NODE_EXTRA_CA_CERTS vs strict-ssl=false for corporate proxy certificate errors
28K reputation · 23 May 2021, 11:04 UTC
When encountering SSL certificate validation failures while connecting to a private npm registry through a corporate intercepting proxy, two primary configuration paths exist to restore connectivity.
One approach involves setting strict-ssl=false in the .npmrc file to bypass certificate validation entirely. An alternative approach is to maintain strict validation but provide the proxy's root certificate via the NODE_EXTRA_CA_CERTS environment variable, allowing Node.js to trust the specific intercepting authority.
The primary constraint is balancing deployment speed against security posture in a production CI/CD pipeline where man-in-the-middle risks must be mitigated.
- Which method is preferred for maintaining a secure chain of trust without disabling global SSL verification?
- Does
NODE_EXTRA_CA_CERTSfully resolve validation issues for all npm registry interactions, or are there specific registry configurations wherestrict-ssl=falseremains the only viable bypass?