Repository navigation
NODE_EXTRA_CA_CERTS does not work when set in env file #51426
Description
Activity
cc @anonrig
Please help with
console.log(process.env)for debugging purpose. Just to verify the env variable is set but the path specified is getting wrong while using--env-fileflag.
After I will write a reproducing snippets.Reacted by joshribakoff-smDoc says:
The NODE_EXTRA_CA_CERTS environment variable is only read when the Node.js process is first launched. Changing the value at runtime [..] has no effect on the current process.
Reacted by joshribakoff-sm, Giuliano Bellini and Sean Connollyfor now, i think it not supported to set
NODE_EXTRA_CA_CERTSin env file, may need to note this on the documentPlease help with
console.log(process.env)for debugging purpose. Just to verify the env variable is set but the path specified is getting wrong while using--env-fileflag. After I will write a reproducing snippets.I can confirm that the variable is getting correctly set 😄. (I can't share my whole process.env with you)
@slukes I checked the code, in the start process, it will use
NODE_EXTRA_CA_CERTSfrom process env to init openssl first, then load the file from--env-file, so it will not work for settingNODE_EXTRA_CA_CERTSin--env-file, maybe you need to set it before you start nodeReacted by Samuel Lukes and joshribakoff-sm- addedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.
on Jan 17, 2024 @anonrig if it expects to work, I want to try to fix it
Reacted by Samuel Lukes- addeddotenvIssues and PRs related to .env file parsing.Issues and PRs related to .env file parsing.
on Jan 18, 2024 @anonrig if we can do anything to help please let me know!
Hi, just wanted to say that it would be amazing to be able to set this in
.env🥺Same issue here. Regardless of what version of nodeJS I use (20, 22, 23), I run into the error
unable to get local issuer certon any requests. This is despite the fact that when I printprocess.envon startup, the env var is set.Since I was working on upgrading from NodeJS 16 and this was working before, I decided to downgrade back to NodeJS 16 to test, at which point I ran into errors about
--env-filenot existing in Node 16. Upon checking my git history I was previously using a 3rd party package https://www.npmjs.com/package/env-cmd instead of the built in NodeJS--env-fileon Node 16. If I use that package, it works on all versions of NodeJS 16, 18, 20, 22, 23, etc...Based on my reading of the comment(s) and the research I have done, it sounds like NodeJS reads the contents of the
NODE_EXTRA_CA_CERTSenv var only on initial startup, and it is happening too early in the startup before the--env-fileis parsed and loaded (which is what writes the env vars).In my opinion, this means the
--env-filemechanism is likely half baked, broken, or otherwise just has a bug, so it should either be fixed or the feature should be removed if there is no plan to fix it. It makes no sense to have an official way to set env vars that only sets them after they were already read (in the case of env vars only read during startup)! 😡.Alternatively, if all NodeJS official APIs read their env vars at runtime instead of startup, that would probably also fix it, but I'm guessing there is a reason this env var is only read 1x on startup. Assuming there is a good reason (security) to only read the env var 1x on startup, the logical solution then is to ensure the official APIs for setting those env vars runs first.
Note, @MrJithil comment is incorrect. It's not an issue with the path to the file having a typo. It's exactly what the OP said, the env var is ignored. Also exactly like @xsbchen said.
I had a working setup before switching from 3rd party
env-cmdnpm package, and now I don't have a working setup anymore after switching to this new (broken)--env-fileofficial NodeJS API. That is the issue, simple as. Nothing else has changed.Any pull requests are welcome.
Version
v21.5.0
Platform
Darwin MACM-YXGQWMKDQK 22.6.0 Darwin Kernel Version 22.6.0: Wed Jul 5 22:22:05 PDT 2023; root:xnu-8796.141.3~6/RELEASE_ARM64_T6000 arm64
Subsystem
No response
What steps will reproduce the bug?
Run
node --env-file ./config/.env.development
With env file containing NODE_EXTRA_CA_CERTS
The variable is not taken into account.
Run same script but exporting the variable first, it is correctly taken into account.
How often does it reproduce? Is there a required condition?
Always!
What is the expected behavior? Why is that the expected behavior?
The ca cert should be taken into account
What do you see instead?
It is not correctly taken into account and I get errors about self signed certificates
Additional information
No response