Photo by Fotis Fotopoulos on Unsplash
So there I was, setting up a fresh Node project on a corporate laptop at like 9am, coffee still brewing, and I run npm install — and boom. Red wall of text. The one that stops you cold:
npm error code UNABLE_TO_GET_ISSUER_CERT_LOCALLY
npm error errno UNABLE_TO_GET_ISSUER_CERT_LOCALLY
npm error network request to https://registry.npmjs.org/some-package failed
npm error network This is a problem related to network connectivity.
I've seen this error probably a hundred times across different teams and environments. It's one of those npm errors that looks terrifying but is almost always caused by the same handful of things. The short version: npm is trying to verify an SSL certificate during the install, and something in that chain is broken or untrusted. Could be a corporate proxy, a self-signed cert, or a VPN doing deep packet inspection. Fun stuff.
Alright, let's get into the actual fixes.
Fix #1: Tell npm to use your system's certificate store
This is the fix that works for most people on corporate networks. Your company's IT team has almost certainly installed a custom root CA on your machine — npm just doesn't know about it yet. You can point npm to your system's CA bundle explicitly.
First, find where your Node installation keeps its CA file. On most systems you can run:
node -e "console.log(require('tls').rootCertificates.length)"
That's just a sanity check. What you actually want to do is export your system certificates and tell npm to use them. On Windows, you can use a tool called win-ca or just grab the cert file directly. But the quickest cross-platform fix is this:
npm config set cafile /path/to/your/ca-bundle.crt
If you're on a corporate machine and your IT admin gave you a .crt or .pem file, that's the path you drop in there. On a lot of enterprise setups, there's already one sitting in something like C:\certs\company-root.crt or /etc/ssl/certs/ca-certificates.crt on Linux.
After setting that, run npm install again. Honestly, this alone resolves it about 70% of the time.
Fix #2: Disable strict SSL (carefully — read this first)
I want to be upfront here — this is a workaround, not a permanent solution. Disabling SSL verification is fine on a local dev machine behind a firewall, but you don't want this in a CI/CD pipeline or production environment. That said, sometimes you just need to get unblocked.
npm config set strict-ssl false
Run your install, get what you need, then turn it back on:
npm config set strict-ssl true
Or, if you only want to disable it for a single install without changing your global config:
npm install --legacy-peer-deps --strict-ssl=false
Now here's where it gets tricky — some people just leave strict-ssl false set globally and forget about it. I've audited projects where this was baked into the team's shared .npmrc file committed to the repo. Please don't do that. Fix the actual cert issue when you get time.
Fix #3: Set the registry to HTTP instead of HTTPS (for internal registries)
This one applies if you're using a private npm registry — like Artifactory, Verdaccio, or Nexus — and that's what's throwing the cert error. Sometimes the internal registry is running on HTTP or has a self-signed cert that npm won't trust.
Check your current registry setting first:
npm config get registry
If it's pointing to an internal URL, you've got two options. Either switch to HTTP temporarily:
npm config set registry http://your-internal-registry.company.com/
Or, better yet, add the certificate for your internal registry specifically rather than disabling SSL globally. You do that by adding a scoped cert in your .npmrc:
//your-internal-registry.company.com/:cafile=/path/to/registry-cert.pem
This is the cleanest approach because it only trusts that specific cert for that specific registry, rather than blowing up your SSL settings across the board. Takes an extra five minutes to set up but you'll thank yourself later.
Fallback: Clear the npm cache and check your proxy settings
If none of the above worked, two more things to try before you start Googling more aggressively.
Clear your npm cache — sometimes stale or corrupted cache entries cause weird cert-related behavior:
npm cache clean --force
Then check if you've got proxy settings that might be intercepting your traffic:
npm config get proxy
npm config get https-proxy
If either of those returns something that shouldn't be there, you can clear them:
npm config delete proxy
npm config delete https-proxy
Also worth checking your NODE_EXTRA_CA_CERTS environment variable. If it's set to a cert file that no longer exists, that'll cause this exact error. Just run echo $NODE_EXTRA_CA_CERTS (or echo %NODE_EXTRA_CA_CERTS% on Windows CMD) to see if it's pointing somewhere valid.
One last thing — if you're bouncing between a work network and home, this error has a habit of appearing whenever you switch environments. A VPN that does SSL inspection will cause this when you connect, and then it magically disappears when you disconnect. If that's the pattern you're seeing, the Fix #1 approach with your company's CA bundle is almost certainly the right long-term answer.
Hope this saves you the 45 minutes of Stack Overflow rabbit-holing I did the first time I hit this one.
๋๊ธ
๋๊ธ ์ฐ๊ธฐ