You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linux Mint下Minikube部署遇SSL错误,Windows环境正常

问题:Linux Mint上Minikube Pod内SSL证书验证失败(Windows环境正常)

问题概述

在本地Linux Mint机器上部署R-ShinyVerse镜像时,curl、apt-get install等网络操作均因SSL错误失败。相同配置在Windows 11环境下完全正常,甚至配置cloudflared隧道后也能正常运行。已尝试禁用ufw防火墙并重启服务,问题仍未解决。

Dockerfile内容

FROM rocker/shiny-verse:4.4.1

ARG WHEN
ENV NVM_DIR /root/.nvm

# Install apps
RUN apt-get update
RUN apt-get install -y sudo curl rclone cron rsyslog procps systemd \
  libcurl4-openssl-dev libssl-dev \
  libxml2-dev libfontconfig1-dev libharfbuzz-dev libfribidi-dev \
  libfreetype6-dev libpng-dev libtiff5-dev libjpeg-dev
  
RUN curl https://rclone.org/install.sh | bash

# Install library for R
RUN R -e "options(repos = \
  list(CRAN = 'https://packagemanager.posit.co/cran/${WHEN}/')); \
  if (!require('pacman')) install.packages('pacman'); \
  pacman::p_load(tidyverse, ggplot2, dplyr, httr2, glue, stats, readr, \
  lubridate, jsonlite, qualtRics, here, rmarkdown, \
  formattable, tidyr, shiny, DT, knitr, kableExtra, data.table, \
  tinytex, flextable, officer, stringr, rlang, mailR, geometry, install = T, update = F); \
  tinytex::install_tinytex();"

Kubernetes部署YAML

当前未配置服务组件(如LoadBalancer/NodePort),部署文件如下:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: test-rwmain
spec:
  replicas: 1
  selector:
    matchLabels:
      app: rwmain-app
  template:
    metadata:
      labels:
        app: rwmain-app
    spec:
      containers:
      - name: rwmain
        image: rwmain:latest 
        imagePullPolicy: Never

错误日志示例

执行curl -vvv https://example.net返回以下SSL错误:

# curl -vvv https://example.net
*   Trying 192.168.1.1:443...
* Connected to example.net (192.168.1.1) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
*  CAfile: /etc/ssl/certs/ca-certificates.crt
*  CApath: /etc/ssl/certs
* TLSv1.0 (OUT), TLS header, Certificate Status (22):
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.2 (IN), TLS header, Certificate Status (22):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS header, Finished (20):
* TLSv1.2 (IN), TLS header, Supplemental data (23):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.2 (IN), TLS header, Supplemental data (23):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (OUT), TLS header, Unknown (21):
* TLSv1.3 (OUT), TLS alert, bad certificate (554):
* SSL certificate problem: EE certificate key too weak
* Closing connection 0
curl: (60) SSL certificate problem: EE certificate key too weak
More details here: https://curl.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the web page mentioned above.

补充信息

  • 系统环境:Minikube v1.34.0,Linux Mint 22(Cinnamon),Kubernetes v1.31.0,Docker 27.2.0
  • 调试发现:在Linux Mint的Pod内执行openssl s_client -connect example.net:443 -showcerts,返回的是1024位Sagemcom RSA密钥(推测为错误根源);但Linux宿主机、Windows机器及Windows Minikube Pod均返回Digicert 2048位密钥。

待解决问题

  1. 如何进一步调试该SSL证书验证失败问题?
  2. 为何相同配置在Windows环境正常,却在Linux Mint上失败?

内容的提问来源于stack exchange,提问作者silverfox

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 13:55:54