vectordotdev/vector · error

Invalid stored authority certificate

Error message

Invalid stored authority certificate

What it means

`TlsSettings::authorities_pem` returns an iterator that re-encodes each stored root authority certificate to PEM, documented to panic if an authority is invalid. The certificate was already parsed successfully at config load, so a panic here means stored X509 state cannot be serialized — an internal invariant break.

Solutions

  1. Ensure authorities are loaded from valid PEM files via the standard TLS config path
  2. Pre-validate each CA file with `X509::from_pem` (or openssl `verify`) before use
  3. Regenerate the CA certificate file if it was truncated or corrupted
  4. Report as a bug if a config-validated authority panics

Example fix

// before
for ca in settings.authorities_pem() { /* panics on bad cert */ }
// after
let ca_pem = std::fs::read_to_string("ca.crt")?;
openssl::x509::X509::from_pem(ca_pem.as_bytes())
    .expect("CA file is not valid PEM"); // fail early with context
for ca in settings.authorities_pem() { ... }
Defensive patterns

Strategy: validation

Validate before calling

let ca = std::fs::read("ca.crt")?;
openssl::x509::X509::from_pem(&ca)?; // fails early, before TlsSettings

Prevention

When it happens

Trigger: Iterating `authorities_pem()` when any stored authority `X509` fails `to_pem()`; effectively only from corrupted/invalid in-memory certificate objects.

Common situations: Custom code paths that insert X509 authorities directly from unvalidated DER; corrupted test fixtures.

Understand the failure class

Background: "This is a bug, please report it": internal invariant violations, unreachable panics, and SNH errors explained — this error's family across 47 libraries.

Related errors


AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16). Data as JSON: /api/errors/f507988d2984a133. Report an issue: GitHub.

Appendix: source

Thrown at lib/vector-core/src/tls/settings.rs:271

                            .to_pem()
                            .expect("Invalid stored identity chain certificate"),
                    );
                }
            }
            (cert, key)
        })
    }

    /// Returns the authorities as PEM data
    ///
    /// # Panics
    ///
    /// Panics if the authority is invalid.
    pub fn authorities_pem(&self) -> impl Iterator<Item = Vec<u8>> + '_ {
        self.authorities.iter().map(|authority| {
            authority
                .to_pem()
                .expect("Invalid stored authority certificate")
        })
    }

    pub(super) fn apply_context(&self, context: &mut SslContextBuilder) -> Result<()> {
        self.apply_context_base(context, false)
    }

    pub(super) fn apply_context_base(
        &self,
        context: &mut SslContextBuilder,
        for_server: bool,
    ) -> Result<()> {
        context.set_verify(if self.verify_certificate {
            SslVerifyMode::PEER | SslVerifyMode::FAIL_IF_NO_PEER_CERT
        } else {
            SslVerifyMode::NONE
        });
        if let Some(identity) = &self.identity {

View on GitHub (pinned to bdb87aeaa4)