rust-lang/cargo · error
error: Found a `@cert-authority` marker for
Error message
error: Found a `@cert-authority` marker for `{hostname}`
Cargo doesn't support certificate authorities for host key verification. It is
recommended that the command line Git client is used instead. This can be achieved
by setting `net.git-fetch-with-cli` to `true` in the Cargo config.
The `@cert-authority` line was found in {location}.
See https://doc.rust-lang.org/stable/cargo/appendix/git-authentication.html#ssh-known-hosts for more information.
What it means
Error "error: Found a `@cert-authority` marker for `{hostname}` Cargo doesn't support certificate authorities for host key verification. It is recommended that the command line Git client is used instead. This can be achieved by setting `net.git-fetch-with-cli` to `true` in the Cargo config. The `@cert-authority` line was found in {location}. See https://doc.rust-lang.org/stable/cargo/appendix/git-authentication.html#ssh-known-hosts for more information. " thrown in rust-lang/cargo.
When it happens
Trigger: Thrown at src/sources/git/known_hosts.rs:312 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
AI-assisted analysis of rust-lang/cargo@eb98b54bc9 (2026-08-11).
Data as JSON: /api/errors/44824c48b7627685.
Report an issue: GitHub.
Appendix: source
Thrown at src/sources/git/known_hosts.rs:312
remote_host_key,
location,
}) => {
let key_type_short_name = key_type.short_name();
anyhow::bail!(
"error: Key has been revoked for `{hostname}`\n\
**************************************\n\
* WARNING: REVOKED HOST KEY DETECTED *\n\
**************************************\n\
This may indicate that the key provided by this host has been\n\
compromised and should not be accepted.
\n\
The host key {key_type_short_name} {remote_host_key} is revoked\n\
in {location} and has been rejected.\n\
"
)
}
Err(KnownHostError::HostHasOnlyCertAuthority { hostname, location }) => {
anyhow::bail!("error: Found a `@cert-authority` marker for `{hostname}`\n\
\n\
Cargo doesn't support certificate authorities for host key verification. It is\n\
recommended that the command line Git client is used instead. This can be achieved\n\
by setting `net.git-fetch-with-cli` to `true` in the Cargo config.\n\
\n
The `@cert-authority` line was found in {location}.\n\
\n\
See https://doc.rust-lang.org/stable/cargo/appendix/git-authentication.html#ssh-known-hosts \
for more information.\n\
")
}
}
}
/// Checks if the given host/host key pair is known.
fn check_ssh_known_hosts(
gctx: &GlobalContext,
cert_host_key: &git2::cert::CertHostkey<'_>,View on GitHub (pinned to eb98b54bc9)