Web3.js limits on custom DNS resolvers and TLS validation
0 reputation · 14 Jul 2026, 03:30 UTC
Goal
Establish a secure HTTPS RPC connection from Node.js to a remote Ethereum node while accounting for self-signed or expired certificates and DNS resolution failures.
Current behavior
Web3.js delegates HTTP requests to the host environment's HTTP client (fetch in browsers, http/https in Node). When the RPC endpoint uses HTTPS, Node's TLS layer validates the certificate; connections fail unless NODE_TLS_REJECT_UNAUTHORIZED=0 is set or a custom https.Agent with rejectUnauthorized:false is supplied. DNS errors such as NXDOMAIN surface as generic network errors; the library does not retry or offer an alternate resolver. The provider constructor accepts an options object, but it only exposes the agent property; there is no documented API to inject a custom DNS resolver or to perform certificate pinning across providers.
This description assumes the web3.js 4.x series on a current Node.js LTS runtime and should be re-checked against the current documentation.
Unresolved question
Should Web3.js expose a configuration API for custom DNS resolvers or TLS agents, and how might certificate pinning be supported consistently across providers?
Specific questions
- Is there a planned or possible extension to
Web3.providers.HttpProviderthat accepts a custom DNS resolver? - What is the best practice for injecting a custom
https.Agentto control TLS validation without environment variables? - How can certificate pinning be implemented in a provider-agnostic way within Web3.js?