{"record":{"id":"98d5ce9976a14ade","repo":"grpc/grpc-go","slug":"spiffe-x509-certificate-verify-failed-v","errorCode":null,"errorMessage":"spiffe: x509 certificate Verify failed: %v","messagePattern":"spiffe: x509 certificate Verify failed: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/bootstrap/tlscreds/bundle.go","lineNumber":190,"sourceCode":"\t\t}\n\t\tleafCert := rawCertList[0]\n\t\troots, err := spiffe.GetRootsFromSPIFFEBundleMap(spiffeBundleMap, leafCert)\n\t\tif err != nil {\n\t\t\treturn err\n\t\t}\n\n\t\topts := x509.VerifyOptions{\n\t\t\tRoots:         roots,\n\t\t\tCurrentTime:   time.Now(),\n\t\t\tIntermediates: x509.NewCertPool(),\n\t\t}\n\n\t\tfor _, cert := range rawCertList[1:] {\n\t\t\topts.Intermediates.AddCert(cert)\n\t\t}\n\t\t// The verified chain is (surprisingly) unused.\n\t\tif _, err = rawCertList[0].Verify(opts); err != nil {\n\t\t\treturn fmt.Errorf(\"spiffe: x509 certificate Verify failed: %v\", err)\n\t\t}\n\t\treturn nil\n\t}\n}\n","sourceCodeStart":172,"sourceCodeEnd":195,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/bootstrap/tlscreds/bundle.go#L172-L195","documentation":"Returned when x509.Certificate.Verify fails against the SPIFFE-derived root pool (bundle.go:190). The leaf certificate's chain cannot be built to a trusted root in the SPIFFE bundle map, so verification is rejected even though InsecureSkipVerify bypassed the standard check.","triggerScenarios":"During ClientHandshake, buildSPIFFEVerifyFunc computes roots via spiffe.GetRootsFromSPIFFEBundleMap for the leaf's trust domain, then calls leaf.Verify with those roots. Any chain-building failure (unknown issuer, expired cert, wrong trust domain) surfaces here.","commonSituations":"Client and server are in different SPIFFE trust domains and the bundle map lacks the server's domain; the SPIFFE bundle map file is stale and missing the current root; server certificate is expired or the client clock is skewed; intermediates are not sent by the server.","solutions":["Confirm the leaf certificate's SPIFFE trust domain has a matching entry in spiffe_trust_bundle_map_file.","Refresh the SPIFFE bundle map from the trust authority (Workload API, bundle endpoint) and reload.","Check certificate validity dates and client clock synchronization.","Ensure the server sends all required intermediate certificates."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"if err != nil && strings.Contains(err.Error(), \"spiffe: x509 certificate Verify failed\") {\n    // chain could not be built to a SPIFFE root; refresh bundle map\n}","preventionTips":["Automate refresh of the SPIFFE bundle map (bundle endpoint or Workload API).","Test mTLS handshakes against each trust domain after cert rotation.","Sync client clocks via NTP to avoid expiry-related Verify failures."],"tags":["spiffe","tls","mtls","certificate","trust","xds"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}