Verified diagnostic signature
request to https:// … failed, reason: unable to get local issuer certificate
npm could not build a trusted certificate path for the selected registry or HTTPS proxy. Match this output from npm, then continue with sourced, read-only checks.
- Confidence
- high
- Platforms
- linux · macos · windows
- Verified
- 2026-07-24
Recognized output
Signature matched locally
request to https://.* failed, reason: unable to get local issuer certificateOneLiners matches this pattern in your browser. Your pasted output is not stored or indexed.
Likely causes
What usually produces this signal
- The registry omitted a required intermediate certificate
- A private registry or authorized inspection CA is not in npm's trust bundle
- npm reached an unexpected registry, tarball host, or proxy
- The effective cafile is missing, unreadable, malformed, or overridden
Safe next checks
Collect evidence before changing the system
Inspect a remote TLS certificate
openssl s_client -connect <host>:<port> -servername <host> </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -datesThe output matches the expected target and exits without an error.
Print subjects, issuers, and validity dates for a TLS chain
openssl s_client -showcerts -connect <host>:<port> -servername <host> </dev/null 2>/dev/null | openssl crl2pkcs7 -nocrl -certfile /dev/stdin | openssl pkcs7 -print_certs -nooutThe output matches the expected target and exits without an error.
Resolve a hostname to its IP address
dig +short <domain>The output matches the expected target and exits without an error.
Related signals