# Fail to verify delegation certificate

**URL:** <https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125>\
**Category:** Developers\
**Created:** [February 25, 2022, 9:07am UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125 "2022-02-25T09:07:43Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![shashika](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/shashika/32/4622_2.png) [@shashika](https://forum.dfinity.org/u/shashika)\
**Post date:** [February 25, 2022, 9:07am UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125/1 "2022-02-25T09:07:43Z")

</div>

I tried to pass identity using the key file as below.

```auto
public async init(host: string, idlFactory: IDL.InterfaceFactory, canisterId: string, keyFile?: string) : Promise<void> {
        try {
            let identity = undefined;
            if (keyFile) {
                const rawKey = fs
                    .readFileSync(keyFile, 'utf8')
                    .toString()
                    .replace("-----BEGIN EC PRIVATE KEY-----", "")
                    .replace("-----END EC PRIVATE KEY-----", "")
                    .trim();
                    console.log(rawKey);
                // const rawBuffer = Buffer.from(rawKey, 'utf-8');

                // Convert the pem file to a sha256 hash
                const privKey = Uint8Array.from(sha256(rawKey, { asBytes: true }));

                // Initialize an identity from the secret key
                identity = Secp256k1KeyIdentity.fromSecretKey(
                    Uint8Array.from(privKey).buffer
                );
                console.log(identity.getPrincipal().toText());
            }
            const agent = new HttpAgent({ host, fetch: fetch as any, identity });
            
            // if (process.env.PRODUCTION === undefined || process.env.PRODUCTION !== 'prod') {
            // await agent.fetchRootKey();
            // }

            this.actor = Actor.createActor(idlFactory,{
                agent,
                canisterId,
            });
        } catch (err) {
            return Promise.reject(err);
        }
    }

```

I’m getting an error `fail to verify delegation certificate`  
I printed out the principle as well and the generated one is different than my actual principle id.  
I really appriciate someone can help me to resolve this issue.

---

<div class="post-metadata">

**Author:** ![peterparker](https://avatars.discourse-cdn.com/v4/letter/p/b9bd4f/32.png) [@peterparker](https://forum.dfinity.org/u/peterparker)\
**Post date:** [February 25, 2022, 10:30am UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125/2 "2022-02-25T10:30:54Z")

</div>

I tried quite a bit too (see this [post](https://forum.dfinity.org/t/where-actually-is-the-dfx-idendity-pem-file/10881)) but did not manage to make it neither.

At the end of the day, if your goal is to reproduce itentities from `dfx` in `agent-js`, it might just unfortunately not be possible at the moment 👉 [Using @dfinity/agent in node.js - #39 by kpeacock](https://forum.dfinity.org/t/using-dfinity-agent-in-node-js/6169/39)

---

<div class="post-metadata">

**Author:** ![anon74414410](https://avatars.discourse-cdn.com/v4/letter/a/85f322/32.png) [@anon74414410](https://forum.dfinity.org/u/anon74414410)\
**Post date:** [February 25, 2022, 3:33pm UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125/3 "2022-02-25T15:33:34Z")

</div>

It’s definitely possible to get a reproducible identity from a PEM file, but reproducing the exact behavior from the Rust library used by `dfx` to parse .pem files takes a lot of work.

I suggest structuring your code with the assumption of multiple controllers or privileged users, and then using a separate identity in JS from your command line

---

<div class="post-metadata">

**Author:** ![shashika](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/shashika/32/4622_2.png) [@shashika](https://forum.dfinity.org/u/shashika)\
**Post date:** [February 28, 2022, 4:57am UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125/4 "2022-02-28T04:57:39Z")

</div>

Thanks for the reply @anon74414410. Actually, What I’m trying to do is that deploy a serverless application that interacts with the ICP

---

<div class="post-metadata">

**Author:** ![shashika](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/shashika/32/4622_2.png) [@shashika](https://forum.dfinity.org/u/shashika)\
**Post date:** [March 3, 2022, 11:48am UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125/5 "2022-03-03T11:48:43Z")

</div>

Any updates on this?

---

<div class="post-metadata">

**Author:** ![GLdev](https://avatars.discourse-cdn.com/v4/letter/g/4bbf92/32.png) [@GLdev](https://forum.dfinity.org/u/GLdev)\
**Post date:** [March 3, 2022, 12:01pm UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125/6 "2022-03-03T12:01:04Z")

</div>

> [@shashika](#):
>
> What I’m trying to do is that deploy a serverless application that interacts with the ICP

Could rust be an option for you for this project? Rust is often touted as the future of serverless, and for good reasons.

---

<div class="post-metadata">

**Author:** ![shashika](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/shashika/32/4622_2.png) [@shashika](https://forum.dfinity.org/u/shashika)\
**Post date:** [March 4, 2022, 4:15am UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125/7 "2022-03-04T04:15:39Z")

</div>

Thanks for the reply @GLdev. I wrapped a nestjs project inside my serverless application that has been written in Typescript. So using Rust maybe not be possible for me. Is there any other way to set identity in the javascript client?

---

<div class="post-metadata">

**Author:** ![GLdev](https://avatars.discourse-cdn.com/v4/letter/g/4bbf92/32.png) [@GLdev](https://forum.dfinity.org/u/GLdev)\
**Post date:** [March 4, 2022, 5:34am UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125/8 "2022-03-04T05:34:09Z")

</div>

I would go the route suggested in another post: create an arbitrary identity and add it in your ACL on the canister side, so you can accept messages from it. A new feature of dfx is that you can add multiple controllers, so that could also be done.

Basically with this new feature you shouldn’t need to add the exact same key from dfx to your serverless functions. You can use different identities and just add them as controllers / in the ACL

---

<div class="post-metadata">

**Author:** ![shashika](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/shashika/32/4622_2.png) [@shashika](https://forum.dfinity.org/u/shashika)\
**Post date:** [March 4, 2022, 5:51am UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125/9 "2022-03-04T05:51:11Z")

</div>

Could you share some useful resources with me?  
Another quick question if you could help, I printed out the caller’s identity in a canister function in my local development environment and I called the function from Nodejs client by fetching the root key. It doesn’t match the principal id of mine. Why is that?

---

<div class="post-metadata">

**Author:** ![shashika](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/shashika/32/4622_2.png) [@shashika](https://forum.dfinity.org/u/shashika)\
**Post date:** [March 14, 2022, 9:13am UTC](https://forum.dfinity.org/t/fail-to-verify-delegation-certificate/11125/10 "2022-03-14T09:13:34Z")

</div>

I was possible to generate the principle id as in the following post and generated a new identity using the keysmith tool. Use **seeds** example.

> [@Using @dfinity/agent in node.js](https://forum.dfinity.org/t/using-dfinity-agent-in-node-js/6169/40):
>
> It might be happening on tweetnacl, better using try catch and loop the keypair function

> **[GitHub - dfinity/keysmith: Hierarchical Deterministic Key Derivation for the...](https://github.com/dfinity/keysmith)**
>
> Hierarchical Deterministic Key Derivation for the Internet Computer - GitHub - dfinity/keysmith: Hierarchical Deterministic Key Derivation for the Internet Computer

It’ll be very useful if someone can document these since a lot of developers facing the same kind of issues. Thank you very much for helping me guys.
