Photo by รrpรกd Czapp on Unsplash
So I was setting up a new dev environment behind a corporate proxy — you know how it goes — and every single npm install I ran just died with this:
npm error code self_signed_cert_in_chain
npm error errno self_signed_cert_in_chain
npm error request to https://registry.npmjs.org/some-package failed, reason: self signed certificate in certificate chain
First time I saw this I spent about 45 minutes going down the wrong rabbit hole. The second time it happened to me (different job, same corporate network nonsense), I fixed it in under 5 minutes. Let me save you that 45 minutes.
Why This Actually Happens
Here's the thing — this isn't really an npm bug. What's happening is that your npm client is trying to reach the npm registry over HTTPS, and somewhere between your machine and the internet there's a proxy or a firewall doing SSL inspection. It basically intercepts your HTTPS traffic and re-signs it with its own certificate. npm looks at that certificate, doesn't recognize the issuer because it's not in Node's trusted CA bundle, and throws its hands up.
This is stupidly common in enterprise environments. I've seen it a hundred times. Sometimes it also pops up if you're on a VPN that does deep packet inspection, or if someone set up a private npm registry with a self-signed cert and didn't finish the configuration properly.
There's also a related error you might see — npm error code unable_to_get_issuer_cert_locally — which is basically the same root cause, just slightly different depending on where in the cert chain the validation fails.
Fix 1: Add Your Company's CA Certificate to npm
This is honestly the right way to fix it, especially if you're on a work machine long-term. Your IT team or network admin should be able to give you the corporate root CA certificate file (usually a .pem or .crt file). Once you have it, you tell npm to use it:
npm config set cafile /path/to/your-corporate-ca.pem
You can verify it got set with:
npm config get cafile
If you don't know where to get the cert file, on Windows you can export it from the Certificate Manager (certmgr.msc), find the root CA under Trusted Root Certification Authorities, and export it as Base-64 encoded X.509. On Mac, you'd dig into Keychain Access. It's a bit of a pain, but you only do it once per machine.
Fix 2: Point npm at the Right Node CA Store
Sometimes the corporate cert is already trusted by your OS but Node.js doesn't use the system cert store by default — it ships with its own bundled CA list. There's a workaround for this using an environment variable called NODE_EXTRA_CA_CERTS.
On Mac/Linux, add this to your .bashrc or .zshrc:
export NODE_EXTRA_CA_CERTS=/path/to/your-corporate-ca.pem
On Windows (Command Prompt):
set NODE_EXTRA_CA_CERTS=C:\path\to\your-corporate-ca.pem
Or set it permanently through System Properties > Environment Variables. This approach is cleaner than the next fix because it actually solves the problem rather than working around it — you're telling Node to trust the right cert instead of telling it to stop caring about certs entirely.
Fix 3: Disable SSL Verification (Use With Caution)
Alright, so sometimes you just need to ship something and you don't have time to chase down a CA cert file. Or you're on a personal machine and it's a one-off weird network situation. In that case:
npm config set strict-ssl false
And then run your install. After you're done, please turn it back on:
npm config set strict-ssl true
I want to be real with you here — leaving strict-ssl set to false permanently is a bad idea. You're basically telling npm "I don't care who signed this, just trust it." That's fine on a trusted network in a pinch, but you shouldn't make it a habit. I've seen people set this and forget it for months. Don't be that person.
(Side note: if you're also hitting the npm error code unable_to_get_issuer_cert_locally variant, all three of these fixes apply the same way. Same root cause, same solutions.)
Fallback: Check if It's Your Registry, Not npm
If you've tried all of the above and you're still getting the cert error, check what registry npm is actually pointed at:
npm config get registry
If it's showing something other than https://registry.npmjs.org/ — like an internal Nexus or Artifactory URL — then the self-signed cert might belong to that private registry. In that case, whoever set up that registry needs to either get a proper cert or give you the self-signed one to add via the cafile method above. That's a conversation to have with your DevOps or infrastructure team.
Also worth double-checking: run npm config list to see if there's an .npmrc file somewhere in your project directory overriding your global settings. I've been burned by that more than once — spent ages fixing the global config while a local .npmrc was quietly undoing everything.
Hope this gets you unblocked fast. The CA cert method is the one I'd recommend for anything longer than a one-day setup — it's the fix that'll actually stick.
๋๊ธ
๋๊ธ ์ฐ๊ธฐ