I have a node application running as an Azure function. Every 60 seconds it makes a number of web api calls, and one of the web apis has its SSL certificate signed by LetsEncrypt (R3).
On September 30th 2021 a root certificate expired. https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/
Now the function fails to call the API. (See the error below).
Where would the fault be?
- Is the fault in NodeJS itself? Does it have its own set of root certificates built into it?
- Or is the fault with Azure? Should the server that this is running on have the correct set of root certificates set up?
- Or am I supposed to do something?
I tried running similar code on my own machine and had similar problems, even after deleting all the expired certificates from the Windows Certificate store.
Here is the error that is being thrown in the Azure Function app:
Result: Failure Exception: AggregateError: RequestError: certificate has expired
at ClientRequest.<anonymous> (C:/home/site/wwwroot/node_modules/got/dist/source/core/index.js:953:111)
at ClientRequest.origin.emit (C:/home/site/wwwroot/node_modules/@szmarczak/http-timer/dist/source/index.js:39:20) RequestError: certificate has expired
at ClientRequest.<anonymous> (C:/home/site/wwwroot/node_modules/got/dist/source/core/index.js:953:111)
at ClientRequest.origin.emit (C:/home/site/wwwroot/node_modules/@szmarczak/http-timer/dist/source/index.js:39:20) Stack: AggregateError: RequestError: certificate has expired at ClientRequest.<anonymous>
The actual trigger for this is my first call
import { Issuer } from 'openid-client';
// ...
// This line of code throws the exception
const laqorrIssuer = await Issuer.discover(clientMetaData.laqorr_api_base);