{"record":{"id":"9fc218fa53e38bd4","repo":"grpc/grpc-go","slug":"servername-for-peer-validation-must-be-configured","errorCode":null,"errorMessage":"serverName for peer validation must be configured as a list of acceptable SANs","messagePattern":"serverName for peer validation must be configured as a list of acceptable SANs","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"credentials/xds/xds.go","lineNumber":229,"sourceCode":"\t\t},\n\t}\n\tinfo.SPIFFEID = credinternal.SPIFFEIDFromState(conn.ConnectionState())\n\treturn credinternal.WrapSyscallConn(rawConn, conn), info, nil\n}\n\n// Info provides the ProtocolInfo of this TransportCredentials.\nfunc (c *credsImpl) Info() credentials.ProtocolInfo {\n\treturn credentials.ProtocolInfo{SecurityProtocol: \"tls\"}\n}\n\n// Clone makes a copy of this TransportCredentials.\nfunc (c *credsImpl) Clone() credentials.TransportCredentials {\n\tclone := *c\n\treturn &clone\n}\n\nfunc (c *credsImpl) OverrideServerName(_ string) error {\n\treturn errors.New(\"serverName for peer validation must be configured as a list of acceptable SANs\")\n}\n\n// UsesXDS returns true if c uses xDS to fetch security configuration\n// used at handshake time, and false otherwise.\nfunc (c *credsImpl) UsesXDS() bool {\n\treturn true\n}\n","sourceCodeStart":211,"sourceCodeEnd":237,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/credentials/xds/xds.go#L211-L237","documentation":"Always returned by credsImpl.OverrideServerName. xDS credentials derive peer validation from the security configuration pushed by the management server (a list of acceptable SANs), so overriding the server name via the deprecated OverrideServerName method is intentionally unsupported. The error message tells the developer to configure SAN matching through xDS instead.","triggerScenarios":"Calling OverrideServerName on an xDS credentials instance. This method exists on the TransportCredentials interface but xDS implementations reject it unconditionally.","commonSituations":"Developers migrating from TLS credentials (where OverrideServerName or grpc.WithAuthority was used) to xDS credentials and attempting to reuse the same server-name override pattern. Legacy code that calls OverrideServerName generically on any TransportCredentials.","solutions":["Remove the OverrideServerName call for xDS credentials; configure SAN matching via the xDS security policy from the management server.","Use grpc.WithAuthority on the dial options to override the :authority header if that is the intent.","For the fallback credentials (non-xDS path), you may still call OverrideServerName on the fallback instance directly."],"exampleFix":"// before\ncreds, _ := xds.NewClientCredentials(opts)\ncreds.OverrideServerName(\"example.com\") // always errors\n// after\ncreds, _ := xds.NewClientCredentials(opts)\nconn, _ := grpc.Dial(addr, grpc.WithTransportCredentials(creds), grpc.WithAuthority(\"example.com\"))","handlingStrategy":"validation","validationCode":"// Do not call OverrideServerName on xDS credentials.\n// Use grpc.WithAuthority for header override:\nconn, err := grpc.Dial(addr, grpc.WithTransportCredentials(xdsCreds), grpc.WithAuthority(\"example.com\"))","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Never call OverrideServerName on xDS credentials; it always errors.","Use grpc.WithAuthority for :authority header override.","Configure SAN matching via the xDS security policy from the management server."],"tags":["go","grpc","xds","credentials","san"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}