Skip to content

Retrieve built-in root certificates within node application #25824

Description

@LuukDeVille

Is there any way to retrieve the built-in root certificates, that are shiped with node (https://github.com/nodejs/node/blob/master/src/node_root_certs.h) from a node application?

Via https.globalAgent.options.ca it is possible to define custom certificates, but the already existing ones are not listed here.

Activity

  1. added
    tlsIssues and PRs related to the tls subsystem.
    feature requestIssues requesting new Node.js features.
    on Jan 30, 2019
  2. sam-github commented on Jan 30, 2019

    @sam-github
    Contributor

    Not currently. I've considered adding it, but couldn't really think of a use-case. What's yours? I assume you ask for a reason! :-)

  3. LuukDeVille commented on Feb 4, 2019

    @LuukDeVille
    Author

    We have the requirement to add a lot of intermediate CAs via https.globalAgent.options.ca. As the option https.globalAgent.options.ca is going to overwrite the built-in root CAs, we also need to add those root CAs as well. Due to this, my idea was to read the built-in root CAs as well as our intermediate CAs and pass these to https.globalAgent.options.ca.

    As there is no option at the moment to get the built-in root CAs, we need to think of getting them somewhere else.

    Thus it would be great, if there is an interface to read the built-in root CAs.

  4. sam-github commented on Feb 4, 2019

    @sam-github
    Contributor

    Your use-case seems reasonable to me. No promises on if/when someone will get to this feature, though, sorry.

    Have you considered using NODE_EXTRA_CA_CERTS? It does what you want (adds to the CAs without replacing them), but you need them to be in a file, and to set an env variable before node starts, which may or may not work for you.

  5. LuukDeVille commented on Feb 4, 2019

    @LuukDeVille
    Author

    We have considered using NODE_EXTRA_CA_CERTS, but we can not use it due to the constraints you have mentioned.

  6. added a commit that references this issue on May 20, 2019
  7. khitrenovich commented on May 20, 2019

    @khitrenovich

    @bnoordhuis / @targos - what is the target release for that enhancement, please?

  8. bnoordhuis commented on May 21, 2019

    @bnoordhuis
    Member

    @khitrenovich Yeah, there's no simple answer... it will probably go into the next v12.x release but if you're asking about LTS releases, I can't give a precise answer.

  9. khitrenovich commented on May 21, 2019

    @khitrenovich

    @bnoordhuis So, if it makes its way to one of v12.x releases, it will eventually become LTS once v12 will get to LTS phase... unless I'm missing something in how Node release scheduling works, right?

  10. bnoordhuis commented on May 21, 2019

    @bnoordhuis
    Member

    @khitrenovich That's right.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    feature requestIssues requesting new Node.js features.tlsIssues and PRs related to the tls subsystem.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions