You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu Pro 20.04镜像中自定义根CA证书无法被识别,导致Terraform、Docker等工具安装失败

Ubuntu Pro 20.04镜像中自定义根CA证书无法被识别,导致Terraform、Docker等工具安装失败

Hi there, let's troubleshoot this step by step. I spotted a few potential issues in your setup that could be causing the certificate not to be picked up, plus some tool-specific configurations you might need to adjust.

1. Fix the directory name typo (critical mistake!)

Looking at your reproduction steps, there's a typo in the directory path when copying the certificate:

sudo cp root-ca-certificate.pem  /usr/local/share/ca-certificat/root-ca-certificate.crt

Notice the missing 'e' at the end of ca-certificat—it should be ca-certificates. This means your certificate was copied to a non-standard directory that update-ca-certificates doesn't scan. Correct this step to:

sudo cp root-ca-certificate.pem /usr/local/share/ca-certificates/root-ca-certificate.crt

2. Verify and re-run the certificate installation

After fixing the path, follow these steps properly to ensure the certificate is recognized:

  • Double-check that the certificate file uses the .crt extension (you did this correctly, but it's worth confirming)
  • Set proper permissions on the certificate:
    sudo chmod 644 /usr/local/share/ca-certificates/root-ca-certificate.crt
    
  • Run update-ca-certificates in verbose mode to see exactly what's happening:
    sudo update-ca-certificates -v
    
    You should see output like 1 added, 0 removed; done. if the certificate was successfully loaded. If not, check if your PEM file is correctly formatted (make sure the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines are present and not corrupted).

3. Check if system tools recognize the certificate

Test if curl trusts the certificate now:

curl -v https://your-target-url.com

If you still get the SSL error, verify that the root CA you added is indeed the one that signs the certificate chain for the target URL. Sometimes company proxies intercept SSL traffic, so you might need to add the proxy's CA certificate instead of your custom root CA.

4. Tool-specific configurations

Even if the system CA store is updated, some tools like Docker don't automatically use the system certificates. Here's how to fix that:

For Docker:

  • Create a directory for Docker certificates:
    sudo mkdir -p /etc/docker/certs.d
    
  • Copy your root CA certificate to this directory:
    sudo cp /usr/local/share/ca-certificates/root-ca-certificate.crt /etc/docker/certs.d/
    
  • Restart the Docker daemon:
    sudo systemctl restart docker
    

For Terraform and other curl-based installs:

Ensure your proxy and SSL environment variables are correctly set. Add these lines to your shell script (adjust proxy URLs as needed):

export HTTP_PROXY=http://your-proxy:port
export HTTPS_PROXY=http://your-proxy:port
export NO_PROXY=localhost,127.0.0.1
export SSL_CERT_FILE=/etc/ssl/certs/ca-certificates.crt

The SSL_CERT_FILE variable ensures curl uses the system CA bundle.

5. Additional checks if issues persist

  • Run dpkg-reconfigure ca-certificates and make sure the "trust new certificates from /usr/local/share/ca-certificates" option is enabled (it should be by default)
  • Verify that your certificate is listed in /etc/ca-certificates.conf (files in /usr/local/share/ca-certificates/ are usually added automatically, but you can manually add a line like local/root-ca-certificate.crt if needed)
  • Check if any other SSL-related environment variables are overriding the system CA store (e.g., CURL_CA_BUNDLE)

Let me know if any of these steps resolve your issue!

备注:内容来源于stack exchange,提问作者Petria3s

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 08:37:59