Photo by Artiom Vallat on Unsplash
So I was trying to set up a new dev environment on a work laptop at like 11pm, running npm install on a fresh project, and immediately got smacked with this:
npm ERR! code SELF_SIGNED_CERT_IN_CHAIN
npm ERR! errno SELF_SIGNED_CERT_IN_CHAIN
npm ERR! request to https://registry.npmjs.org/react failed,
reason: self signed certificate in certificate chain
Cool. Love it. Nothing like a cryptic SSL error to ruin your evening.
If you've landed here, you're probably seeing some variation of that — maybe it's UNABLE_TO_VERIFY_LEAF_SIGNATURE or just a generic certificate has expired message. They're all cousins of the same problem, and honestly, the npm self signed certificate error is one of those things that catches people off guard because it has nothing to do with your code.
Why Does This Even Happen?
Here's the thing — this almost always comes down to one of two situations. Either you're on a corporate network that uses a proxy with its own SSL certificate (super common in enterprise environments), or your Node.js/npm installation is working with an outdated or misconfigured CA (Certificate Authority) store.
Corporate proxies are the usual culprit. Your company's network does SSL inspection — it intercepts HTTPS traffic, decrypts it, inspects it, then re-encrypts it with their own internal certificate. Which is... fine, I guess, from a security standpoint. But npm doesn't know about that internal cert, so it freaks out and refuses the connection.
The other scenario is less common but worth mentioning — if you're running an older version of Node, the bundled CA store might just be stale. Certificate authority stuff changes more often than you'd think.
Fix #1: Point npm to Your Corporate Certificate (The Right Way)
This is the proper fix if you're on a work machine. Your IT department should be able to give you the corporate root certificate — it's usually a .pem or .crt file. Once you've got it, you tell npm to trust it:
npm config set cafile /path/to/your-corporate-cert.pem
You can verify it got set with:
npm config get cafile
This is the cleanest solution because you're not disabling any security — you're just giving npm the context it needs to verify the certificate chain properly. In my experience, this fixes it permanently and you never have to touch it again on that machine.
If you don't know where to get the certificate file, honestly just ask IT. They deal with this all the time. You can also export it manually from your browser — in Chrome, go to the padlock on any HTTPS site, view the certificate, and export the root CA cert. A bit tedious but it works.
Fix #2: Set the NODE_EXTRA_CA_CERTS Environment Variable
This one's great if you need the fix to apply across different tools, not just npm. Instead of configuring npm specifically, you set an environment variable that Node itself uses:
On Mac/Linux, add this to your .bashrc or .zshrc:
export NODE_EXTRA_CA_CERTS=/path/to/your-corporate-cert.pem
On Windows (PowerShell):
[System.Environment]::SetEnvironmentVariable("NODE_EXTRA_CA_CERTS", "C:\path\to\your-corporate-cert.pem", "User")
Then restart your terminal. This is handy because it also covers tools like Yarn, pnpm, or anything else that runs on Node and might hit the same SSL verification issue. I've seen teams set this globally on dev machines as part of their onboarding scripts — smart move if your company has a lot of devs hitting this.
Fix #3: Disable Strict SSL (Use With Caution)
Alright, I'm going to include this one because people do it and sometimes it's the only option when you're in a pinch — but I want to be upfront that it's not ideal for anything beyond local development or a quick temporary fix.
npm config set strict-ssl false
This tells npm to stop verifying SSL certificates entirely. It'll work, your packages will install, and you'll move on with your life. But you're essentially turning off the part of npm that checks whether you're actually talking to the real npmjs.org. On a corporate network where SSL inspection is happening, the risk is relatively low. In other contexts, it's a genuine security concern.
If you go this route, at least limit it to your local config and undo it when you're done:
# Check your current config
npm config list
# To revert later
npm config set strict-ssl true
Seriously though — use Fix #1 or Fix #2 if at all possible.
Fallback: Update Node.js
If none of the above applies — you're not behind a corporate proxy, your certificate stuff looks fine — try updating Node.js. Old versions sometimes have CA store issues that just... go away with an update. Grab the latest LTS from nodejs.org or use a version manager:
# If you're using nvm
nvm install --lts
nvm use --lts
And while you're at it, update npm itself:
npm install -g npm@latest
I've had this silently fix SSL-related weirdness more than once. Worth trying before you go too deep into certificate debugging rabbit holes.
One more thing — if you're running this in a Docker container or CI pipeline, the certificate issue might be at the image level. You'd need to add the CA cert to the container's trust store during the build step. That's a whole other post, but worth knowing if none of this is sticking.
Hope this saves you the hour of Googling I had to do at 11pm. Fix #1 with the cafile setting is almost always the answer on corporate machines — get that cert file from IT and you'll be good.
Related: How to Fix npm Error Code self_signed_cert_in_chain (Quick Fix)
๋๊ธ
๋๊ธ ์ฐ๊ธฐ