@@ -2388,21 +2388,35 @@ const additionalCerts = ['-----BEGIN CERTIFICATE-----\n...'];
23882388tls .setDefaultCACertificates ([... currentCerts, ... additionalCerts]);
23892389```
23902390
2391- ## ` tls.getCACertificates([type ]) `
2391+ ## ` tls.getCACertificates([options ]) `
23922392
23932393<!-- YAML
23942394added:
23952395 - v23.10.0
23962396 - v22.15.0
2397- -->
2398-
2399- * ` type ` {string|undefined} The type of CA certificates that will be returned. Valid values
2400- are ` "default" ` , ` "system" ` , ` "bundled" ` and ` "extra" ` .
2401- ** Default:** ` "default" ` .
2402- * Returns: {string\[ ] } An array of PEM-encoded certificates. The array may contain duplicates
2403- if the same certificate is repeatedly stored in multiple sources.
2404-
2405- Returns an array containing the CA certificates from various sources, depending on ` type ` :
2397+ changes:
2398+ - version: REPLACEME
2399+ pr-url: https://github.com/nodejs/node/pull/59349
2400+ description: Added the `format` option and support for passing the `type`
2401+ as an `options` object to `getCACertificates()`.
2402+ -->
2403+
2404+ * ` options ` {string|Object|undefined}
2405+ Optional. If a string, it is treated as the ` type ` of certificates to return.
2406+ If an object, it may contain:
2407+ * ` type ` {string} The type of CA certificates to return. One of ` "default" ` , ` "system" ` , ` "bundled" ` , or ` "extra" ` .
2408+ ** Default:** ` "default" ` .
2409+ * ` format ` {string} The format of returned certificates. One of ` "pem" ` , ` "der" ` , or ` "x509" ` .
2410+ ** Default:** ` "pem" ` .
2411+ * ` "pem" ` (alias: ` "string" ` ): Returns an array of PEM-encoded certificate strings.
2412+ * ` "der" ` (alias: ` "buffer" ` ): Returns an array of certificate data as ` Buffer ` objects in DER format.
2413+ * ` "x509" ` : Returns an array of [ ` X509Certificate ` ] [ x509certificate ] instances.
2414+
2415+ * Returns: {Array}
2416+ An array of certificate data in the specified format:
2417+ * PEM strings when ` format ` is ` "pem" ` (or ` "string" ` ).
2418+ * ` Buffer ` objects containing DER data when ` format ` is ` "der" ` (or ` "buffer" ` ).
2419+ * [ ` X509Certificate ` ] [ x509certificate ] instances when ` format ` is ` "x509" ` .
24062420
24072421* ` "default" ` : return the CA certificates that will be used by the Node.js TLS clients by default.
24082422 * When [ ` --use-bundled-ca ` ] [ ] is enabled (default), or [ ` --use-openssl-ca ` ] [ ] is not enabled,
@@ -2411,11 +2425,14 @@ Returns an array containing the CA certificates from various sources, depending
24112425 trusted store.
24122426 * When [ ` NODE_EXTRA_CA_CERTS ` ] [ ] is used, this would also include certificates loaded from the specified
24132427 file.
2428+
24142429* ` "system" ` : return the CA certificates that are loaded from the system's trusted store, according
24152430 to rules set by [ ` --use-system-ca ` ] [ ] . This can be used to get the certificates from the system
24162431 when [ ` --use-system-ca ` ] [ ] is not enabled.
2432+
24172433* ` "bundled" ` : return the CA certificates from the bundled Mozilla CA store. This would be the same
24182434 as [ ` tls.rootCertificates ` ] [ ] .
2435+
24192436* ` "extra" ` : return the CA certificates loaded from [ ` NODE_EXTRA_CA_CERTS ` ] [ ] . It's an empty array if
24202437 [ ` NODE_EXTRA_CA_CERTS ` ] [ ] is not set.
24212438
@@ -2602,7 +2619,7 @@ added: v0.11.3
26022619[ `tls.connect()` ] : #tlsconnectoptions-callback
26032620[ `tls.createSecureContext()` ] : #tlscreatesecurecontextoptions
26042621[ `tls.createServer()` ] : #tlscreateserveroptions-secureconnectionlistener
2605- [ `tls.getCACertificates()` ] : #tlsgetcacertificatestype
2622+ [ `tls.getCACertificates()` ] : #tlsgetcacertificatesoptions
26062623[ `tls.getCiphers()` ] : #tlsgetciphers
26072624[ `tls.rootCertificates` ] : #tlsrootcertificates
26082625[ `x509.checkHost()` ] : crypto.md#x509checkhostname-options
@@ -2611,3 +2628,4 @@ added: v0.11.3
26112628[ cipher list format ] : https://www.openssl.org/docs/man1.1.1/man1/ciphers.html#CIPHER-LIST-FORMAT
26122629[ forward secrecy ] : https://en.wikipedia.org/wiki/Perfect_forward_secrecy
26132630[ perfect forward secrecy ] : #perfect-forward-secrecy
2631+ [ x509certificate ] : crypto.md#class-x509certificate
0 commit comments