You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

运行Nodemon时出现UNABLE_TO_VERIFY_LEAF_SIGNATURE错误求助

解决Node.js中UNABLE_TO_VERIFY_LEAF_SIGNATURE错误导致Nodemon崩溃的问题

首先还原你的代码场景:

const express = require('express'); 
const https = require('https'); 
const app = express(); 
app.get("/" , function(req, res) { 
  const url = "https://api.openweathermap.org/data/2.5/weather?q=Bhubaneswar&appid=5b1ee8df0720f3eca886c9ca1cb03385&units=metric"; 
  https.get(url, function(request, response){ 
    console.log(response); 
  }); 
  res.send("Server is up & running"); 
}); 
app.listen(5000, function() { 
  console.log("Server is running at port 5000"); 
});

你遇到的UNABLE_TO_VERIFY_LEAF_SIGNATURE错误,本质是Node.js在验证SSL证书链时失败——通常是目标服务器的中间证书不被Node的默认信任库认可,或者你的网络环境(比如公司代理、防火墙)插入了自定义证书导致验证链断裂。以下是几种针对性的解决方案:

方案一:临时禁用SSL验证(仅用于测试,禁止生产环境)

这是最快的临时解决方法,通过在https.get请求中添加rejectUnauthorized: false选项跳过证书验证:

app.get("/" , function(req, res) { 
  const url = "https://api.openweathermap.org/data/2.5/weather?q=Bhubaneswar&appid=5b1ee8df0720f3eca886c9ca1cb03385&units=metric"; 
  // 添加rejectUnauthorized选项
  https.get(url, { rejectUnauthorized: false }, function(request, response){ 
    console.log(response); 
  }); 
  res.send("Server is up & running"); 
});

⚠️ 注意:这个方法会关闭SSL证书的安全性验证,绝对不能在生产环境使用,仅用于本地测试排查问题。

方案二:手动指定可信CA证书

如果是目标服务器的中间证书未被Node信任,你可以下载对应的CA证书并在请求中指定:

  1. 打开浏览器访问https://api.openweathermap.org,查看网站的SSL证书,导出其中的根CA证书(格式为PEM)
  2. 在代码中读取证书并添加到请求选项:
const fs = require('fs');
const express = require('express'); 
const https = require('https'); 
const app = express(); 

// 读取本地CA证书文件
const trustedCa = fs.readFileSync('/path/to/your/ca-cert.pem');

app.get("/" , function(req, res) { 
  const url = "https://api.openweathermap.org/data/2.5/weather?q=Bhubaneswar&appid=5b1ee8df0720f3eca886c9ca1cb03385&units=metric"; 
  https.get(url, { ca: trustedCa }, function(request, response){ 
    console.log(response); 
  }); 
  res.send("Server is up & running"); 
}); 
app.listen(5000, function() { 
  console.log("Server is running at port 5000"); 
});

方案三:升级Node.js版本

旧版本的Node.js内置的根证书库可能过时,无法识别新的CA证书。建议升级到最新的LTS版本(比如18.x或20.x),新版本会包含更新的信任证书列表,很多时候能直接解决这个问题。

方案四:配置环境变量添加额外CA证书(适合公司网络环境)

如果是公司代理/防火墙插入了自定义证书导致验证失败,可以通过NODE_EXTRA_CA_CERTS环境变量告诉Node信任这个证书:

  1. 导出公司的根CA证书为PEM格式
  2. 在运行Nodemon前设置环境变量:
# Linux/macOS
export NODE_EXTRA_CA_CERTS="/path/to/company-root-ca.pem"
# Windows(PowerShell)
$env:NODE_EXTRA_CA_CERTS="C:\path\to\company-root-ca.pem"
  1. 然后正常启动Nodemon:
nodemon your-app-file.js

你可以根据自己的场景选择合适的方案,优先尝试方案三(升级Node)或方案四(如果是公司网络),方案一仅作为临时测试用。

内容的提问来源于stack exchange,提问作者Amrit Kumar Sutar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 00:43:12