{"record":{"id":"f7fbadb58b070758","repo":"vectordotdev/vector","slug":"invalid-stored-identity-chain-certificate","errorCode":null,"errorMessage":"Invalid stored identity chain certificate","messagePattern":"Invalid stored identity chain certificate","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"lib/vector-core/src/tls/settings.rs","lineNumber":254,"sourceCode":"    /// Returns the identity as PEM encoded byte arrays\n    ///\n    /// # Panics\n    ///\n    /// Panics if the identity is missing, invalid, or the authorities to chain are invalid.\n    pub fn identity_pem(&self) -> Option<(Vec<u8>, Vec<u8>)> {\n        self.identity.as_ref().map(|identity| {\n            // we have verified correct formatting at ingest time\n            let mut cert = identity.cert.to_pem().expect(\"Invalid stored identity\");\n            let key = identity\n                .key\n                .private_key_to_pem_pkcs8()\n                .expect(\"Invalid stored identity\");\n            if let Some(chain) = identity.ca.as_ref() {\n                for authority in chain {\n                    cert.extend(\n                        authority\n                            .to_pem()\n                            .expect(\"Invalid stored identity chain certificate\"),\n                    );\n                }\n            }\n            (cert, key)\n        })\n    }\n\n    /// Returns the authorities as PEM data\n    ///\n    /// # Panics\n    ///\n    /// Panics if the authority is invalid.\n    pub fn authorities_pem(&self) -> impl Iterator<Item = Vec<u8>> + '_ {\n        self.authorities.iter().map(|authority| {\n            authority\n                .to_pem()\n                .expect(\"Invalid stored authority certificate\")\n        })","sourceCodeStart":236,"sourceCodeEnd":272,"githubUrl":"https://github.com/vectordotdev/vector/blob/bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013/lib/vector-core/src/tls/settings.rs#L236-L272","documentation":"Inside `TlsSettings::identity_pem`, each CA certificate in the identity's chain is re-encoded to PEM via `to_pem().expect(...)`. The panic means a stored chain authority could not be PEM-encoded despite chain certificates being validated at configuration load time. Like error 300, it indicates corrupted stored certificate state, not a normal caller-visible failure.","triggerScenarios":"Calling `identity_pem()` when an entry of `identity.ca` fails `to_pem()` — only reachable if the CA X509 object is invalid/corrupted in memory.","commonSituations":"Constructing `TlsSettings` identity with CA certs built from invalid DER in tests or custom loaders that skip ingest validation.","solutions":["Load identities via standard config parsing so chain certs are validated as PEM at ingest","Validate each CA cert parses (e.g. `X509::from_pem`) before adding it to the identity","Drop or replace the offending chain entry and reload the config","File a bug if a validated chain still fails to encode"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"for ca in &chain_pems {\n    openssl::x509::X509::from_pem(ca).expect(\"CA cert must be valid PEM\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Validate each CA chain certificate parses as X509 before adding to identity settings","Avoid hand-building TlsSettings identities in tests from raw bytes","Regenerate corrupted CA files rather than retrying"],"tags":["tls","rust","panic","certificate-chain"],"backgroundTag":"internal-invariant-violation","analyzedSha":"bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}