You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GoDaddy SSL证书在Node.js+Express中无法生效,报错0906D06C求助

Fixing "PEM_read_bio:no start line" Error with GoDaddy SSL Certificates in Express

Hey there, let's work through this SSL issue together! That error:0906D06C:PEM routines:PEM_read_bio:no start line error almost always boils down to invalid certificate/key formatting or incorrect file handling in your code. Since you're working with GoDaddy certificates, here's a step-by-step solution tailored to your setup:

1. Understand GoDaddy's Certificate Files

GoDaddy typically provides two key files when you download your SSL certificate:

  • Your domain's primary certificate (e.g., yourdomain.cert or yourdomain.crt)
  • A bundle of intermediate certificates (e.g., gd_bundle-g2-g1.cert)

These are already in PEM format—they just use .cert instead of .pem as the file extension. You don't need to convert them, but you do need to make sure they're read correctly.

2. Fix Common Code Issues

A. Use Reliable File Paths

Instead of relying on path.resolve (which depends on the working directory), use path.join(__dirname, ...) to ensure Node.js always finds your SSL files, no matter where you run the app from.

B. Avoid Unnecessary Encoding Specifiers

Sometimes specifying 'utf8' when reading certificates can introduce hidden formatting issues. Let Node.js read the files as raw buffers instead—this is more reliable for SSL assets.

C. Updated Code Example

Here's a revised version of your code with these fixes:

const fs = require('fs');
const path = require('path');
const express = require('express');
const app = express();

app.set('port', process.env.PORT || 443);

if (process.env.SSL_PRIVATE_KEY && process.env.SSL_CERTIFICATE) { 
  const https = require('https');
  
  const sslOptions = {
    // Ensure your private key is in PEM format (starts with -----BEGIN PRIVATE KEY-----)
    key: fs.readFileSync(path.join(__dirname, 'ssl', 'key.pem')),
    // Use your GoDaddy domain certificate (even if it has .cert extension)
    cert: fs.readFileSync(path.join(__dirname, 'ssl', 'server.cert')),
    // Use GoDaddy's intermediate certificate bundle
    ca: fs.readFileSync(path.join(__dirname, 'ssl', 'bundle.cert')),
    requestCert: false,
    rejectUnauthorized: false
  };

  https.createServer(sslOptions, app).listen(app.get('port'), () => { 
    console.log(`Express server listening on https://localhost:${app.get('port')}`); 
  }); 
} else { 
  const http = require('http');
  http.createServer(app).listen(app.get('port'), () => { 
    console.log(`Express server listening on http://localhost:${app.get('port')}`); 
  }); 
}

3. Verify Your Private Key

The error can also happen if your private key is invalid:

  • Open key.pem and confirm it starts with -----BEGIN PRIVATE KEY----- or -----BEGIN RSA PRIVATE KEY----- and ends with the corresponding END line.
  • If your key is password-protected, remove the password with this OpenSSL command:
    openssl rsa -in encrypted-key.pem -out key.pem
    
  • Verify the key is valid with:
    openssl rsa -in key.pem -check
    

4. Check Certificate Chain Integrity

Ensure your intermediate certificate bundle includes all necessary certificates. You can verify the full chain with OpenSSL:

openssl s_client -connect localhost:443 -CAfile ssl/bundle.cert

Look for "Verify return code: 0 (ok)" in the output—this means the chain is valid.

5. File Permissions

Make sure Node.js has read access to your SSL files. Run this command to set appropriate permissions:

chmod 600 ssl/*

If you follow these steps, that PEM error should disappear, and your Express app should serve HTTPS traffic correctly with your GoDaddy certificate!

内容的提问来源于stack exchange,提问作者Manuel Ortega

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 13:42:37