vectordotdev/vector · error

Invalid stored identity chain certificate

Error message

Invalid stored identity chain certificate

What it means

Inside `TlsSettings::identity_pem`, each CA certificate in the identity's chain is re-encoded to PEM via `to_pem().expect(...)`. The panic means a stored chain authority could not be PEM-encoded despite chain certificates being validated at configuration load time. Like error 300, it indicates corrupted stored certificate state, not a normal caller-visible failure.

Solutions

  1. Load identities via standard config parsing so chain certs are validated as PEM at ingest
  2. Validate each CA cert parses (e.g. `X509::from_pem`) before adding it to the identity
  3. Drop or replace the offending chain entry and reload the config
  4. File a bug if a validated chain still fails to encode
Defensive patterns

Strategy: validation

Validate before calling

for ca in &chain_pems {
    openssl::x509::X509::from_pem(ca).expect("CA cert must be valid PEM");
}

Prevention

When it happens

Trigger: Calling `identity_pem()` when an entry of `identity.ca` fails `to_pem()` — only reachable if the CA X509 object is invalid/corrupted in memory.

Common situations: Constructing `TlsSettings` identity with CA certs built from invalid DER in tests or custom loaders that skip ingest validation.

Understand the failure class

Background: "This is a bug, please report it": internal invariant violations, unreachable panics, and SNH errors explained — this error's family across 47 libraries.

Related errors


AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16). Data as JSON: /api/errors/f7fbadb58b070758. Report an issue: GitHub.

Appendix: source

Thrown at lib/vector-core/src/tls/settings.rs:254

    /// Returns the identity as PEM encoded byte arrays
    ///
    /// # Panics
    ///
    /// Panics if the identity is missing, invalid, or the authorities to chain are invalid.
    pub fn identity_pem(&self) -> Option<(Vec<u8>, Vec<u8>)> {
        self.identity.as_ref().map(|identity| {
            // we have verified correct formatting at ingest time
            let mut cert = identity.cert.to_pem().expect("Invalid stored identity");
            let key = identity
                .key
                .private_key_to_pem_pkcs8()
                .expect("Invalid stored identity");
            if let Some(chain) = identity.ca.as_ref() {
                for authority in chain {
                    cert.extend(
                        authority
                            .to_pem()
                            .expect("Invalid stored identity chain certificate"),
                    );
                }
            }
            (cert, key)
        })
    }

    /// Returns the authorities as PEM data
    ///
    /// # Panics
    ///
    /// Panics if the authority is invalid.
    pub fn authorities_pem(&self) -> impl Iterator<Item = Vec<u8>> + '_ {
        self.authorities.iter().map(|authority| {
            authority
                .to_pem()
                .expect("Invalid stored authority certificate")
        })

View on GitHub (pinned to bdb87aeaa4)