{"record":{"id":"4a30b810daaf678e","repo":"gofiber/fiber","slug":"tls-cannot-load-tls-key-pair-from-certfile-q-and","errorCode":null,"errorMessage":"tls: cannot load TLS key pair from certFile=%q and keyFile=%q: %w","messagePattern":"tls: cannot load TLS key pair from certFile=%q and keyFile=%q: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"listen.go","lineNumber":230,"sourceCode":"func (app *App) Listen(addr string, config ...ListenConfig) error {\n\tcfg := listenConfigDefault(config...)\n\n\t// Configure TLS\n\tvar tlsConfig *tls.Config\n\tvar tlsHandler *TLSHandler\n\tif cfg.TLSConfig != nil {\n\t\ttlsConfig = cfg.TLSConfig.Clone()\n\t\twarnSupersededTLSFields(&cfg)\n\t} else {\n\t\tvalidateTLSMinVersion(&cfg)\n\n\t\tswitch {\n\t\tcase cfg.AutoCertManager != nil && (cfg.CertFile != \"\" || cfg.CertKeyFile != \"\"):\n\t\t\treturn ErrAutoCertWithCertFile\n\t\tcase cfg.CertFile != \"\" && cfg.CertKeyFile != \"\":\n\t\t\tcert, err := tls.LoadX509KeyPair(cfg.CertFile, cfg.CertKeyFile)\n\t\t\tif err != nil {\n\t\t\t\treturn fmt.Errorf(\"tls: cannot load TLS key pair from certFile=%q and keyFile=%q: %w\", cfg.CertFile, cfg.CertKeyFile, err)\n\t\t\t}\n\n\t\t\ttlsHandler = &TLSHandler{}\n\t\t\ttlsConfig = &tls.Config{\n\t\t\t\tMinVersion: cfg.TLSMinVersion,\n\t\t\t\tCertificates: []tls.Certificate{\n\t\t\t\t\tcert,\n\t\t\t\t},\n\t\t\t\tGetCertificate: tlsHandler.GetClientInfo,\n\t\t\t}\n\n\t\tcase cfg.AutoCertManager != nil:\n\t\t\ttlsConfig = &tls.Config{\n\t\t\t\tMinVersion:     cfg.TLSMinVersion,\n\t\t\t\tGetCertificate: cfg.AutoCertManager.GetCertificate,\n\t\t\t\tNextProtos:     []string{\"http/1.1\", \"acme-tls/1\"},\n\t\t\t}\n\t\tdefault:","sourceCodeStart":212,"sourceCodeEnd":248,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/listen.go#L212-L248","documentation":"Returned by App.Listen / ListenTLS at startup when tls.LoadX509KeyPair fails to load the configured CertFile and CertKeyFile. The error wraps the cert and key paths and the underlying crypto/tls error: 'tls: cannot load TLS key pair from certFile=\"server.crt\" and keyFile=\"server.key\": open server.crt: no such file or directory'. Fires only when both CertFile and CertKeyFile are set and TLSConfig is nil (the manual-cert branch at listen.go:227).","triggerScenarios":"Calling app.ListenTLS(...) or app.Listen(addr, WithTLS(cert, key)) where the cert or key file cannot be read or is not a valid PEM-encoded X.509 key pair. AutoCertManager being set with cert files returns a different error (ErrAutoCertWithCertFile) earlier.","commonSituations":"Wrong paths (relative path resolved against cwd, not source), cert/key not mounted into the container, permissions on the key file, PEM block missing or wrong type (e.g. cert file contains only the chain without the leaf, key file is PKCS#12 instead of PEM), expired/rotated cert files replaced incompletely, or cert and key swapped.","solutions":["Verify both files exist and are readable by the process uid; log their absolute paths at startup.","Confirm the key file is PEM-encoded (BEGIN PRIVATE KEY / BEGIN RSA PRIVATE KEY / BEGIN EC PRIVATE KEY) and matches the cert's public key.","Use absolute paths or resolve them from a known root; in containers, mount certs from a secret and reference the mount path.","Validate the pair in isolation with tls.LoadX509KeyPair in a tiny program or a startup self-check before Listen."],"exampleFix":"// before\napp.ListenTLS(\":443\", \"server.crt\", \"server.key\") // paths wrong / unreadable\n\n// after\nif _, err := tls.LoadX509KeyPair(certPath, keyPath); err != nil {\n    log.Fatalf(\"cert check failed: %v\", err)\n}\napp.ListenTLS(\":443\", certPath, keyPath)","handlingStrategy":"validation","validationCode":"// preflight: load and validate the cert/key pair before Listen\nif _, err := tls.LoadX509KeyPair(certFile, keyFile); err != nil {\n    log.Fatalf(\"invalid TLS key pair: %v\", err)\n}\nif _, err := os.Stat(certFile); err != nil { log.Fatal(err) }\nif _, err := os.Stat(keyFile); err != nil { log.Fatal(err) }","typeGuard":"null","tryCatchPattern":"if err := app.ListenTLS(\":443\", certFile, keyFile); err != nil {\n    if strings.Contains(err.Error(), \"cannot load TLS key pair\") {\n        log.Fatalf(\"TLS cert/key invalid: %v\", err)\n    }\n    log.Fatal(err)\n}","preventionTips":["Self-check tls.LoadX509KeyPair at startup before calling ListenTLS.","Use absolute paths or resolve from a known root; mount secrets in containers.","Confirm the key file is PEM and its type matches the cert (RSA/EC/private key).","Do not mix AutoCertManager with manual CertFile/CertKeyFile (that returns ErrAutoCertWithCertFile instead)."],"tags":["tls","startup","configuration","security","gofiber","certificates"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}