Skip to content

Use local SSL trust store #1694

Description

@Clete2

I am using opencode with a LiteLLM proxy that has a SSL cert signed internally by my corporate organization.

When I try to test it, I get an error message: "UnknownError Error: unable to get local issuer certificate"

Image

When I cURL the LiteLLM proxy URL, it works, because the certificate is signed by a trusted signer. Opencode should use my system truststore.

macOS Sequoia 15.6

(PS I also am having #1154 as an issue, which might be related, I am not sure)

Activity

  1. Clete2 commented on Aug 8, 2025

    @Clete2
    Author

    For now I can work around it with "NODE_TLS_REJECT_UNAUTHORIZED=0"

  2. thdxr commented on Aug 11, 2025

    @thdxr
    Member

    does setting NODE_EXTRA_CA_CERTS fix?

  3. self-assigned this
    on Aug 11, 2025
  4. Clete2 commented on Aug 12, 2025

    @Clete2
    Author

    @thdxr yes, but most apps just use system store without having to specify.

    ~> opencode # error
    ~> NODE_EXTRA_CA_CERTS=truststore.crt opencode # works
    

    I'm not familiar with what HTTP libraries are being used, but maybe there's one that can use system certs?

    For instance, when using npm, I connect to a custom package proxy URL which has a company-signed SSL cert, and I don't have any special configuration that I know of which makes it trust that cert.

    Setup is like... Mac -> Zscaler -> GitHub Copilot. SSL decrypt enabled, so the destination appears to have a company-signed certifiate.

  5. thdxr commented on Aug 12, 2025

    @thdxr
    Member

    this isn't something bun or node seems to do automatically. need to see if we can load it somehow

  6. james-gour commented on Oct 24, 2025

    @james-gour

    I am also getting this! This will need to be fixed for many corporate settings :)

  7. maxious commented on Dec 23, 2025

    @maxious
    Contributor

    NODE_OPTIONS="--use-system-ca" or BUN_OPTIONS="--use-system-ca" should allow use of local corporate proxy certificates stored in the system security store. https://nodejs.org/docs/v23.8.0/api/cli.html#--use-system-ca

    This option was added to node in v22/23 this year which sadly means some LLMs with 2024 knowledge still think it's impossible 😂

  8. davidw-philips commented on Jan 5, 2026

    @davidw-philips

    Same issue here, deep wiki failing over http due to corporate proxy,, can't set in ENV variables without allowing insecure TLS.

  9. amolmishra23 commented on Jan 17, 2026

    @amolmishra23

    Facing the same issue. FYI I am running with the currently available latest version.

    ~ ❯ opencode --version                                                                                                                                                                                                                                                       
    1.1.25

    Also tried using the NODE_OPTIONS="--use-system-ca" or BUN_OPTIONS="--use-system-ca". Doesnt work either. On same 1.1.25 version.

    The only option which so far worked for me is, NODE_TLS_REJECT_UNAUTHORIZED=0.

    Why cant we have a permanent fix for this? Given everything else works perfectly in my corporate proxy (Cursor, VS Code, Antigravity etc).

  10. yancgi commented on Jan 22, 2026

    @yancgi

    On Linux, I resolved this adding this env variable in my .bashrc file:

    export NODE_EXTRA_CA_CERTS=/etc/ssl/certs/ca-certificates.crt
    

    Note: the file ca-certificates.crt does include our company's ZScaler root certificate.

  11. dklymenk commented on Jan 23, 2026

    @dklymenk

    I found a workaround for my exact case, using github-copilot provider. Copilot is an approved LLM provider in my org, but opencode fails to interact with it.

    My employer takes it a step further with their Zscaler setup. Even when I manage to get past the "Error: unable to get local issuer certificate", opencode just gets stuck with a loading animation. Meanwhile, the proprietary github copilot cli and the vscode extension were totally fine.

    https://models.dev/api.json lists https://api.githubcopilot.com/ as the API URL for github-copilot. This host doesn't just get its certificate replaced by Zscaler, it actually redirects you to some "safe browsing" environment. Needless to say, no POST request bodies survive that. The host is essentially banned for API use.

    By looking through Zscaler logs, I found that github copilot cli is instead calling https://api.business.githubcopilot.com/, which doesn't even have any man-in-the-middle business -- I see the original GitHub certificate. I assume copilot CLI is looking into whether my copilot plan is coming from my org and uses the business url for API requests.

    After that, getting past Zscaler was only a matter of updating ~/.cache/opencode/models.json with the whitelisted URL and starting opencode with OPENCODE_DISABLE_MODELS_FETCH=true opencode.

    Currently, I'm using an alias that replaces the URL and starts opencode with the env var:

    alias oc="sed -i '' 's/api\.githubcopilot\.com/api.business.githubcopilot.com/g' ~/.cache/opencode/models.json && OPENCODE_DISABLE_MODELS_FETCH=true opencode"

    When a new model is released, I plan to run opencode to refetch the models, close it and get back to oc.

  12. dklymenk commented on Jan 23, 2026

    @dklymenk

    I also wanted to do a summary of the "Error: unable to get local issuer certificate" solutions above:

    • NODE_TLS_REJECT_UNAUTHORIZED=0 works but exposes you to potential MITM attacks if someone were to sit between you and Zscaler. This also blindly disables SSL certificate verification for all requests bun/opencode would make (even ones not going through zscaler) exposing you even more.
    • NODE_EXTRA_CA_CERTS works if you don't mind going through the trouble of exporting the certificate from your keychain and converting the binary into the plain text PEM thing that bun/node expect.
    • NODE_OPTIONS="--use-system-ca" has no effect, likely not supported by bun at all
    • BUN_OPTIONS="--use-system-ca" prevents opencode from opening at all, likely related to The --bun flag breaks bun upgrade oven-sh/bun#20347. BUN_OPTIONS seems to break bun parameter parsing.

    There is a way to use --use-system-ca, if you were to clone opencode and add it directly to the dev script in package.json. However, for most users, I would assume exporting the certificate and passing it via NODE_EXTRA_CA_CERTS is the cleanest and the safest solution.

  13. added a commit that references this issue on Jan 26, 2026
    14b64d4
  14. github-actions commented on Mar 29, 2026

    @github-actions
    Contributor

    To stay organized issues are automatically closed after 90 days of no activity. If the issue is still relevant please open a new one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions