{"record":{"id":"f507988d2984a133","repo":"vectordotdev/vector","slug":"invalid-stored-authority-certificate","errorCode":null,"errorMessage":"Invalid stored authority certificate","messagePattern":"Invalid stored authority certificate","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"lib/vector-core/src/tls/settings.rs","lineNumber":271,"sourceCode":"                            .to_pem()\n                            .expect(\"Invalid stored identity chain certificate\"),\n                    );\n                }\n            }\n            (cert, key)\n        })\n    }\n\n    /// Returns the authorities as PEM data\n    ///\n    /// # Panics\n    ///\n    /// Panics if the authority is invalid.\n    pub fn authorities_pem(&self) -> impl Iterator<Item = Vec<u8>> + '_ {\n        self.authorities.iter().map(|authority| {\n            authority\n                .to_pem()\n                .expect(\"Invalid stored authority certificate\")\n        })\n    }\n\n    pub(super) fn apply_context(&self, context: &mut SslContextBuilder) -> Result<()> {\n        self.apply_context_base(context, false)\n    }\n\n    pub(super) fn apply_context_base(\n        &self,\n        context: &mut SslContextBuilder,\n        for_server: bool,\n    ) -> Result<()> {\n        context.set_verify(if self.verify_certificate {\n            SslVerifyMode::PEER | SslVerifyMode::FAIL_IF_NO_PEER_CERT\n        } else {\n            SslVerifyMode::NONE\n        });\n        if let Some(identity) = &self.identity {","sourceCodeStart":253,"sourceCodeEnd":289,"githubUrl":"https://github.com/vectordotdev/vector/blob/bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013/lib/vector-core/src/tls/settings.rs#L253-L289","documentation":"`TlsSettings::authorities_pem` returns an iterator that re-encodes each stored root authority certificate to PEM, documented to panic if an authority is invalid. The certificate was already parsed successfully at config load, so a panic here means stored X509 state cannot be serialized — an internal invariant break.","triggerScenarios":"Iterating `authorities_pem()` when any stored authority `X509` fails `to_pem()`; effectively only from corrupted/invalid in-memory certificate objects.","commonSituations":"Custom code paths that insert X509 authorities directly from unvalidated DER; corrupted test fixtures.","solutions":["Ensure authorities are loaded from valid PEM files via the standard TLS config path","Pre-validate each CA file with `X509::from_pem` (or openssl `verify`) before use","Regenerate the CA certificate file if it was truncated or corrupted","Report as a bug if a config-validated authority panics"],"exampleFix":"// before\nfor ca in settings.authorities_pem() { /* panics on bad cert */ }\n// after\nlet ca_pem = std::fs::read_to_string(\"ca.crt\")?;\nopenssl::x509::X509::from_pem(ca_pem.as_bytes())\n    .expect(\"CA file is not valid PEM\"); // fail early with context\nfor ca in settings.authorities_pem() { ... }","handlingStrategy":"validation","validationCode":"let ca = std::fs::read(\"ca.crt\")?;\nopenssl::x509::X509::from_pem(&ca)?; // fails early, before TlsSettings","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Verify CA bundle files are valid PEM before configuring TLS options","Use `openssl x509 -in ca.crt -noout` as a preflight check in deployment scripts","Load authorities via config files rather than programmatic DER construction"],"tags":["tls","rust","panic","certificate-authority"],"backgroundTag":"internal-invariant-violation","analyzedSha":"bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}