grpc/grpc-go · error
invalid spiffeid
Error message
invalid spiffeid: %v
What it means
Raised by idFromCert when spiffeid.FromURI fails on the certificate's single URI. The URI must use the `spiffe://` scheme, have a valid trust domain in the host, and a path satisfying SPIFFE ID rules. Any deviation (wrong scheme, empty host, disallowed characters, missing path) is rejected.
Solutions
- Confirm the URI SAN is a well-formed SPIFFE ID: scheme `spiffe://`, lowercase host = trust domain, non-empty path with no query/fragment.
- Re-mint the certificate with the corrected SPIFFE ID.
- Validate SPIFFE IDs at issuance time using spiffeid.FromURI in a test.
- Inspect the URI SAN with openssl and correct the CA template.
Example fix
// before: URI = https://example.org/workload // after: URI = spiffe://example.org/workload
Defensive patterns
Strategy: validation
Validate before calling
func validSpiffeURI(u *url.URL) bool {
if u == nil { return false }
if u.Scheme != "spiffe" { return false }
if u.Host == "" { return false }
if u.Path == "" || u.Path == "/" { return false }
if u.RawQuery != "" || u.Fragment != "" { return false }
return true
} Type guard
func parseSpiffeID(u *url.URL) (spiffeid.ID, error) {
if !validSpiffeURI(u) { return spiffeid.ID{}, errors.New("not a valid spiffe URI") }
return spiffeid.FromURI(u)
} Try / catch
Wrap spiffeid.FromURI; on error, capture the offending URI (redacted) and re-mint the cert. Do not treat a non-spiffe URI as a fallback identity.
Prevention
- Validate SPIFFE IDs at issuance with spiffeid.FromURI in a unit test of the CA template.
- Use lowercase trust domains; never embed spaces or slashes in the host.
- Reject certs whose URI SAN scheme is not exactly spiffe://.
When it happens
Trigger: A URI SAN like `https://example.org/svc`, `spiffe:///svc` (empty trust domain), `spiffe://example.org` (no path), or `spiffe://Exa mple/svc` (illegal characters).
Common situations: Cert generator wrote a non-SPIFFE URI into the SAN; SPIFFE ID constructed with an empty trust domain; copy-paste introduced a scheme typo; trust domain with uppercase or spaces.
Related errors
- input cert has URIs but should have 1
- spiffe: BundleMapFromBytes() failed to parse bundle for…
- input cert is nil
- spiffe: BundleMapFromBytes() invalid trust domain
- spiffe: BundleMapFromBytes() no bundles parsed from spiffe…
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/0a185a16e4718688.
Report an issue: GitHub.
Appendix: source
Thrown at internal/credentials/spiffe/spiffe.go:104
for _, root := range roots {
rootPool.AddCert(root)
}
return rootPool, nil
}
// idFromCert parses the SPIFFE ID from the x509.Certificate. If the certificate
// does not have a valid SPIFFE ID, returns an error.
func idFromCert(cert *x509.Certificate) (*spiffeid.ID, error) {
if cert == nil {
return nil, fmt.Errorf("input cert is nil")
}
// A valid SPIFFE Certificate should have exactly one URI.
if len(cert.URIs) != 1 {
return nil, fmt.Errorf("input cert has %v URIs but should have 1", len(cert.URIs))
}
id, err := spiffeid.FromURI(cert.URIs[0])
if err != nil {
return nil, fmt.Errorf("invalid spiffeid: %v", err)
}
return &id, nil
}
View on GitHub (pinned to 0c51461d27)