{"record":{"id":"6e4d265280282dd8","repo":"siyuan-note/siyuan","slug":"failed-to-parse-ca-certificate-w","errorCode":null,"errorMessage":"failed to parse CA certificate: %w","messagePattern":"failed to parse CA certificate: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/util/cert.go","lineNumber":323,"sourceCode":"\t}\n\n\tif err = pem.Encode(keyFile, &pem.Block{Type: \"EC PRIVATE KEY\", Bytes: keyDER}); err != nil {\n\t\treturn err\n\t}\n\n\treturn nil\n}\n\n// ImportCABundle imports a CA certificate and private key from PEM-encoded strings.\nfunc ImportCABundle(caCertPEM, caKeyPEM string) error {\n\tcertBlock, _ := pem.Decode([]byte(caCertPEM))\n\tif certBlock == nil {\n\t\treturn fmt.Errorf(\"failed to decode CA certificate PEM\")\n\t}\n\n\tcaCert, err := x509.ParseCertificate(certBlock.Bytes)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"failed to parse CA certificate: %w\", err)\n\t}\n\n\tif !caCert.IsCA {\n\t\treturn fmt.Errorf(\"the provided certificate is not a CA certificate\")\n\t}\n\n\tkeyBlock, _ := pem.Decode([]byte(caKeyPEM))\n\tif keyBlock == nil {\n\t\treturn fmt.Errorf(\"failed to decode CA private key PEM\")\n\t}\n\n\t_, err = x509.ParseECPrivateKey(keyBlock.Bytes)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"failed to parse CA private key: %w\", err)\n\t}\n\n\tcaCertPath := filepath.Join(ConfDir, TLSCACertFilename)\n\tcaKeyPath := filepath.Join(ConfDir, TLSCAKeyFilename)","sourceCodeStart":305,"sourceCodeEnd":341,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/util/cert.go#L305-L341","documentation":"ImportCABundle accepts a CA certificate PEM and private key, validates them, and installs them into the workspace ConfDir as the TLS CA bundle. This error is returned when the PEM block decodes fine but x509.ParseCertificate rejects the DER bytes, so the certificate body is malformed or not an X.509 certificate.","triggerScenarios":"Calling ImportCABundle with caCertPEM whose first PEM block has a non-certificate type (e.g. 'PRIVATE KEY', 'CERTIFICATE REQUEST') or corrupted/truncated base64 DER payload.","commonSituations":"Pasting the wrong PEM file (the CA key instead of the CA cert), a certificate re-saved or truncated by a text editor, or a CSR/Public-key PEM copied from a CSR generation step.","solutions":["Verify the file starts with -----BEGIN CERTIFICATE----- and re-export it with 'openssl x509 -in ca.crt -outform PEM'","Check with 'openssl x509 -text -noout -in ca.crt' that the file parses as an X.509 certificate","Regenerate the CA (e.g. with openssl req -x509 or the kernel's own CA generation) and re-import"],"exampleFix":"// before\ncaCertPEM := caKeyFileContents // wrong PEM (private key)\nImportCABundle(caCertPEM, caKeyPEM)\n// after\ncaCertPEM := string(caCertFileContents) // -----BEGIN CERTIFICATE----- block\nImportCABundle(caCertPEM, caKeyPEM)","handlingStrategy":"validation","validationCode":"func validCertPEM(pemStr string) bool {\n    block, _ := pem.Decode([]byte(pemStr))\n    if block == nil || block.Type != \"CERTIFICATE\" { return false }\n    _, err := x509.ParseCertificate(block.Bytes)\n    return err == nil\n}","typeGuard":"if block == nil || block.Type != \"CERTIFICATE\" { return errors.New(\"not a certificate PEM\") }","tryCatchPattern":"if err := util.ImportCABundle(caCertPEM, caKeyPEM); err != nil {\n    if strings.Contains(err.Error(), \"failed to parse CA certificate\") {\n        // surface 'not a valid X.509 certificate' to the user\n    }\n}","preventionTips":["Always export the CA as PEM ('openssl x509 -outform pem') before import","Sanity-check with 'openssl x509 -text -noout' before pasting","Do not paste keys, CSRs, or public keys where a certificate is expected"],"tags":["tls","certificate","pem","x509"],"backgroundTag":"invalid-argument-format","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}