Skip to content

client-certificate-auth API Reference


client-certificate-auth API Reference / parsers / parseBase64Der

Function: parseBase64Der() ​

parseBase64Der(headerValue, options?): ChainedPeerCertificate | null

Defined in: parsers.js:419

Parse base64-encoded DER certificate (Cloudflare format). Also handles Traefik's comma-separated cert chains - parses all certs and links them via the issuerCertificate property. Empty entries after the leaf are ignored; more than MAX_CHAIN_CERTS entries reject the header.

Parameters ​

headerValue ​

string

Base64-encoded DER certificate(s)

options? ​

chainInLeafHeader: false rejects a comma instead of reading the value as a chain, for a source that forwards the leaf alone.

chainInLeafHeader? ​

boolean = true

Returns ​

ChainedPeerCertificate | null

Parsed certificate or null on failure

See ​

https://developers.cloudflare.com/api-shield/security/mtls/configure/

Released under the MIT License.