grpc/grpc-go · error

invalid spiffeid

Error message

invalid spiffeid: %v

What it means

Raised by idFromCert when spiffeid.FromURI fails on the certificate's single URI. The URI must use the `spiffe://` scheme, have a valid trust domain in the host, and a path satisfying SPIFFE ID rules. Any deviation (wrong scheme, empty host, disallowed characters, missing path) is rejected.

Solutions

  1. Confirm the URI SAN is a well-formed SPIFFE ID: scheme `spiffe://`, lowercase host = trust domain, non-empty path with no query/fragment.
  2. Re-mint the certificate with the corrected SPIFFE ID.
  3. Validate SPIFFE IDs at issuance time using spiffeid.FromURI in a test.
  4. Inspect the URI SAN with openssl and correct the CA template.

Example fix

// before: URI = https://example.org/workload
// after: URI = spiffe://example.org/workload
Defensive patterns

Strategy: validation

Validate before calling

func validSpiffeURI(u *url.URL) bool {
    if u == nil { return false }
    if u.Scheme != "spiffe" { return false }
    if u.Host == "" { return false }
    if u.Path == "" || u.Path == "/" { return false }
    if u.RawQuery != "" || u.Fragment != "" { return false }
    return true
}

Type guard

func parseSpiffeID(u *url.URL) (spiffeid.ID, error) {
    if !validSpiffeURI(u) { return spiffeid.ID{}, errors.New("not a valid spiffe URI") }
    return spiffeid.FromURI(u)
}

Try / catch

Wrap spiffeid.FromURI; on error, capture the offending URI (redacted) and re-mint the cert. Do not treat a non-spiffe URI as a fallback identity.

Prevention

When it happens

Trigger: A URI SAN like `https://example.org/svc`, `spiffe:///svc` (empty trust domain), `spiffe://example.org` (no path), or `spiffe://Exa mple/svc` (illegal characters).

Common situations: Cert generator wrote a non-SPIFFE URI into the SAN; SPIFFE ID constructed with an empty trust domain; copy-paste introduced a scheme typo; trust domain with uppercase or spaces.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/0a185a16e4718688. Report an issue: GitHub.

Appendix: source

Thrown at internal/credentials/spiffe/spiffe.go:104

	for _, root := range roots {
		rootPool.AddCert(root)
	}
	return rootPool, nil
}

// idFromCert parses the SPIFFE ID from the x509.Certificate. If the certificate
// does not have a valid SPIFFE ID, returns an error.
func idFromCert(cert *x509.Certificate) (*spiffeid.ID, error) {
	if cert == nil {
		return nil, fmt.Errorf("input cert is nil")
	}
	// A valid SPIFFE Certificate should have exactly one URI.
	if len(cert.URIs) != 1 {
		return nil, fmt.Errorf("input cert has %v URIs but should have 1", len(cert.URIs))
	}
	id, err := spiffeid.FromURI(cert.URIs[0])
	if err != nil {
		return nil, fmt.Errorf("invalid spiffeid: %v", err)
	}
	return &id, nil
}

View on GitHub (pinned to 0c51461d27)