grpc/grpc-go · error

spiffe: x509 certificate Verify failed

Error message

spiffe: x509 certificate Verify failed: %v

What it means

Returned when x509.Certificate.Verify fails against the SPIFFE-derived root pool (bundle.go:190). The leaf certificate's chain cannot be built to a trusted root in the SPIFFE bundle map, so verification is rejected even though InsecureSkipVerify bypassed the standard check.

Solutions

  1. Confirm the leaf certificate's SPIFFE trust domain has a matching entry in spiffe_trust_bundle_map_file.
  2. Refresh the SPIFFE bundle map from the trust authority (Workload API, bundle endpoint) and reload.
  3. Check certificate validity dates and client clock synchronization.
  4. Ensure the server sends all required intermediate certificates.
Defensive patterns

Strategy: try-catch

Try / catch

if err != nil && strings.Contains(err.Error(), "spiffe: x509 certificate Verify failed") {
    // chain could not be built to a SPIFFE root; refresh bundle map
}

Prevention

When it happens

Trigger: During ClientHandshake, buildSPIFFEVerifyFunc computes roots via spiffe.GetRootsFromSPIFFEBundleMap for the leaf's trust domain, then calls leaf.Verify with those roots. Any chain-building failure (unknown issuer, expired cert, wrong trust domain) surfaces here.

Common situations: Client and server are in different SPIFFE trust domains and the bundle map lacks the server's domain; the SPIFFE bundle map file is stale and missing the current root; server certificate is expired or the client clock is skewed; intermediates are not sent by the server.

Understand the failure class

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/98d5ce9976a14ade. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/bootstrap/tlscreds/bundle.go:190

		}
		leafCert := rawCertList[0]
		roots, err := spiffe.GetRootsFromSPIFFEBundleMap(spiffeBundleMap, leafCert)
		if err != nil {
			return err
		}

		opts := x509.VerifyOptions{
			Roots:         roots,
			CurrentTime:   time.Now(),
			Intermediates: x509.NewCertPool(),
		}

		for _, cert := range rawCertList[1:] {
			opts.Intermediates.AddCert(cert)
		}
		// The verified chain is (surprisingly) unused.
		if _, err = rawCertList[0].Verify(opts); err != nil {
			return fmt.Errorf("spiffe: x509 certificate Verify failed: %v", err)
		}
		return nil
	}
}

View on GitHub (pinned to 0c51461d27)