{"record":{"id":"1fda7c882c41f821","repo":"gofiber/fiber","slug":"tls-autocertmanager-cannot-be-combined-with-certf","errorCode":null,"errorMessage":"tls: AutoCertManager cannot be combined with CertFile/CertKeyFile","messagePattern":"tls: AutoCertManager cannot be combined with CertFile/CertKeyFile","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"error.go","lineNumber":24,"sourceCode":"\n\t\"github.com/gofiber/schema\"\n)\n\n// Wrap and return this for unreachable code if panicking is undesirable (i.e., in a handler).\n// Unexported because users will hopefully never need to see it.\nvar errUnreachable = errors.New(\"fiber: unreachable code, please create an issue at github.com/gofiber/fiber\")\n\n// General errors\nvar (\n\tErrGracefulTimeout = errors.New(\"shutdown: graceful timeout has been reached, exiting\")\n\t// ErrNotRunning indicates that a Shutdown method was called when the server was not running.\n\tErrNotRunning = errors.New(\"shutdown: server is not running\")\n\t// ErrHandlerExited is returned by App.Test if a handler panics or calls runtime.Goexit().\n\tErrHandlerExited = errors.New(\"runtime.Goexit() called in handler or server panic\")\n\t// ErrNoViewEngineConfigured indicates that a helper requiring a view engine was invoked without one configured.\n\tErrNoViewEngineConfigured = errors.New(\"fiber: no view engine configured\")\n\t// ErrAutoCertWithCertFile indicates AutoCertManager cannot be used with CertFile/CertKeyFile.\n\tErrAutoCertWithCertFile = errors.New(\"tls: AutoCertManager cannot be combined with CertFile/CertKeyFile\")\n\t// ErrRouteNotRepresentable indicates a route whose path no relative URL can\n\t// name, so Route.URL, GetRouteURL and Redirect().Route cannot compose one.\n\t// A path starting with two or more slashes is such a route: the URL that\n\t// would reach it opens an authority instead.\n\tErrRouteNotRepresentable = errors.New(\"router: route path cannot be expressed as a relative URL\")\n)\n\n// Fiber redirection errors\nvar (\n\tErrRedirectBackNoFallback = NewError(StatusInternalServerError, \"Referer not found, you have to enter fallback URL for redirection.\")\n)\n\n// Range errors\nvar (\n\t// ErrRangeMalformed is returned for a syntactically invalid Range header,\n\t// which RFC 9110 Section 14.2 allows a server to reject; it carries a\n\t// 400 Bad Request status so propagating it does not surface as a 500.\n\tErrRangeMalformed = NewError(StatusBadRequest, \"range: malformed range header string\")","sourceCodeStart":6,"sourceCodeEnd":42,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/error.go#L6-L42","documentation":"ErrAutoCertWithCertFile is returned by App.Listen (listen.go:226) when a ListenConfig supplies both an AutoCertManager and at least one of CertFile or CertKeyFile. These two TLS sources are mutually exclusive because autocert manages its certificates internally, so letting the caller also pin a static cert would produce ambiguous TLS behavior.","triggerScenarios":"Calling app.Listen(addr, fiber.ListenConfig{AutoCertManager: mgr, CertFile: \"fullchain.pem\", CertKeyFile: \"privkey.pem\"}). The switch in listen.go:225-227 sees both sources and returns the sentinel before configuring any TLS.","commonSituations":"Migrating from static certs to Let's Encrypt autocert and forgetting to clear the CertFile/CertKeyFile fields; copy-pasting a ListenConfig struct; combining staging and production TLS configs.","solutions":["For autocert, omit CertFile and CertKeyFile: app.Listen(addr, fiber.ListenConfig{AutoCertManager: mgr}).","For static certs, omit AutoCertManager: app.Listen(addr, fiber.ListenConfig{CertFile: cf, CertKeyFile: kf}).","Centralize TLS configuration in one struct so the two sources are never both populated."],"exampleFix":"// before\napp.Listen(\":443\", fiber.ListenConfig{\n    AutoCertManager: mgr,\n    CertFile:        \"fullchain.pem\",\n    CertKeyFile:     \"privkey.pem\",\n})\n// after\napp.Listen(\":443\", fiber.ListenConfig{\n    AutoCertManager: mgr,\n})","handlingStrategy":"validation","validationCode":"// Reject incompatible TLS configs before calling Listen.\nfunc validateTLS(cfg fiber.ListenConfig) error {\n    if cfg.AutoCertManager != nil && (cfg.CertFile != \"\" || cfg.CertKeyFile != \"\") {\n        return fiber.ErrAutoCertWithCertFile\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"if err := app.Listen(\":443\", cfg); err != nil {\n    if errors.Is(err, fiber.ErrAutoCertWithCertFile) {\n        log.Fatal(\"choose either AutoCertManager OR CertFile/CertKeyFile, not both\")\n    }\n    log.Fatal(err)\n}","preventionTips":["Use one struct to assemble TLS config so the two sources are never both populated.","When migrating from static certs to autocert, clear CertFile and CertKeyFile explicitly.","Add a startup test that asserts validateTLS(cfg) returns nil for production configs."],"tags":["tls","listen","config","autocert","startup"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}