The Argo CD server presents a self-signed (or private-CA) certificate your machine does not trust - TLS verification fails before any credential is sent. For labs, argocd login --insecure skips verification; for anything real, add the server's CA to the system trust store (or pass the CA properly) instead of training yourself to ignore TLS.

## The error
```text
FATA[0000] x509: certificate signed by unknown authority
```

## What to do
1. Lab-only quick path:
```bash
argocd login [server] --insecure --username [user]
```
   Expected: Login succeeds with verification skipped.
2. Proper fix: fetch the server CA and add it to the OS trust store (Linux: /usr/local/share/ca-certificates + update-ca-certificates; macOS: Keychain).
   Expected: System trusts the CA.
3. Log in normally:
```bash
argocd login [server] --username [user]
```
   Expected: Succeeds without --insecure.

## When this applies
- the exact x509: certificate signed by unknown authority message
- self-signed Argo CD installs
- private-CA corporate environments

## When it does NOT apply
- certificate expired (different x509 message - renew the cert)
- hostname mismatch (cert valid, wrong name - fix DNS or the cert)

## Works with
argocd CLI 2.x/3.x

### x509: certificate has expired or is not yet valid
Clock skew or an actually expired cert. Check date on both ends, then renew.

## Why it happens
argocd-server generates a self-signed cert at install unless you provide one. The CLI verifies TLS like any HTTPS client, and an unknown CA fails the handshake.

## Edge cases
- --insecure is stored per context; teammates copying your config inherit the skip - document it.
- Some setups terminate TLS at the ingress with a public cert - then this error means you are hitting the wrong endpoint.

## Resolved from
computingforgeeks argocd login guide - https://computingforgeeks.com/argocd-cli-login-authentication/