Skip to content

Tracking issue: custom CA certificate support #58990

Description

@joyeecheung

Trying to track the recent changes that allow easier configuration of custom CA certificate for constrained environments and the backports

Activity

  1. added
    tlsIssues and PRs related to the tls subsystem.
    cryptoIssues and PRs related to the crypto subsystem.
    metaIssues and PRs related to the general management of the project.
    on Jul 8, 2025
  2. gengjiawen commented on Jul 23, 2025

    @gengjiawen
    Member

    will use-system-ca default to true in next major ?

    Node.js is the only software I know doesn't respect system CA, really weird behavior.

  3. joyeecheung commented on Jul 29, 2025

    @joyeecheung
    MemberAuthor

    Currently this still has a non-trivial performance overhead on the first TLS connection. We'll need to check and see if that can be mitigated or reduced.

  4. EmperorArthur commented on Aug 5, 2025

    @EmperorArthur

    Node.js is the only software I know doesn't respect system CA, really weird behavior.

    Python requires that trustore be installed, and pip only recently stopped requiring an experimental flag.

    I do agree it's a bit of a pain though. Especially in corporate environments.

  5. joyeecheung commented on Aug 20, 2025

    @joyeecheung
    MemberAuthor

    I found a way to minimize the performance impact - #59550 with this I think there would be a much smaller performance impact to enable it by default.

  6. amilshahsahab commented on Aug 23, 2025

    @amilshahsahab
  7. gengjiawen commented on May 13, 2026

    @gengjiawen
    Member

    I found this really annoying for enterprise user, if user have enterprise cert installed globally, so fetch won't work. Maybe also add a runtime check or env check since --use-system-ca not by default?

  8. joyeecheung commented on May 13, 2026

    @joyeecheung
    MemberAuthor

    It's unclear to me what runtime checks etc. means. There are runtime APIs for querying and setting certificates that users can invoke, but from a runtime point of view, Node.js has no way of knowing what the system certificates are. Most systems likely have some certificates different from the Mozilla bundle, so if the signal is that there is some difference then practically it's enabling by default.

  9. github-actions commented on Aug 12, 2026

    @github-actions
    Contributor

    This issue has been marked as stale due to 90 days of inactivity.
    It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.

  10. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Aug 12, 2026
  11. added
    never-staleIssues and PRs exempt from automated stale handling.
    and removed
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Aug 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.metaIssues and PRs related to the general management of the project.never-staleIssues and PRs exempt from automated stale handling.tlsIssues and PRs related to the tls subsystem.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions