{"record":{"id":"0aa161f6909e964a","repo":"grpc/grpc-go","slug":"xds-certificateprovider-to-fetch-identity-certifi","errorCode":null,"errorMessage":"xds: CertificateProvider to fetch identity certificate is missing, cannot perform TLS handshake. Please check configuration on the management server","messagePattern":"xds: CertificateProvider to fetch identity certificate is missing, cannot perform TLS handshake\\. Please check configuration on the management server","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"internal/credentials/xds/handshake_info.go","lineNumber":334,"sourceCode":"\t\t\t// TODO: Print the complete certificate once the x509 package\n\t\t\t// supports a String() method on the Certificate type.\n\t\t\treturn fmt.Errorf(\"xds: received SANs {DNSNames: %v, EmailAddresses: %v, IPAddresses: %v, URIs: %v} do not match any of the accepted SANs\", cert.DNSNames, cert.EmailAddresses, cert.IPAddresses, cert.URIs)\n\t\t}\n\t\treturn nil\n\t}\n}\n\n// serverSideTLSConfigInternal constructs a tls.Config to be used in a\n// server-side handshake based on the contents of the HandshakeInfo.\nfunc (hi *HandshakeInfo) serverSideTLSConfigInternal(ctx context.Context) (*tls.Config, error) {\n\tcfg := &tls.Config{\n\t\tClientAuth: tls.NoClientCert,\n\t\tNextProtos: []string{\"h2\"},\n\t}\n\t// On the server side, identityProvider is mandatory. RootProvider is\n\t// optional based on whether the server is doing TLS or mTLS.\n\tif hi.identityProvider == nil {\n\t\treturn nil, errors.New(\"xds: CertificateProvider to fetch identity certificate is missing, cannot perform TLS handshake. Please check configuration on the management server\")\n\t}\n\tif hi.requireClientCert {\n\t\tcfg.ClientAuth = tls.RequireAndVerifyClientCert\n\t}\n\n\t// identityProvider is mandatory on the server side.\n\tkm, err := hi.identityProvider.KeyMaterial(ctx)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"xds: fetching identity certificates from CertificateProvider failed: %v\", err)\n\t}\n\tcfg.Certificates = km.Certs\n\n\tif hi.rootProvider != nil {\n\t\tkm, err := hi.rootProvider.KeyMaterial(ctx)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"xds: fetching trusted roots from CertificateProvider failed: %v\", err)\n\t\t}\n\t\tif km.SPIFFEBundleMap != nil && hi.requireClientCert {","sourceCodeStart":316,"sourceCodeEnd":352,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/credentials/xds/handshake_info.go#L316-L352","documentation":"Returned by serverSideTLSConfigInternal when hi.identityProvider is nil. On the server side, the identity certificate provider is mandatory—it supplies the server's own TLS certificate (the cert presented to clients). Without it the server has nothing to present in the handshake. The root provider is optional (needed only for mTLS client verification), but identity is always required.","triggerScenarios":"Server-side xDS TLS handshake where the HandshakeInfo exists and is not fallback but identityProvider is nil—NewHandshakeInfo was called with nil for the identity provider. This means the xDS server-side security config (UpstreamTLSContext on the xDS server, or DownstreamTLSContext for inbound) has no certificate (ServerCertificateProvider) configured.","commonSituations":"xDS management server sends a server-side security policy with a validation context (for verifying clients) but no server certificate; cert rotation job failed to provision the server cert SDS secret; Istio Gateway/VirtualService or PeerAuthentication configured for mTLS but the server's own cert SDS resource is missing.","solutions":["On the xDS management server, configure the server-side TLS context with a certificate provider (ServerCertificateProvider or TlsCertificate) that supplies the server's identity certificate.","If using SDS (Secret Discovery Service), verify the server certificate secret is provisioned and accessible.","Check the SDS/secret agent logs for certificate fetch failures.","Confirm the xDS LDS listener resource has a CommonHttpProtocolOptions.tls_context with certificates populated."],"exampleFix":"// Ensure server-side xDS config includes a certificate provider.\n// On Istio, verify the Gateway has a server certificate:\n// before: Gateway with tls but no credentialName\n// after:\nspec:\n  servers:\n  - port:\n      number: 443\n      name: https\n      protocol: HTTPS\n    tls:\n      mode: SIMPLE\n      credentialName: server-cert  # <-- provides identity provider","handlingStrategy":"validation","validationCode":"// Server-side: verify the identity certificate provider is configured.\n// Check the xDS listener resource has certificates in the TLS context.\n//   istioctl proxy-config listener <pod> -o json | jq '...certificates...'\n// Ensure SDS has the server cert secret provisioned.","typeGuard":null,"tryCatchPattern":"// This is a server-side startup error; the server cannot handshake without identity cert.\n// Catch is not applicable—fix the xDS config.\n// Log and alert:\nlog.Fatal(\"xDS security config missing identity certificate provider; cannot serve TLS\")","preventionTips":["Always configure a server certificate (identity provider) in xDS server-side TLS.","Provision SDS secrets for the server cert before starting the server.","Monitor certificate provisioning and rotation health.","Run istioctl analyze or equivalent config validation before deployment."],"tags":["xds","tls","server","credentials","certificates","grpc"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}