Edge Functions: Deno.createHttpClient({ cert, key }) terminates the isolate on edge-runtime 1.76.0, and { certChain, privateKey } silently presents no certificate #50534
Replies: 2 comments
|
This issue is caused by the upgrade to Deno 2.1.4 in Here is the exact root cause and the immediate fix for your mTLS integrations: 1. Root Cause: Rustls Dropped Support for PKCS#1 (
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Client certificates (mTLS) from Edge Functions stopped working for us between 15 and 17 September 2026 with no change to our code. Raising it here as well as on a Pro ticket (SU-477290) because it looks like a runtime regression rather than a usage problem.
Runtime, as reported by the function itself:
The detail that rules out our certificate
Deliberately invalid PEM text fails in exactly the same way as a valid certificate. Both terminate the isolate. Invalid input should produce a catchable error such as
No keys found in key data, which this runtime used to return, and which is how we diagnosed a PKCS#8 key on this same project on 15 September.Three behaviours
1.
Deno.createHttpClient({ cert, key })terminates the isolate.function_logsshowsbooted (time: 24ms)function_edge_logsshows no entry at all, so no status code is ever recordedtry/catcharound the call never runs2.
Deno.createHttpClient({ certChain, privateKey })builds, and presents nothing.The old option names do not crash and return a client object, but no certificate reaches the wire:
Byte identical, so the options are ignored rather than applied. Worth flagging because it looks like a workaround for about a minute.
3.
Deno.connectTls({ hostname, port, cert, key })did not return within 20 seconds. Lower confidence: our test wrapped the handshake and a raw socket read together, so we cannot say which one stalls.Control: the same function, returning before it reaches
createHttpClient, answers 200 with normal JSON every time.Reproduction
No secrets involved. Deploy and POST
{"mode":"junk"}.Expected:
THREWwith a message about the key data.Actual: isolate terminates, no response, no
function_edge_logsentry.Questions
createHttpClientwithcertandkeystill supported on the current edge runtime?Related but not the same: discussion #36035 covers
invalid peer certificate: UnknownIssuer, which is a handshake being rejected. Here the handshake is never reached.Context: this blocks two UK property portal integrations that both require mutual TLS. Everything up to the outbound request works.
All reactions