# Error: The certificate contains a delegation that does not include the canister aaaaa-aa in the canister\_ranges field

**URL:** <https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766>\
**Category:** JavaScript\
**Created:** [September 21, 2025, 2:25am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766 "2025-09-21T02:25:57Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Huygon764](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/huygon764/32/30890_2.png) [@Huygon764](https://forum.dfinity.org/u/Huygon764)\
**Post date:** [September 21, 2025, 2:25am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/1 "2025-09-21T02:25:57Z")

</div>

Hi guys, I’m trying to create a canister from the backend (NestJS) and install\_code into it. But I’m getting this error:

`The certificate contains a delegation that does not include the canister aaaaa-aa in the canister_ranges field`

This happens when I use `provisionalCreateCanisterWithCycles` locally.

I also started the replica with:  
`dfx start --clean`  
and it shows:  
`Replica API running on 127.0.0.1:4943. You must open a new terminal to continue developing. If you’d prefer to stop, quit with 'Ctrl-C'.`

This is the TypeScript code I’m using. Has anyone else faced this error before? Please help if you’ve run into it.

 ![image](https://us1.discourse-cdn.com/flex023/uploads/dfn/original/3X/0/b/0bf6f5c38e0db0a1f16cbc1af166489b5350b654.png)

---

<div class="post-metadata">

**Author:** ![rem.codes](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/rem.codes/32/40260_2.png) [@rem.codes](https://forum.dfinity.org/u/rem.codes)\
**Post date:** [September 21, 2025, 6:21am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/2 "2025-09-21T06:21:20Z")

</div>

You should install the NNS locally,

You can do so by doing;

`dfx extension install nns`  
`dfx extension run nns install`

After you ran your

`dfx start —clean —background`

---

<div class="post-metadata">

**Author:** ![peterparker](https://avatars.discourse-cdn.com/v4/letter/p/b9bd4f/32.png) [@peterparker](https://forum.dfinity.org/u/peterparker)\
**Post date:** [September 21, 2025, 6:23am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/3 "2025-09-21T06:23:31Z")

</div>

The issue - not being able to provision a canister locally - might be related to the fact that you’re executing the create call as an anonymous user. Try passing the identity to your agent:

```auto
const agent = await HttpAgent.create({
   // same
   identity <-----------

```

Side note: This isn’t your issue, but you can remove the line `await agent.fetchRootKey()` since you already pass `shouldFetchRootKey: true` when creating the agent.

---

<div class="post-metadata">

**Author:** ![Huygon764](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/huygon764/32/30890_2.png) [@Huygon764](https://forum.dfinity.org/u/Huygon764)\
**Post date:** [September 21, 2025, 7:52am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/4 "2025-09-21T07:52:06Z")

</div>

I tried, but it still not working man

---

<div class="post-metadata">

**Author:** ![Huygon764](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/huygon764/32/30890_2.png) [@Huygon764](https://forum.dfinity.org/u/Huygon764)\
**Post date:** [September 21, 2025, 7:52am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/5 "2025-09-21T07:52:46Z")

</div>

Yeah, I also tried to using it first: “const identity = Ed25519KeyIdentity.generate();”. But it still not working :((

---

<div class="post-metadata">

**Author:** ![peterparker](https://avatars.discourse-cdn.com/v4/letter/p/b9bd4f/32.png) [@peterparker](https://forum.dfinity.org/u/peterparker)\
**Post date:** [September 21, 2025, 8:09am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/6 "2025-09-21T08:09:43Z")

</div>

1. I’m confuse, did you pass the `identity` to `await HttpAgent.create` or not? Can you share the resulting code snippet?

2. What version of `@dfinity/ic-management` are you using?

---

<div class="post-metadata">

**Author:** ![Huygon764](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/huygon764/32/30890_2.png) [@Huygon764](https://forum.dfinity.org/u/Huygon764)\
**Post date:** [September 21, 2025, 8:23am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/8 "2025-09-21T08:23:25Z")

</div>

here is the code man, and I use the newest version from yarn: “@dfinitydfinitydfinitydfinity/ic-management”: "^7.0.2”

 ![image](https://us1.discourse-cdn.com/flex023/uploads/dfn/original/3X/4/a/4a9ac66d425adbfa74b5e5aff42cc710684a974d.png)

---

<div class="post-metadata">

**Author:** ![Huygon764](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/huygon764/32/30890_2.png) [@Huygon764](https://forum.dfinity.org/u/Huygon764)\
**Post date:** [September 21, 2025, 8:25am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/9 "2025-09-21T08:25:18Z")

</div>

I tried to log it, and it seem created success. But I dont know why it still return error

 ![image](https://us1.discourse-cdn.com/flex023/uploads/dfn/original/3X/c/3/c371385557781acfc9c7685f7f9c5147f4f6f433.png)

---

<div class="post-metadata">

**Author:** ![peterparker](https://avatars.discourse-cdn.com/v4/letter/p/b9bd4f/32.png) [@peterparker](https://forum.dfinity.org/u/peterparker)\
**Post date:** [September 21, 2025, 8:40am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/10 "2025-09-21T08:40:33Z")

</div>

Great.

1. I’m not familiar with DFX but, isn’t port `8080` deprecated in favor of `4943` as in your first snippet? Have you try both this port and passing the identity?

2. Have you try to use `127.0.0.1` instead of `localhost`?

3. `v7.0.2` should be good. You can try `v7.0.1`, that’s the version I’m using but, I doubt that’s really the issue.

---

<div class="post-metadata">

**Author:** ![Huygon764](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/huygon764/32/30890_2.png) [@Huygon764](https://forum.dfinity.org/u/Huygon764)\
**Post date:** [September 21, 2025, 8:48am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/11 "2025-09-21T08:48:34Z")

</div>

I tried all you said man, hmm it’s still not working. I means by log I give you above, it’s created success, but it still return error, dont understand it hmm

---

<div class="post-metadata">

**Author:** ![peterparker](https://avatars.discourse-cdn.com/v4/letter/p/b9bd4f/32.png) [@peterparker](https://forum.dfinity.org/u/peterparker)\
**Post date:** [September 21, 2025, 8:49am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/12 "2025-09-21T08:49:43Z")

</div>

Umm, I don’t know then, sorry. It doesn’t seem related to the JS code.

---

<div class="post-metadata">

**Author:** ![Huygon764](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/huygon764/32/30890_2.png) [@Huygon764](https://forum.dfinity.org/u/Huygon764)\
**Post date:** [September 21, 2025, 8:54am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/13 "2025-09-21T08:54:34Z")

</div>

okay thank you man, I will try to find another way hmm

---

<div class="post-metadata">

**Author:** ![Vivienne](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/vivienne/32/29170_2.png) [@Vivienne](https://forum.dfinity.org/u/Vivienne)\
**Post date:** [September 22, 2025, 8:29am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/14 "2025-09-22T08:29:40Z")

</div>

This error usually happens if the effective canister id of the call is not set properly, but I can’t figure out how to set it. @ilbert do you know?

---

<div class="post-metadata">

**Author:** ![Huygon764](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/huygon764/32/30890_2.png) [@Huygon764](https://forum.dfinity.org/u/Huygon764)\
**Post date:** [September 22, 2025, 8:45am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/15 "2025-09-22T08:45:01Z")

</div>

I see we can set it with install\_code, but not for “provisional\_create\_canister\_with\_cycles” :((

---

<div class="post-metadata">

**Author:** ![ilbert](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/ilbert/32/8717_2.png) [@ilbert](https://forum.dfinity.org/u/ilbert)\
**Post date:** [September 22, 2025, 8:59am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/16 "2025-09-22T08:59:57Z")

</div>

Since [v3.2.0](https://js.icp.build/core/latest/changelog#320---2025-08-07) (and specifically [PR#1083](https://github.com/dfinity/icp-js-core/pull/1083)), we always check if the target canister is in the allowed subnet’s range. Before, we were only performing the check it if the target canister was not the management canister.

After a quick discussion with @mraszyk, I plan to fix this by skipping the check if, and only if, the target canister is the management canister, the target method is `provisional_create_canister_with_cycles` and network is not mainnet.

---

<div class="post-metadata">

**Author:** ![peterparker](https://avatars.discourse-cdn.com/v4/letter/p/b9bd4f/32.png) [@peterparker](https://forum.dfinity.org/u/peterparker)\
**Post date:** [September 22, 2025, 9:18am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/17 "2025-09-22T09:18:32Z")

</div>

Good input!

@Huygon764 what version of `@dfinity/ic-management` are you using?

The library uses a custom [transform](https://github.com/dfinity/ic-js/blob/370ec885c057c30221846e8d9e425d78435130ac/packages/ic-management/src/utils/transform.utils.ts#L21) function that correctly sets the `effectiveCanisterId` for `provisional_create_canister_with_cycles`. This was added at the beginning of June.

---

<div class="post-metadata">

**Author:** ![Huygon764](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/huygon764/32/30890_2.png) [@Huygon764](https://forum.dfinity.org/u/Huygon764)\
**Post date:** [September 22, 2025, 9:22am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/18 "2025-09-22T09:22:56Z")

</div>

I using newest version: “7.0.2” man

---

<div class="post-metadata">

**Author:** ![mraszyk](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/mraszyk/32/7945_2.png) [@mraszyk](https://forum.dfinity.org/u/mraszyk)\
**Post date:** [September 22, 2025, 10:09am UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/19 "2025-09-22T10:09:15Z")

</div>

> [@peterparker](#):
>
> The library uses a custom [transform](https://github.com/dfinity/ic-js/blob/370ec885c057c30221846e8d9e425d78435130ac/packages/ic-management/src/utils/transform.utils.ts#L21) function that correctly sets the `effectiveCanisterId` for `provisional_create_canister_with_cycles`. This was added at the beginning of June.

In that case, there should be no need for an exception to verifying canister ranges as @ilbert described it above.

---

<div class="post-metadata">

**Author:** ![peterparker](https://avatars.discourse-cdn.com/v4/letter/p/b9bd4f/32.png) [@peterparker](https://forum.dfinity.org/u/peterparker)\
**Post date:** [September 22, 2025, 5:19pm UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/20 "2025-09-22T17:19:11Z")

</div>

Is your code open source, or can you share your script’s code?

I can try using it to reproduce the issue against my Docker container, where all the features we mentioned in this thread are working as expected. If I cannot reproduce the issue in this setup, then maybe someone else can try with dfx.

---

<div class="post-metadata">

**Author:** ![marc0olo](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/marc0olo/32/17290_2.png) [@marc0olo](https://forum.dfinity.org/u/marc0olo)\
**Post date:** [September 22, 2025, 6:36pm UTC](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766/21 "2025-09-22T18:36:15Z")

</div>

he shared the code on Discord: [GitHub - Huygon764/test-create-canister](https://github.com/Huygon764/test-create-canister)

[Next page](https://forum.dfinity.org/t/error-the-certificate-contains-a-delegation-that-does-not-include-the-canister-aaaaa-aa-in-the-canister-ranges-field/57766.md?page=2)
