{"record":{"id":"10d1f35e1d640069","repo":"hashicorp/terraform","slug":"client-private-key-pem-is-set-but-client-certifica","errorCode":null,"errorMessage":"client_private_key_pem is set but client_certificate_pem is not","messagePattern":"client_private_key_pem is set but client_certificate_pem is not","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/http/backend.go","lineNumber":279,"sourceCode":"\t\tconfigVal, \"client_ca_certificate_pem\",\n\t\t\"TF_HTTP_CLIENT_CA_CERTIFICATE_PEM\", cty.StringVal(\"\"),\n\t).AsString()\n\tclientCertificatePem := backendbase.GetAttrEnvDefaultFallback(\n\t\tconfigVal, \"client_certificate_pem\",\n\t\t\"TF_HTTP_CLIENT_CERTIFICATE_PEM\", cty.StringVal(\"\"),\n\t).AsString()\n\tclientPrivateKeyPem := backendbase.GetAttrEnvDefaultFallback(\n\t\tconfigVal, \"client_private_key_pem\",\n\t\t\"TF_HTTP_CLIENT_PRIVATE_KEY_PEM\", cty.StringVal(\"\"),\n\t).AsString()\n\tif !skipCertVerification && clientCACertificatePem == \"\" && clientCertificatePem == \"\" && clientPrivateKeyPem == \"\" {\n\t\treturn nil\n\t}\n\tif clientCertificatePem != \"\" && clientPrivateKeyPem == \"\" {\n\t\treturn fmt.Errorf(\"client_certificate_pem is set but client_private_key_pem is not\")\n\t}\n\tif clientPrivateKeyPem != \"\" && clientCertificatePem == \"\" {\n\t\treturn fmt.Errorf(\"client_private_key_pem is set but client_certificate_pem is not\")\n\t}\n\n\t// TLS configuration is needed; create an object and configure it\n\tvar tlsConfig tls.Config\n\tclient.HTTPClient.Transport.(*http.Transport).TLSClientConfig = &tlsConfig\n\n\tif skipCertVerification {\n\t\t// ignores TLS verification\n\t\ttlsConfig.InsecureSkipVerify = true\n\t}\n\tif clientCACertificatePem != \"\" {\n\t\t// trust servers based on a CA\n\t\ttlsConfig.RootCAs = x509.NewCertPool()\n\t\tif !tlsConfig.RootCAs.AppendCertsFromPEM([]byte(clientCACertificatePem)) {\n\t\t\treturn errors.New(\"failed to append certs\")\n\t\t}\n\t}\n\tif clientCertificatePem != \"\" && clientPrivateKeyPem != \"\" {","sourceCodeStart":261,"sourceCodeEnd":297,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/backend.go#L261-L297","documentation":"Inverse of error 248: client_private_key_pem (or TF_HTTP_CLIENT_PRIVATE_KEY_PEM) is non-empty while client_certificate_pem (or TF_HTTP_CLIENT_CERTIFICATE_PEM) is empty. A private key alone cannot complete a TLS client-auth handshake; the certificate is required.","triggerScenarios":"Private key supplied but the matching certificate was omitted.","commonSituations":"Certificate stored separately and not referenced; cert line dropped during templating; only the key was migrated to a new config.","solutions":["Set client_certificate_pem to the PEM certificate matching the private key.","If mTLS is not required, remove client_private_key_pem entirely.","Ensure TF_HTTP_CLIENT_CERTIFICATE_PEM and TF_HTTP_CLIENT_PRIVATE_KEY_PEM are both exported."],"exampleFix":"// before\nclient_private_key_pem = file(\"client.key\")\n// client_certificate_pem missing\n// after\nclient_certificate_pem = file(\"client.crt\")\nclient_private_key_pem = file(\"client.key\")","handlingStrategy":"validation","validationCode":"# Pre-flight: key and cert must both be set (or both unset)\ncert=\"${TF_HTTP_CLIENT_CERTIFICATE_PEM:-}\"\nkey=\"${TF_HTTP_CLIENT_PRIVATE_KEY_PEM:-}\"\nif [ -n \"$key\" ] && [ -z \"$cert\" ]; then\n  echo \"ERROR: client_private_key_pem set but client_certificate_pem is empty\"; exit 1\nfi","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always configure client_certificate_pem and client_private_key_pem as a pair.","If mTLS is not needed, leave both unset.","In CI, assert both TF_HTTP_CLIENT_*_PEM vars are exported together."],"tags":["config","tls","mtls","http-backend","validation"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}