> For the complete documentation index, see [llms.txt](https://doc.duaer.com/zh/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/zh/troubleshooting/http-request-ssl-certificate-error.md).

# 在 Duaer 里排查 HTTP Request 证书报错 self-signed certificate

Duaer 的 HTTP Request 调内网或测试服务时报 self-signed certificate、unable to verify the first certificate，是对方证书不被信任。
## Duaer 里常见的证书报错

- self-signed certificate、self-signed certificate in certificate chain：对方用的是自签证书或内部 CA。
- unable to verify the first certificate：对方服务器没把中间证书发全。浏览器能打开，Duaer 不行，多半是这个。
- certificate has expired：证书过期了。
- Hostname/IP does not match certificate's altnames：用 IP 或别名访问，和证书上的域名对不上。

## 按顺序修

1. 能改服务器就改服务器：续期证书，配置完整证书链（服务器证书加中间证书），用证书上的域名访问。这是唯一不降低安全性的办法。
2. 自托管 Duaer 调内部 CA 签的服务：把 CA 证书放进容器，设环境变量 NODE_EXTRA_CA_CERTS 指向它，重启。
3. 只是临时测内网：[HTTP Request](/zh/build/http-request.md) 的 Options 里打开 Ignore SSL Issues (Insecure)。这样不再校验证书，数据可能被中间人看到，不要用在公网和敏感数据上。
## Questions

### Duaer 里浏览器能打开的网址，HTTP Request 为什么报证书错？

浏览器会自己补齐缺失的中间证书，Duaer 的 HTTP Request 不会。让对方服务器配置完整证书链。

### Duaer 云端能用 NODE_EXTRA_CA_CERTS 吗？

不能，这是自托管 Duaer 的环境变量。Duaer 云端调用的服务应使用公开受信任的证书。

## 相关

- [在 Duaer 里用 HTTP Request 调接口](https://doc.duaer.com/zh/build/http-request.md)
- [Duaer 环境变量](https://doc.duaer.com/zh/hosting/configuration/environment-variables.md)
- [在 Duaer 里妥善处理错误](https://doc.duaer.com/zh/flow-logic/error-handling.md)

