Skip to content

Conversation

@tsmithsz
Copy link
Contributor

@tsmithsz tsmithsz commented Jun 25, 2025

Problem

We were previously setting NODE_OPTIONS=--use-openssl-ca, which causes Node to ignore the OS trust store and only use its built-in OpenSSL bundle—breaking TLS validation against corporate/internal CAs and leading to unable to get local issuer certificate errors.

We reverted the change to enable experimental proxy support and use the built-in OpenSSL. We only need to modify the use of the NODE_OPTIONS environment variable.

Reverted commit: #7487
Screenshot 2025-06-11 at 4 12 11 PM

Solution

  • Switch to (--use-system-ca)[https://nodejs.org/api/cli.html#--use-system-ca] so Node will load both its bundled roots and the system’s certificate store, restoring proper trust and eliminating the errors.
  • Re-enable experimental proxy support

Testing

  • Verified logs related to SSPC:

[2025-06-25T21:55:45.956Z] Successfully uploaded to S3: workspaceFolder=aws-toolkit-vscode language=javascript`

  • Treat all work as PUBLIC. Private feature/x branches will not be squash-merged at release time.
  • Your code changes must meet the guidelines in CONTRIBUTING.md.
  • License: I confirm that my contribution is made under the terms of the Apache 2.0 license.

@tsmithsz tsmithsz requested a review from a team as a code owner June 25, 2025 22:03
@github-actions
Copy link

  • This pull request modifies code in src/* but no tests were added/updated.
    • Confirm whether tests should be added or ensure the PR description explains why tests are not required.
  • This pull request implements a feat or fix, so it must include a changelog entry (unless the fix is for an unreleased feature). Review the changelog guidelines.
    • Note: beta or "experiment" features that have active users should announce fixes in the changelog.
    • If this is not a feature or fix, use an appropriate type from the title guidelines. For example, telemetry-only changes should use the telemetry type.

@laileni-aws
Copy link
Contributor

/retryBuilds

@tsmithsz tsmithsz merged commit 0b76f7f into aws:master Jun 25, 2025
30 of 31 checks passed
@tsmithsz tsmithsz deleted the fix-amazonq-proxy branch June 25, 2025 22:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants