Repository navigation
Use local SSL trust store #1694
Description
Activity
For now I can work around it with "NODE_TLS_REJECT_UNAUTHORIZED=0"
Reacted by Michał Nowotnik, rnizametdinov and Michael Christendoes setting NODE_EXTRA_CA_CERTS fix?
Reacted by Ingvar Stepanyan, Fredrik Hansteen and mauricemabika@thdxr yes, but most apps just use system store without having to specify.
~> opencode # error ~> NODE_EXTRA_CA_CERTS=truststore.crt opencode # worksI'm not familiar with what HTTP libraries are being used, but maybe there's one that can use system certs?
For instance, when using npm, I connect to a custom package proxy URL which has a company-signed SSL cert, and I don't have any special configuration that I know of which makes it trust that cert.
Setup is like... Mac -> Zscaler -> GitHub Copilot. SSL decrypt enabled, so the destination appears to have a company-signed certifiate.
this isn't something bun or node seems to do automatically. need to see if we can load it somehow
I am also getting this! This will need to be fixed for many corporate settings :)
Reacted by Abhi Sohal, Frank Meyer, Erik Ahlburg-Schmidt, Tianshu Wang, Charles Buffington, ibeex, Yannik Tausch, Landon Buttars and vvvrvvvrNODE_OPTIONS="--use-system-ca" or BUN_OPTIONS="--use-system-ca" should allow use of local corporate proxy certificates stored in the system security store. https://nodejs.org/docs/v23.8.0/api/cli.html#--use-system-ca
This option was added to node in v22/23 this year which sadly means some LLMs with 2024 knowledge still think it's impossible 😂
Reacted by JT and Landon ButtarsSame issue here, deep wiki failing over http due to corporate proxy,, can't set in ENV variables without allowing insecure TLS.
Facing the same issue. FYI I am running with the currently available latest version.
~ ❯ opencode --version 1.1.25Also tried using the NODE_OPTIONS="--use-system-ca" or BUN_OPTIONS="--use-system-ca". Doesnt work either. On same 1.1.25 version.
The only option which so far worked for me is, NODE_TLS_REJECT_UNAUTHORIZED=0.
Why cant we have a permanent fix for this? Given everything else works perfectly in my corporate proxy (Cursor, VS Code, Antigravity etc).
On Linux, I resolved this adding this env variable in my
.bashrcfile:export NODE_EXTRA_CA_CERTS=/etc/ssl/certs/ca-certificates.crtNote: the file
ca-certificates.crtdoes include our company's ZScaler root certificate.Reacted by Xu PeibaiI found a workaround for my exact case, using github-copilot provider. Copilot is an approved LLM provider in my org, but opencode fails to interact with it.
My employer takes it a step further with their Zscaler setup. Even when I manage to get past the "Error: unable to get local issuer certificate", opencode just gets stuck with a loading animation. Meanwhile, the proprietary github copilot cli and the vscode extension were totally fine.
https://models.dev/api.json lists https://api.githubcopilot.com/ as the API URL for github-copilot. This host doesn't just get its certificate replaced by Zscaler, it actually redirects you to some "safe browsing" environment. Needless to say, no POST request bodies survive that. The host is essentially banned for API use.
By looking through Zscaler logs, I found that github copilot cli is instead calling https://api.business.githubcopilot.com/, which doesn't even have any man-in-the-middle business -- I see the original GitHub certificate. I assume copilot CLI is looking into whether my copilot plan is coming from my org and uses the business url for API requests.
After that, getting past Zscaler was only a matter of updating
~/.cache/opencode/models.jsonwith the whitelisted URL and starting opencode withOPENCODE_DISABLE_MODELS_FETCH=true opencode.Currently, I'm using an alias that replaces the URL and starts opencode with the env var:
alias oc="sed -i '' 's/api\.githubcopilot\.com/api.business.githubcopilot.com/g' ~/.cache/opencode/models.json && OPENCODE_DISABLE_MODELS_FETCH=true opencode"
When a new model is released, I plan to run
opencodeto refetch the models, close it and get back tooc.Reacted by Clauber-camiloI also wanted to do a summary of the "Error: unable to get local issuer certificate" solutions above:
NODE_TLS_REJECT_UNAUTHORIZED=0works but exposes you to potential MITM attacks if someone were to sit between you and Zscaler. This also blindly disables SSL certificate verification for all requests bun/opencode would make (even ones not going through zscaler) exposing you even more.NODE_EXTRA_CA_CERTSworks if you don't mind going through the trouble of exporting the certificate from your keychain and converting the binary into the plain text PEM thing that bun/node expect.NODE_OPTIONS="--use-system-ca"has no effect, likely not supported by bun at allBUN_OPTIONS="--use-system-ca"prevents opencode from opening at all, likely related to The--bunflag breaksbun upgradeoven-sh/bun#20347. BUN_OPTIONS seems to break bun parameter parsing.
There is a way to use
--use-system-ca, if you were to clone opencode and add it directly to thedevscript in package.json. However, for most users, I would assume exporting the certificate and passing it viaNODE_EXTRA_CA_CERTSis the cleanest and the safest solution.Reacted by Yanick Rochon, Landon Buttars, pawlakus, Rodrigo Victor, Aleksandr Sidorov and Nathan Dawson- added a commit that references this issue
on Jan 26, 2026 github-actions commented
on Mar 29, 2026 on Mar 29, 2026 – with GitHub ActionsContributorMore actionsTo stay organized issues are automatically closed after 90 days of no activity. If the issue is still relevant please open a new one.
- added a commit that references this issue
on May 12, 2026
I am using opencode with a LiteLLM proxy that has a SSL cert signed internally by my corporate organization.
When I try to test it, I get an error message: "UnknownError Error: unable to get local issuer certificate"
When I cURL the LiteLLM proxy URL, it works, because the certificate is signed by a trusted signer. Opencode should use my system truststore.
macOS Sequoia 15.6
(PS I also am having #1154 as an issue, which might be related, I am not sure)