{"record":{"id":"2113f5e7dc6f6df5","repo":"hashicorp/terraform","slug":"cannot-load-client-certificate-w","errorCode":null,"errorMessage":"cannot load client certificate: %w","messagePattern":"cannot load client certificate: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/http/backend.go","lineNumber":301,"sourceCode":"\tvar tlsConfig tls.Config\n\tclient.HTTPClient.Transport.(*http.Transport).TLSClientConfig = &tlsConfig\n\n\tif skipCertVerification {\n\t\t// ignores TLS verification\n\t\ttlsConfig.InsecureSkipVerify = true\n\t}\n\tif clientCACertificatePem != \"\" {\n\t\t// trust servers based on a CA\n\t\ttlsConfig.RootCAs = x509.NewCertPool()\n\t\tif !tlsConfig.RootCAs.AppendCertsFromPEM([]byte(clientCACertificatePem)) {\n\t\t\treturn errors.New(\"failed to append certs\")\n\t\t}\n\t}\n\tif clientCertificatePem != \"\" && clientPrivateKeyPem != \"\" {\n\t\t// attach a client certificate to the TLS handshake (aka mTLS)\n\t\tcertificate, err := tls.X509KeyPair([]byte(clientCertificatePem), []byte(clientPrivateKeyPem))\n\t\tif err != nil {\n\t\t\treturn fmt.Errorf(\"cannot load client certificate: %w\", err)\n\t\t}\n\t\ttlsConfig.Certificates = []tls.Certificate{certificate}\n\t}\n\n\treturn nil\n}\n\nfunc (b *Backend) StateMgr(name string) (statemgr.Full, tfdiags.Diagnostics) {\n\tvar diags tfdiags.Diagnostics\n\n\tif name != backend.DefaultStateName {\n\t\treturn nil, diags.Append(backend.ErrWorkspacesNotSupported)\n\t}\n\n\tsm := &remote.State{Client: b.client}\n\n\tif err := sm.RefreshState(); err != nil {\n\t\treturn nil, diags.Append(err)","sourceCodeStart":283,"sourceCodeEnd":319,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/backend.go#L283-L319","documentation":"tls.X509KeyPair(clientCertificatePem, clientPrivateKeyPem) failed. Both PEM strings were supplied but the pair could not be assembled into a tls.Certificate. The '%w' wraps the underlying crypto/tls error. Causes: invalid PEM encoding, wrong PEM block type (e.g. 'CERTIFICATE REQUEST' instead of 'CERTIFICATE'), a key that does not match the certificate, corrupted/truncated PEM, or an unsupported key type.","triggerScenarios":"Cert and key are both present but are not a matching pair; one is not valid PEM; the 'private key' file actually contains a public key or CSR; PEM bytes were mangled (line-wrapping, charset, escaping) by a secret store or shell.","commonSituations":"Pasted cert/key truncated; copied the public cert into the key field; cert and key generated for different subjects; CRLF vs LF line endings introduced by Windows; secret manager base64-encoded the value and it was not decoded.","solutions":["Regenerate the cert/key pair and verify both load: openssl x509 -in client.crt -noout -text and openssl rsa -in client.key -check.","Confirm the modulus matches: openssl x509 -in client.crt -modulus -noout | openssl md5 vs openssl rsa -in client.key -modulus | openssl md5.","Ensure each value is full PEM including '-----BEGIN CERTIFICATE-----'/'-----BEGIN PRIVATE KEY-----' headers and footers.","If reading via a secret manager, confirm the value is decoded (not base64) and uses LF line endings.","Use file() to load from disk rather than inlining PEM in HCL to avoid escaping issues."],"exampleFix":"// before (inline, often mangled)\nclient_certificate_pem = \"-----BEGIN CERTIFICATE-----\\nMIIB...==\\n-----END CERTIFICATE-----\"\nclient_private_key_pem  = \"-----BEGIN RSA PRIVATE KEY-----\\nMIIE...==\\n-----END RSA PRIVATE KEY-----\"\n// after (load full files from disk)\nclient_certificate_pem = file(\"${path.module}/client.crt\")\nclient_private_key_pem = file(\"${path.module}/client.key\")","handlingStrategy":"validation","validationCode":"# Pre-flight: verify the cert/key pair loads and the moduli match\nopenssl x509 -in client.crt -noout >/dev/null 2>&1 || { echo 'invalid cert PEM'; exit 1; }\nopenssl rsa -in client.key -check -noout >/dev/null 2>&1 || openssl pkey -in client.key -check -noout >/dev/null 2>&1 || { echo 'invalid key PEM'; exit 1; }\ncmp -s <(openssl x509 -in client.crt -modulus -noout | openssl md5) <(openssl rsa -in client.key -modulus 2>/dev/null | openssl md5) \\\n  || cmp -s <(openssl x509 -in client.crt -pubkey -noout | openssl md5) <(openssl pkey -in client.key -pubout 2>/dev/null | openssl md5) \\\n  || { echo 'cert and key do not match'; exit 1; }","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Load PEM with file() from disk rather than inlining to avoid escaping/charset issues.","Validate the cert/key pair with openssl before terraform init.","Confirm secret-manager values are decoded (not base64) and use LF line endings.","Regenerate the pair together and never mix certs and keys from different generations."],"tags":["tls","mtls","crypto","http-backend","config"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}