Ubuntu Pro 20.04镜像中自定义根CA证书无法被识别,导致Terraform、Docker等工具安装失败
Hi there, let's troubleshoot this step by step. I spotted a few potential issues in your setup that could be causing the certificate not to be picked up, plus some tool-specific configurations you might need to adjust.
1. Fix the directory name typo (critical mistake!)
Looking at your reproduction steps, there's a typo in the directory path when copying the certificate:
sudo cp root-ca-certificate.pem /usr/local/share/ca-certificat/root-ca-certificate.crt
Notice the missing 'e' at the end of ca-certificat—it should be ca-certificates. This means your certificate was copied to a non-standard directory that update-ca-certificates doesn't scan. Correct this step to:
sudo cp root-ca-certificate.pem /usr/local/share/ca-certificates/root-ca-certificate.crt
2. Verify and re-run the certificate installation
After fixing the path, follow these steps properly to ensure the certificate is recognized:
- Double-check that the certificate file uses the
.crtextension (you did this correctly, but it's worth confirming) - Set proper permissions on the certificate:
sudo chmod 644 /usr/local/share/ca-certificates/root-ca-certificate.crt - Run
update-ca-certificatesin verbose mode to see exactly what's happening:
You should see output likesudo update-ca-certificates -v1 added, 0 removed; done.if the certificate was successfully loaded. If not, check if your PEM file is correctly formatted (make sure the-----BEGIN CERTIFICATE-----and-----END CERTIFICATE-----lines are present and not corrupted).
3. Check if system tools recognize the certificate
Test if curl trusts the certificate now:
curl -v https://your-target-url.com
If you still get the SSL error, verify that the root CA you added is indeed the one that signs the certificate chain for the target URL. Sometimes company proxies intercept SSL traffic, so you might need to add the proxy's CA certificate instead of your custom root CA.
4. Tool-specific configurations
Even if the system CA store is updated, some tools like Docker don't automatically use the system certificates. Here's how to fix that:
For Docker:
- Create a directory for Docker certificates:
sudo mkdir -p /etc/docker/certs.d - Copy your root CA certificate to this directory:
sudo cp /usr/local/share/ca-certificates/root-ca-certificate.crt /etc/docker/certs.d/ - Restart the Docker daemon:
sudo systemctl restart docker
For Terraform and other curl-based installs:
Ensure your proxy and SSL environment variables are correctly set. Add these lines to your shell script (adjust proxy URLs as needed):
export HTTP_PROXY=http://your-proxy:port export HTTPS_PROXY=http://your-proxy:port export NO_PROXY=localhost,127.0.0.1 export SSL_CERT_FILE=/etc/ssl/certs/ca-certificates.crt
The SSL_CERT_FILE variable ensures curl uses the system CA bundle.
5. Additional checks if issues persist
- Run
dpkg-reconfigure ca-certificatesand make sure the "trust new certificates from /usr/local/share/ca-certificates" option is enabled (it should be by default) - Verify that your certificate is listed in
/etc/ca-certificates.conf(files in/usr/local/share/ca-certificates/are usually added automatically, but you can manually add a line likelocal/root-ca-certificate.crtif needed) - Check if any other SSL-related environment variables are overriding the system CA store (e.g.,
CURL_CA_BUNDLE)
Let me know if any of these steps resolve your issue!
备注:内容来源于stack exchange,提问作者Petria3s

