{"record":{"id":"8d3d48b27b0f2ece","repo":"grpc/grpc-go","slug":"spiffe-verify-function-has-no-valid-input-certifi","errorCode":null,"errorMessage":"spiffe: verify function has no valid input certificates","messagePattern":"spiffe: verify function has no valid input certificates","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/bootstrap/tlscreds/bundle.go","lineNumber":171,"sourceCode":"\treturn errors.New(\"overriding server name is not supported by xDS client TLS credentials\")\n}\n\nfunc (c *reloadingCreds) ServerHandshake(net.Conn) (net.Conn, credentials.AuthInfo, error) {\n\treturn nil, nil, errors.New(\"server handshake is not supported by xDS client TLS credentials\")\n}\n\nfunc buildSPIFFEVerifyFunc(spiffeBundleMap map[string]*spiffebundle.Bundle) func(rawCerts [][]byte, verifiedChains [][]*x509.Certificate) error {\n\treturn func(rawCerts [][]byte, _ [][]*x509.Certificate) error {\n\t\trawCertList := make([]*x509.Certificate, len(rawCerts))\n\t\tfor i, asn1Data := range rawCerts {\n\t\t\tcert, err := x509.ParseCertificate(asn1Data)\n\t\t\tif err != nil {\n\t\t\t\treturn fmt.Errorf(\"spiffe: verify function could not parse input certificate: %v\", err)\n\t\t\t}\n\t\t\trawCertList[i] = cert\n\t\t}\n\t\tif len(rawCertList) == 0 {\n\t\t\treturn fmt.Errorf(\"spiffe: verify function has no valid input certificates\")\n\t\t}\n\t\tleafCert := rawCertList[0]\n\t\troots, err := spiffe.GetRootsFromSPIFFEBundleMap(spiffeBundleMap, leafCert)\n\t\tif err != nil {\n\t\t\treturn err\n\t\t}\n\n\t\topts := x509.VerifyOptions{\n\t\t\tRoots:         roots,\n\t\t\tCurrentTime:   time.Now(),\n\t\t\tIntermediates: x509.NewCertPool(),\n\t\t}\n\n\t\tfor _, cert := range rawCertList[1:] {\n\t\t\topts.Intermediates.AddCert(cert)\n\t\t}\n\t\t// The verified chain is (surprisingly) unused.\n\t\tif _, err = rawCertList[0].Verify(opts); err != nil {","sourceCodeStart":153,"sourceCodeEnd":189,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/bootstrap/tlscreds/bundle.go#L153-L189","documentation":"Returned by the SPIFFE verify callback when the rawCerts slice received from the peer is empty (bundle.go:171). With InsecureSkipVerify=true and a custom VerifyPeerCertificate, an empty chain means there is nothing to validate, so the handshake fails fast rather than silently succeeding.","triggerScenarios":"The TLS handshake completes at the record layer but the peer supplied zero certificates. This happens during ClientHandshake when the server does not present a chain (e.g. server uses PSK or is misconfigured to not request/send a certificate) and a SPIFFE bundle map is in use.","commonSituations":"Server is configured for one-way TLS but client expects mTLS; server certificate selection fails silently; intermediary (load balancer, sidecar) terminates TLS and does not forward the peer cert; wrong port reached.","solutions":["Ensure the xDS management server is configured for mTLS and will present its certificate chain.","If the deployment intentionally uses one-way TLS, remove the spiffe_trust_bundle_map_file from the bootstrap so the standard RootCAs path is used.","Check for TLS-terminating proxies in the path and reconfigure them to passthrough or to present the upstream chain."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"// Distinguish 'no cert sent' from other handshake errors:\nif err != nil && strings.Contains(err.Error(), \"has no valid input certificates\") {\n    // server did not present a certificate; check mTLS config\n}","preventionTips":["Verify the server requires client certs and presents its own cert.","Use openssl s_client to confirm the server chain is presented before pointing xDS at it.","Ensure no TLS-terminating proxy strips the peer certificate."],"tags":["spiffe","tls","mtls","handshake","xds"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}