Skip to content

NODE_EXTRA_CA_CERTS does not work when set in env file #51426

Description

@slukes

Version

v21.5.0

Platform

Darwin MACM-YXGQWMKDQK 22.6.0 Darwin Kernel Version 22.6.0: Wed Jul 5 22:22:05 PDT 2023; root:xnu-8796.141.3~6/RELEASE_ARM64_T6000 arm64

Subsystem

No response

What steps will reproduce the bug?

Run
node --env-file ./config/.env.development

With env file containing NODE_EXTRA_CA_CERTS

The variable is not taken into account.

Run same script but exporting the variable first, it is correctly taken into account.

How often does it reproduce? Is there a required condition?

Always!

What is the expected behavior? Why is that the expected behavior?

The ca cert should be taken into account

What do you see instead?

It is not correctly taken into account and I get errors about self signed certificates

Additional information

No response

Activity

  1. tniessen commented on Jan 11, 2024

    @tniessen
    Member
  2. MrJithil commented on Jan 12, 2024

    @MrJithil
    Member

    Please help with console.log(process.env) for debugging purpose. Just to verify the env variable is set but the path specified is getting wrong while using --env-file flag.
    After I will write a reproducing snippets.

  3. sosoba commented on Jan 15, 2024

    @sosoba
    Contributor

    Doc says:

    The NODE_EXTRA_CA_CERTS environment variable is only read when the Node.js process is first launched. Changing the value at runtime [..] has no effect on the current process.

  4. xsbchen commented on Jan 15, 2024

    @xsbchen
    Contributor

    for now, i think it not supported to set NODE_EXTRA_CA_CERTS in env file, may need to note this on the document

  5. slukes commented on Jan 15, 2024

    @slukes
    Author

    Please help with console.log(process.env) for debugging purpose. Just to verify the env variable is set but the path specified is getting wrong while using --env-file flag. After I will write a reproducing snippets.

    I can confirm that the variable is getting correctly set 😄. (I can't share my whole process.env with you)

  6. xsbchen commented on Jan 16, 2024

    @xsbchen
    Contributor

    @slukes I checked the code, in the start process, it will use NODE_EXTRA_CA_CERTS from process env to init openssl first, then load the file from --env-file, so it will not work for setting NODE_EXTRA_CA_CERTS in --env-file, maybe you need to set it before you start node

  7. xsbchen commented on Jan 17, 2024

    @xsbchen
    Contributor

    @anonrig if it expects to work, I want to try to fix it

  8. added
    dotenvIssues and PRs related to .env file parsing.
    on Jan 18, 2024
  9. slukes commented on Jan 20, 2024

    @slukes
    Author

    @anonrig if we can do anything to help please let me know!

  10. senicko commented on Jul 20, 2024

    @senicko

    Hi, just wanted to say that it would be amazing to be able to set this in .env 🥺

  11. joshribakoff-sm commented on Nov 18, 2024

    @joshribakoff-sm

    Same issue here. Regardless of what version of nodeJS I use (20, 22, 23), I run into the error unable to get local issuer cert on any requests. This is despite the fact that when I print process.env on startup, the env var is set.

    Since I was working on upgrading from NodeJS 16 and this was working before, I decided to downgrade back to NodeJS 16 to test, at which point I ran into errors about --env-file not existing in Node 16. Upon checking my git history I was previously using a 3rd party package https://www.npmjs.com/package/env-cmd instead of the built in NodeJS --env-file on Node 16. If I use that package, it works on all versions of NodeJS 16, 18, 20, 22, 23, etc...

    Based on my reading of the comment(s) and the research I have done, it sounds like NodeJS reads the contents of the NODE_EXTRA_CA_CERTS env var only on initial startup, and it is happening too early in the startup before the --env-file is parsed and loaded (which is what writes the env vars).

    In my opinion, this means the --env-file mechanism is likely half baked, broken, or otherwise just has a bug, so it should either be fixed or the feature should be removed if there is no plan to fix it. It makes no sense to have an official way to set env vars that only sets them after they were already read (in the case of env vars only read during startup)! 😡.

    Alternatively, if all NodeJS official APIs read their env vars at runtime instead of startup, that would probably also fix it, but I'm guessing there is a reason this env var is only read 1x on startup. Assuming there is a good reason (security) to only read the env var 1x on startup, the logical solution then is to ensure the official APIs for setting those env vars runs first.

    Note, @MrJithil comment is incorrect. It's not an issue with the path to the file having a typo. It's exactly what the OP said, the env var is ignored. Also exactly like @xsbchen said.

    I had a working setup before switching from 3rd party env-cmd npm package, and now I don't have a working setup anymore after switching to this new (broken) --env-file official NodeJS API. That is the issue, simple as. Nothing else has changed.

  12. anonrig commented on Nov 18, 2024

    @anonrig
    Member

    Any pull requests are welcome.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    confirmed-bugIssues and PRs for confirmed bugs.dotenvIssues and PRs related to .env file parsing.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions