Node.js调用外部REST API时出现UNABLE_TO_VERIFY_LEAF_SIGNATURE错误
UNABLE_TO_VERIFY_LEAF_SIGNATURE Error in Node.js POST Requests That UNABLE_TO_VERIFY_LEAF_SIGNATURE error typically pops up when Node.js can't validate the full SSL certificate chain of the API you're calling. This usually happens for one of two reasons: either the API server's certificate is signed by an intermediate Certificate Authority (CA) that isn't in Node's default trusted CA store, or your proxy is interfering with the SSL handshake process.
Here are three actionable solutions, ordered by best practice:
1. Add the Trusted CA Certificate (Recommended for Production)
The safest approach is to explicitly tell Node.js to trust the CA that signed the API's certificate. You'll need the CA certificate file (usually a .pem file) for this step.
Modify your options object to include the ca field, loading the certificate content directly:
const fs = require('fs'); const request = require('request'); return new Promise(function (resolve) { var payload = JSON.stringify({ "data": [ {"Requirement_Description": "xxx" }], "services": ["xxxx"], "labels": ["label_1"] }); // Load your CA certificate file from the filesystem const trustedCa = fs.readFileSync('/path/to/your/ca-certificate.pem'); var options = { 'url': 'https://myHost/xxx/api/model/predict', 'method': 'POST', 'body': payload, 'json': true, 'proxy': 'myProxy', 'timeout': 10000, 'followRedirect': true, 'maxRedirects': 10, 'ca': trustedCa // Attach the trusted CA certificate here }; request.post(options, function(error, response, body) { if (error) { console.error(error); return resolve(null); // Handle error based on your app's needs } resolve(body); }); });
2. Temporarily Disable SSL Verification (Only for Development)
If you're testing in a local/development environment and need a quick workaround (never use this in production), you can skip certificate validation entirely by adding rejectUnauthorized: false to your options:
var options = { 'url': 'https://myHost/xxx/api/model/predict', 'method': 'POST', 'body': payload, 'json': true, 'proxy': 'myProxy', 'timeout': 10000, 'followRedirect': true, 'maxRedirects': 10, 'rejectUnauthorized': false // Disable SSL checks (unsafe for production!) };
This disables Node's SSL validation entirely, which exposes you to man-in-the-middle attacks—so only use this for local testing purposes.
3. Verify Your Proxy Configuration
Since you're using a proxy, it's possible the proxy itself is using a self-signed or untrusted certificate. In this case, you might need to:
- Add the proxy's CA certificate to the
cafield of your options (same as solution 1) - Confirm your proxy is configured to pass through the API's SSL certificate chain correctly
- Double-check that any proxy authentication settings are correctly included in your options
内容的提问来源于stack exchange,提问作者Libin C Jacob

