# Fail to login opal server: untrusted authority

**URL:** <https://datashield.discourse.group/t/fail-to-login-opal-server-untrusted-authority/282>\
**Category:** Analyst Support\
**Created:** [20 October 2020 16:41 UTC](https://datashield.discourse.group/t/fail-to-login-opal-server-untrusted-authority/282 "2020-10-20T16:41:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![HankCao](https://avatars.discourse-cdn.com/v4/letter/h/b782af/32.png) [@HankCao](https://datashield.discourse.group/u/HankCao)\
**Post date:** [20 October 2020 16:41 UTC](https://datashield.discourse.group/t/fail-to-login-opal-server-untrusted-authority/282/1 "2020-10-20T16:41:56Z")

</div>

Dear all,

One of our server successfully installed opal, and we can manage the data via the webbrowser. However, when it come to the R codes, we can not login. See errors below:

```
library("opalr")
> o2=opal.login(url = "xxxx:xxx", user = "xxxx", password = "xxxx")
Error in curl::curl_fetch_memory(url, handle = handle) : 
  schannel: next InitializeSecurityContext failed: SEC_E_UNTRUSTED_ROOT (0x80090325) - The certificate chain was issued by an authority that is not trusted.

```

Does anyone know how to solve it?

Regards, Hank

---

<div class="post-metadata">

**Author:** ![swheater](https://yyz2.discourse-cdn.com/free1/user_avatar/datashield.discourse.group/swheater/32/182_2.png) [@swheater](https://datashield.discourse.group/u/swheater)\
**Post date:** [20 October 2020 18:07 UTC](https://datashield.discourse.group/t/fail-to-login-opal-server-untrusted-authority/282/2 "2020-10-20T18:07:53Z")

</div>

HI Hank,

I suspect you need to use the DSI R Package, try:

```
require('DSI')
require('DSOpal')

builder <- DSI::newDSLoginBuilder()
builder$append(server = "study1", 
              url = "http://xxxx.xxxx:xxxx/", 
              user = "xxxx", password = "xxxx", 
              table = "xxxx.xxxx", driver = "OpalDriver")
logindata <- builder$build()

connections <- DSI::datashield.login(logins = logindata, assign = TRUE, symbol = "D") 

. . . 

DSI::datashield.logout(connections) 

```

Stuart

---

<div class="post-metadata">

**Author:** ![yannick](https://yyz2.discourse-cdn.com/free1/user_avatar/datashield.discourse.group/yannick/32/19_2.png) [@yannick](https://datashield.discourse.group/u/yannick)\
**Post date:** [21 October 2020 11:35 UTC](https://datashield.discourse.group/t/fail-to-login-opal-server-untrusted-authority/282/4 "2020-10-21T11:35:32Z")

</div>

Hi,

Most probably it is a proxy issue. Some proxy block user clients that are scripts (such as R) and let the ones that are browsers work. You should check with the institution’s IT department.

Regards  
Yannick

---

<div class="post-metadata">

**Author:** ![HankCao](https://avatars.discourse-cdn.com/v4/letter/h/b782af/32.png) [@HankCao](https://datashield.discourse.group/u/HankCao)\
**Post date:** [21 October 2020 11:39 UTC](https://datashield.discourse.group/t/fail-to-login-opal-server-untrusted-authority/282/5 "2020-10-21T11:39:50Z")

</div>

Thanks, we were checking that.

Regards, Hank

---

<div class="post-metadata">

**Author:** ![swheater](https://yyz2.discourse-cdn.com/free1/user_avatar/datashield.discourse.group/swheater/32/182_2.png) [@swheater](https://datashield.discourse.group/u/swheater)\
**Post date:** [11 November 2020 16:12 UTC](https://datashield.discourse.group/t/fail-to-login-opal-server-untrusted-authority/282/6 "2020-11-11T16:12:34Z")

</div>

Hank,

I have just encountered a similar problem when accessing, over https, an Opal server with a self-signed, from Windows (Linux not a problem).

The workaround I found was to set the curl backend to openssl, using the command `Sys.setenv(CURL_SSL_BACKEND = "openssl")` or I believe you can add the line `CURL_SSL_BACKEND=openssl` to the “.Renviron” file in your R project.

Stuart

---

<div class="post-metadata">

**Author:** ![HankCao](https://avatars.discourse-cdn.com/v4/letter/h/b782af/32.png) [@HankCao](https://datashield.discourse.group/u/HankCao)\
**Post date:** [12 November 2020 10:34 UTC](https://datashield.discourse.group/t/fail-to-login-opal-server-untrusted-authority/282/7 "2020-11-12T10:34:05Z")

</div>

Dear swheater,

Thanks for the information. I just tried this solution, unfortunately it does not work for us.

Alternatively, we used a “risk” way to avoid the issue:

```
> library(httr)
> httr_options()
> set_config( config( ssl_verifypeer = 0L ) )
> set_config(config(ssl_verifyhost = 0L ))

```

This would shut down the “signature check”. For now, this is the only solution we found.

Regards, Hank
