{"record":{"id":"7ea05dfaca2e98f6","repo":"grpc/grpc-go","slug":"spiffe-verify-function-could-not-parse-input-cert","errorCode":null,"errorMessage":"spiffe: verify function could not parse input certificate: %v","messagePattern":"spiffe: verify function could not parse input certificate: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/bootstrap/tlscreds/bundle.go","lineNumber":166,"sourceCode":"func (c *reloadingCreds) Clone() credentials.TransportCredentials {\n\treturn &reloadingCreds{provider: c.provider}\n}\n\nfunc (c *reloadingCreds) OverrideServerName(string) error {\n\treturn errors.New(\"overriding server name is not supported by xDS client TLS credentials\")\n}\n\nfunc (c *reloadingCreds) ServerHandshake(net.Conn) (net.Conn, credentials.AuthInfo, error) {\n\treturn nil, nil, errors.New(\"server handshake is not supported by xDS client TLS credentials\")\n}\n\nfunc buildSPIFFEVerifyFunc(spiffeBundleMap map[string]*spiffebundle.Bundle) func(rawCerts [][]byte, verifiedChains [][]*x509.Certificate) error {\n\treturn func(rawCerts [][]byte, _ [][]*x509.Certificate) error {\n\t\trawCertList := make([]*x509.Certificate, len(rawCerts))\n\t\tfor i, asn1Data := range rawCerts {\n\t\t\tcert, err := x509.ParseCertificate(asn1Data)\n\t\t\tif err != nil {\n\t\t\t\treturn fmt.Errorf(\"spiffe: verify function could not parse input certificate: %v\", err)\n\t\t\t}\n\t\t\trawCertList[i] = cert\n\t\t}\n\t\tif len(rawCertList) == 0 {\n\t\t\treturn fmt.Errorf(\"spiffe: verify function has no valid input certificates\")\n\t\t}\n\t\tleafCert := rawCertList[0]\n\t\troots, err := spiffe.GetRootsFromSPIFFEBundleMap(spiffeBundleMap, leafCert)\n\t\tif err != nil {\n\t\t\treturn err\n\t\t}\n\n\t\topts := x509.VerifyOptions{\n\t\t\tRoots:         roots,\n\t\t\tCurrentTime:   time.Now(),\n\t\t\tIntermediates: x509.NewCertPool(),\n\t\t}\n","sourceCodeStart":148,"sourceCodeEnd":184,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/bootstrap/tlscreds/bundle.go#L148-L184","documentation":"Emitted by the SPIFFE certificate verification callback inside reloadingCreds.ClientHandshake (bundle.go:166). When the server presents a certificate chain, each ASN.1 blob is parsed with x509.ParseCertificate; if any blob is malformed the handshake is aborted with the underlying parse error. This guard runs only when a SPIFFE trust bundle map is configured.","triggerScenarios":"An xDS management server (or any peer reached via this bundle) presents a certificate whose DER bytes are not a valid X.509 certificate. Triggered during ClientHandshake after the TLS layer hands rawCerts to buildSPIFFEVerifyFunc.","commonSituations":"Server is misconfigured and sends a non-PEM/DER blob or a truncated certificate; a proxy strips or rewrites the chain; version skew between the server's crypto library and the x509 parser; corrupted SPIFFE bundle map causing the wrong bytes to be evaluated.","solutions":["Inspect the server's presented certificate chain with openssl s_client -connect <host:port> -showcerts and confirm each certificate parses.","Verify the management server is actually sending X.509 DER certificates and not, e.g., a raw public key or a JWT-SVID.","Confirm spiffe_trust_bundle_map_file in the bootstrap points at a valid bundle and that GRPC_XDS_SPIFFE is enabled.","Re-issue or reload the server certificate if it is malformed."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"// The error surfaces during ClientHandshake; handle at the RPC level:\nif _, err := conn.Dial(...); err != nil {\n    var sev errdetails.SecurityErrorCode // or string-match the prefix\n    if strings.Contains(err.Error(), \"spiffe: verify function could not parse input certificate\") {\n        // peer cert is malformed; alert the server operator\n    }\n}","preventionTips":["Run an integration test that connects with a known-good server certificate to catch regressions.","Monitor handshake errors and alert on spikes - they usually indicate server cert rotation problems.","Keep the SPIFFE bundle map file fresh so verification uses the intended roots."],"tags":["spiffe","tls","mtls","certificate","handshake","xds"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}