vectordotdev/vector · error
Invalid stored authority certificate
Error message
Invalid stored authority certificate
What it means
`TlsSettings::authorities_pem` returns an iterator that re-encodes each stored root authority certificate to PEM, documented to panic if an authority is invalid. The certificate was already parsed successfully at config load, so a panic here means stored X509 state cannot be serialized — an internal invariant break.
Solutions
- Ensure authorities are loaded from valid PEM files via the standard TLS config path
- Pre-validate each CA file with `X509::from_pem` (or openssl `verify`) before use
- Regenerate the CA certificate file if it was truncated or corrupted
- Report as a bug if a config-validated authority panics
Example fix
// before
for ca in settings.authorities_pem() { /* panics on bad cert */ }
// after
let ca_pem = std::fs::read_to_string("ca.crt")?;
openssl::x509::X509::from_pem(ca_pem.as_bytes())
.expect("CA file is not valid PEM"); // fail early with context
for ca in settings.authorities_pem() { ... } Defensive patterns
Strategy: validation
Validate before calling
let ca = std::fs::read("ca.crt")?;
openssl::x509::X509::from_pem(&ca)?; // fails early, before TlsSettings Prevention
- Verify CA bundle files are valid PEM before configuring TLS options
- Use `openssl x509 -in ca.crt -noout` as a preflight check in deployment scripts
- Load authorities via config files rather than programmatic DER construction
When it happens
Trigger: Iterating `authorities_pem()` when any stored authority `X509` fails `to_pem()`; effectively only from corrupted/invalid in-memory certificate objects.
Common situations: Custom code paths that insert X509 authorities directly from unvalidated DER; corrupted test fixtures.
Understand the failure class
Background: "This is a bug, please report it": internal invariant violations, unreachable panics, and SNH errors explained — this error's family across 47 libraries.
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
Related errors
- Building HTTP client failed
- HTTPS initialization failed
- Invalid stored identity chain certificate
- a record with a next ID must have an event count
- a valid HTTP/1 URI is valid as an HTTP URI
AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16).
Data as JSON: /api/errors/f507988d2984a133.
Report an issue: GitHub.
Appendix: source
Thrown at lib/vector-core/src/tls/settings.rs:271
.to_pem()
.expect("Invalid stored identity chain certificate"),
);
}
}
(cert, key)
})
}
/// Returns the authorities as PEM data
///
/// # Panics
///
/// Panics if the authority is invalid.
pub fn authorities_pem(&self) -> impl Iterator<Item = Vec<u8>> + '_ {
self.authorities.iter().map(|authority| {
authority
.to_pem()
.expect("Invalid stored authority certificate")
})
}
pub(super) fn apply_context(&self, context: &mut SslContextBuilder) -> Result<()> {
self.apply_context_base(context, false)
}
pub(super) fn apply_context_base(
&self,
context: &mut SslContextBuilder,
for_server: bool,
) -> Result<()> {
context.set_verify(if self.verify_certificate {
SslVerifyMode::PEER | SslVerifyMode::FAIL_IF_NO_PEER_CERT
} else {
SslVerifyMode::NONE
});
if let Some(identity) = &self.identity {View on GitHub (pinned to bdb87aeaa4)