GoDaddy SSL证书在Node.js+Express中无法生效,报错0906D06C求助
Hey there, let's work through this SSL issue together! That error:0906D06C:PEM routines:PEM_read_bio:no start line error almost always boils down to invalid certificate/key formatting or incorrect file handling in your code. Since you're working with GoDaddy certificates, here's a step-by-step solution tailored to your setup:
1. Understand GoDaddy's Certificate Files
GoDaddy typically provides two key files when you download your SSL certificate:
- Your domain's primary certificate (e.g.,
yourdomain.certoryourdomain.crt) - A bundle of intermediate certificates (e.g.,
gd_bundle-g2-g1.cert)
These are already in PEM format—they just use .cert instead of .pem as the file extension. You don't need to convert them, but you do need to make sure they're read correctly.
2. Fix Common Code Issues
A. Use Reliable File Paths
Instead of relying on path.resolve (which depends on the working directory), use path.join(__dirname, ...) to ensure Node.js always finds your SSL files, no matter where you run the app from.
B. Avoid Unnecessary Encoding Specifiers
Sometimes specifying 'utf8' when reading certificates can introduce hidden formatting issues. Let Node.js read the files as raw buffers instead—this is more reliable for SSL assets.
C. Updated Code Example
Here's a revised version of your code with these fixes:
const fs = require('fs'); const path = require('path'); const express = require('express'); const app = express(); app.set('port', process.env.PORT || 443); if (process.env.SSL_PRIVATE_KEY && process.env.SSL_CERTIFICATE) { const https = require('https'); const sslOptions = { // Ensure your private key is in PEM format (starts with -----BEGIN PRIVATE KEY-----) key: fs.readFileSync(path.join(__dirname, 'ssl', 'key.pem')), // Use your GoDaddy domain certificate (even if it has .cert extension) cert: fs.readFileSync(path.join(__dirname, 'ssl', 'server.cert')), // Use GoDaddy's intermediate certificate bundle ca: fs.readFileSync(path.join(__dirname, 'ssl', 'bundle.cert')), requestCert: false, rejectUnauthorized: false }; https.createServer(sslOptions, app).listen(app.get('port'), () => { console.log(`Express server listening on https://localhost:${app.get('port')}`); }); } else { const http = require('http'); http.createServer(app).listen(app.get('port'), () => { console.log(`Express server listening on http://localhost:${app.get('port')}`); }); }
3. Verify Your Private Key
The error can also happen if your private key is invalid:
- Open
key.pemand confirm it starts with-----BEGIN PRIVATE KEY-----or-----BEGIN RSA PRIVATE KEY-----and ends with the correspondingENDline. - If your key is password-protected, remove the password with this OpenSSL command:
openssl rsa -in encrypted-key.pem -out key.pem - Verify the key is valid with:
openssl rsa -in key.pem -check
4. Check Certificate Chain Integrity
Ensure your intermediate certificate bundle includes all necessary certificates. You can verify the full chain with OpenSSL:
openssl s_client -connect localhost:443 -CAfile ssl/bundle.cert
Look for "Verify return code: 0 (ok)" in the output—this means the chain is valid.
5. File Permissions
Make sure Node.js has read access to your SSL files. Run this command to set appropriate permissions:
chmod 600 ssl/*
If you follow these steps, that PEM error should disappear, and your Express app should serve HTTPS traffic correctly with your GoDaddy certificate!
内容的提问来源于stack exchange,提问作者Manuel Ortega

