hyperledger/fabric · error
certificate must be different from nil
Error message
certificate must be different from nil
What it means
sanitizeECDSASignedCert guard: the certificate argument is nil. The function needs a real cert to re-sign its ECDSA signature in low-S form; a nil cert is invalid input (exercised by TestSanitizeCertInvalidInput).
Source
Thrown at msp/cert.go:78
UniqueId asn1.BitString `asn1:"optional,tag:1"`
SubjectUniqueId asn1.BitString `asn1:"optional,tag:2"`
Extensions []pkix.Extension `asn1:"optional,explicit,tag:3"`
}
func isECDSASignedCert(cert *x509.Certificate) bool {
return cert.SignatureAlgorithm == x509.ECDSAWithSHA1 ||
cert.SignatureAlgorithm == x509.ECDSAWithSHA256 ||
cert.SignatureAlgorithm == x509.ECDSAWithSHA384 ||
cert.SignatureAlgorithm == x509.ECDSAWithSHA512
}
// sanitizeECDSASignedCert checks that the signatures signing a cert
// is in low-S. This is checked against the public key of parentCert.
// If the signature is not in low-S, then a new certificate is generated
// that is equals to cert but the signature that is in low-S.
func sanitizeECDSASignedCert(cert *x509.Certificate, parentCert *x509.Certificate) (*x509.Certificate, error) {
if cert == nil {
return nil, errors.New("certificate must be different from nil")
}
if parentCert == nil {
return nil, errors.New("parent certificate must be different from nil")
}
expectedSig, err := utils.SignatureToLowS(parentCert.PublicKey.(*ecdsa.PublicKey), cert.Signature)
if err != nil {
return nil, err
}
// if sig == cert.Signature, nothing needs to be done
if bytes.Equal(cert.Signature, expectedSig) {
return cert, nil
}
// otherwise create a new certificate with the new signature
// 1. Unmarshal cert.Raw to get an instance of certificate,
// the lower level interface that represent an x509 certificateView on GitHub (pinned to 2736b63f8f)
Solutions
- Ensure callers pass a parsed, non-nil x509 certificate
- Fix upstream parsing that yielded nil instead of an error
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at msp/cert.go:78 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
AI-assisted analysis of hyperledger/fabric@2736b63f8f (2026-09-04).
Data as JSON: /api/errors/4a5eb0911cf3c986.
Report an issue: GitHub.