{"record":{"id":"6405d99c2fd4d6cd","repo":"grpc/grpc-go","slug":"xds-fetching-identity-certificates-from-certifica","errorCode":null,"errorMessage":"xds: fetching identity certificates from CertificateProvider failed: %v","messagePattern":"xds: fetching identity certificates from CertificateProvider failed: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/credentials/xds/handshake_info.go","lineNumber":242,"sourceCode":"\t\treturn nil, fmt.Errorf(\"xds: fetching trusted roots from CertificateProvider failed: %v\", err)\n\t}\n\tcfg.RootCAs = km.Roots\n\n\t// If AutoHostSNI is true, and the endpoint hostname is present, we use the\n\t// endpoint hostname as the SNI value and also for SAN validation.\n\t// Otherwise, we use the SNI value from HandshakeInfo (which is configured\n\t// by the control plane) and validating SANs based on that.\n\tsni := hi.sni\n\tif hi.useAutoHostSNI && hostname != \"\" {\n\t\tsni = hostname\n\t}\n\n\tcfg.VerifyPeerCertificate = hi.buildVerifyFunc(km, true, sni)\n\n\tif hi.identityProvider != nil {\n\t\tkm, err := hi.identityProvider.KeyMaterial(ctx)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"xds: fetching identity certificates from CertificateProvider failed: %v\", err)\n\t\t}\n\t\tcfg.Certificates = km.Certs\n\t}\n\n\tif envconfig.XDSSNIEnabled && sni != \"\" {\n\t\tcfg.ServerName = sni\n\t}\n\treturn cfg, nil\n}\n\nfunc (hi *HandshakeInfo) buildVerifyFunc(km *certprovider.KeyMaterial, isClient bool, sni string) func(rawCerts [][]byte, _ [][]*x509.Certificate) error {\n\treturn func(rawCerts [][]byte, _ [][]*x509.Certificate) error {\n\t\tif len(rawCerts) == 0 {\n\t\t\treturn fmt.Errorf(\"xds: no peer certificates presented\")\n\t\t}\n\t\t// Parse all raw certificates presented by the peer.\n\t\tvar certs []*x509.Certificate\n\t\tfor _, rc := range rawCerts {","sourceCodeStart":224,"sourceCodeEnd":260,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/credentials/xds/handshake_info.go#L224-L260","documentation":"Raised on the client side during xDS-driven mTLS when hi.identityProvider.KeyMaterial(ctx) returns an error. The identity (client) certificate provider could not return the client cert/key pair the server requires for mutual TLS.","triggerScenarios":"The identity cert/key files are missing or unreadable; the xDS control plane did not deliver an identity CertificateProviderInstance; the provider was closed; the private key does not match the certificate; the context was cancelled mid-handshake.","commonSituations":"Workload identity secret not mounted; cert/key rotation left the provider with a half-written file; mTLS required by server (requireClientCert) but client identity not provisioned; provider plugin misconfigured in the bootstrap.","solutions":["Verify the identity provider config points to valid, readable cert and key files (or the correct xDS resource name).","Confirm the cert and key match (no rotation half-state) and are valid PEM.","Ensure the xDS management server advertises an identity CertificateProviderInstance for this client.","Check the provider is still open and the context is live at handshake time.","If mTLS is not intended, reconfigure the cluster so the server does not require client certs."],"exampleFix":"// before: identity provider points at /etc/certs/client.crt which is absent\n// after: provision and mount client.crt + client.key, reload provider","handlingStrategy":"try-catch","validationCode":"func identityProviderHealthy(p certprovider.Provider) bool {\n    ctx, cancel := context.WithTimeout(context.Background(), 2*time.Second)\n    defer cancel()\n    km, err := p.KeyMaterial(ctx)\n    return err == nil && km != nil && len(km.Certs) > 0\n}","typeGuard":null,"tryCatchPattern":"Treat 'fetching identity certificates failed' as a fatal mTLS setup problem: do not open new RPCs until the provider returns valid KeyMaterial; surface the underlying provider error to the operator.","preventionTips":["Provision workload identity cert+key as a mounted secret with atomic rotation.","Verify cert and key match after each rotation (no half-state).","Add a readiness probe that calls KeyMaterial before marking the pod ready."],"tags":["grpc","xds","tls","mtls","certificates","security","config"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}