grpc/grpc-go · error
spiffe: x509 certificate Verify failed
Error message
spiffe: x509 certificate Verify failed: %v
What it means
Returned when x509.Certificate.Verify fails against the SPIFFE-derived root pool (bundle.go:190). The leaf certificate's chain cannot be built to a trusted root in the SPIFFE bundle map, so verification is rejected even though InsecureSkipVerify bypassed the standard check.
Solutions
- Confirm the leaf certificate's SPIFFE trust domain has a matching entry in spiffe_trust_bundle_map_file.
- Refresh the SPIFFE bundle map from the trust authority (Workload API, bundle endpoint) and reload.
- Check certificate validity dates and client clock synchronization.
- Ensure the server sends all required intermediate certificates.
Defensive patterns
Strategy: try-catch
Try / catch
if err != nil && strings.Contains(err.Error(), "spiffe: x509 certificate Verify failed") {
// chain could not be built to a SPIFFE root; refresh bundle map
} Prevention
- Automate refresh of the SPIFFE bundle map (bundle endpoint or Workload API).
- Test mTLS handshakes against each trust domain after cert rotation.
- Sync client clocks via NTP to avoid expiry-related Verify failures.
When it happens
Trigger: During ClientHandshake, buildSPIFFEVerifyFunc computes roots via spiffe.GetRootsFromSPIFFEBundleMap for the leaf's trust domain, then calls leaf.Verify with those roots. Any chain-building failure (unknown issuer, expired cert, wrong trust domain) surfaces here.
Common situations: Client and server are in different SPIFFE trust domains and the bundle map lacks the server's domain; the SPIFFE bundle map file is stale and missing the current root; server certificate is expired or the client clock is skewed; intermediates are not sent by the server.
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
Related errors
- spiffe: verify function could not parse input certificate
- spiffe: verify function has no valid input certificates
- overriding server name is not supported by xDS client TLS…
- security configuration on the client-side does not contain…
- security configuration on the server-side does not contain…
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/98d5ce9976a14ade.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/bootstrap/tlscreds/bundle.go:190
}
leafCert := rawCertList[0]
roots, err := spiffe.GetRootsFromSPIFFEBundleMap(spiffeBundleMap, leafCert)
if err != nil {
return err
}
opts := x509.VerifyOptions{
Roots: roots,
CurrentTime: time.Now(),
Intermediates: x509.NewCertPool(),
}
for _, cert := range rawCertList[1:] {
opts.Intermediates.AddCert(cert)
}
// The verified chain is (surprisingly) unused.
if _, err = rawCertList[0].Verify(opts); err != nil {
return fmt.Errorf("spiffe: x509 certificate Verify failed: %v", err)
}
return nil
}
}
View on GitHub (pinned to 0c51461d27)