grpc/grpc-go · critical
xds: CertificateProvider to fetch identity certificate is…
Error message
xds: CertificateProvider to fetch identity certificate is missing, cannot perform TLS handshake. Please check configuration on the management server
What it means
Returned by serverSideTLSConfigInternal when hi.identityProvider is nil. On the server side, the identity certificate provider is mandatory—it supplies the server's own TLS certificate (the cert presented to clients). Without it the server has nothing to present in the handshake. The root provider is optional (needed only for mTLS client verification), but identity is always required.
Solutions
- On the xDS management server, configure the server-side TLS context with a certificate provider (ServerCertificateProvider or TlsCertificate) that supplies the server's identity certificate.
- If using SDS (Secret Discovery Service), verify the server certificate secret is provisioned and accessible.
- Check the SDS/secret agent logs for certificate fetch failures.
- Confirm the xDS LDS listener resource has a CommonHttpProtocolOptions.tls_context with certificates populated.
Example fix
// Ensure server-side xDS config includes a certificate provider.
// On Istio, verify the Gateway has a server certificate:
// before: Gateway with tls but no credentialName
// after:
spec:
servers:
- port:
number: 443
name: https
protocol: HTTPS
tls:
mode: SIMPLE
credentialName: server-cert # <-- provides identity provider Defensive patterns
Strategy: validation
Validate before calling
// Server-side: verify the identity certificate provider is configured. // Check the xDS listener resource has certificates in the TLS context. // istioctl proxy-config listener <pod> -o json | jq '...certificates...' // Ensure SDS has the server cert secret provisioned.
Try / catch
// This is a server-side startup error; the server cannot handshake without identity cert.
// Catch is not applicable—fix the xDS config.
// Log and alert:
log.Fatal("xDS security config missing identity certificate provider; cannot serve TLS") Prevention
- Always configure a server certificate (identity provider) in xDS server-side TLS.
- Provision SDS secrets for the server cert before starting the server.
- Monitor certificate provisioning and rotation health.
- Run istioctl analyze or equivalent config validation before deployment.
When it happens
Trigger: Server-side xDS TLS handshake where the HandshakeInfo exists and is not fallback but identityProvider is nil—NewHandshakeInfo was called with nil for the identity provider. This means the xDS server-side security config (UpstreamTLSContext on the xDS server, or DownstreamTLSContext for inbound) has no certificate (ServerCertificateProvider) configured.
Common situations: xDS management server sends a server-side security policy with a validation context (for verifying clients) but no server certificate; cert rotation job failed to provision the server cert SDS secret; Istio Gateway/VirtualService or PeerAuthentication configured for mTLS but the server's own cert SDS resource is missing.
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
Related errors
- server handshake is not supported by xDS client TLS…
- xds: CertificateProvider to fetch trusted roots is missing…
- failed to build credentials bundle from bootstrap for
- overriding server name is not supported by xDS client TLS…
- xds: connection closed or HandshakeInfo dead
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/0aa161f6909e964a.
Report an issue: GitHub.
Appendix: source
Thrown at internal/credentials/xds/handshake_info.go:334
// TODO: Print the complete certificate once the x509 package
// supports a String() method on the Certificate type.
return fmt.Errorf("xds: received SANs {DNSNames: %v, EmailAddresses: %v, IPAddresses: %v, URIs: %v} do not match any of the accepted SANs", cert.DNSNames, cert.EmailAddresses, cert.IPAddresses, cert.URIs)
}
return nil
}
}
// serverSideTLSConfigInternal constructs a tls.Config to be used in a
// server-side handshake based on the contents of the HandshakeInfo.
func (hi *HandshakeInfo) serverSideTLSConfigInternal(ctx context.Context) (*tls.Config, error) {
cfg := &tls.Config{
ClientAuth: tls.NoClientCert,
NextProtos: []string{"h2"},
}
// On the server side, identityProvider is mandatory. RootProvider is
// optional based on whether the server is doing TLS or mTLS.
if hi.identityProvider == nil {
return nil, errors.New("xds: CertificateProvider to fetch identity certificate is missing, cannot perform TLS handshake. Please check configuration on the management server")
}
if hi.requireClientCert {
cfg.ClientAuth = tls.RequireAndVerifyClientCert
}
// identityProvider is mandatory on the server side.
km, err := hi.identityProvider.KeyMaterial(ctx)
if err != nil {
return nil, fmt.Errorf("xds: fetching identity certificates from CertificateProvider failed: %v", err)
}
cfg.Certificates = km.Certs
if hi.rootProvider != nil {
km, err := hi.rootProvider.KeyMaterial(ctx)
if err != nil {
return nil, fmt.Errorf("xds: fetching trusted roots from CertificateProvider failed: %v", err)
}
if km.SPIFFEBundleMap != nil && hi.requireClientCert {View on GitHub (pinned to 0c51461d27)