Keychain).

Expected: System trusts the CA.

  1. Log in normally:
argocd login [server] --username [user]

Expected: Succeeds without --insecure.

When this applies

  • the exact x509: certificate signed by unknown authority message
  • self-signed Argo CD installs
  • private-CA corporate environments

When it does NOT apply

  • certificate expired (different x509 message - renew the cert)
  • hostname mismatch (cert valid, wrong name - fix DNS or the cert)

Works with

argocd CLI 2.x/3.x

x509: certificate has expired or is not yet valid

Clock skew or an actually expired cert. Check date on both ends, then renew.

Why it happens

argocd-server generates a self-signed cert at install unless you provide one. The CLI verifies TLS like any HTTPS client, and an unknown CA fails the handshake.

Edge cases

  • --insecure is stored per context; teammates copying your config inherit the skip - document it.
  • Some setups terminate TLS at the ingress with a public cert - then this error means you are hitting the wrong endpoint.

Resolved from

computingforgeeks argocd login guide - https://computingforgeeks.com/argocd-cli-login-authentication/

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=argocd+login+fails%3A+x509%3A+certificate+signed+by+unknown+authority&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.