Linux Mint下Minikube部署遇SSL错误,Windows环境正常
问题:Linux Mint上Minikube Pod内SSL证书验证失败(Windows环境正常)
问题概述
在本地Linux Mint机器上部署R-ShinyVerse镜像时,curl、apt-get install等网络操作均因SSL错误失败。相同配置在Windows 11环境下完全正常,甚至配置cloudflared隧道后也能正常运行。已尝试禁用ufw防火墙并重启服务,问题仍未解决。
Dockerfile内容
FROM rocker/shiny-verse:4.4.1 ARG WHEN ENV NVM_DIR /root/.nvm # Install apps RUN apt-get update RUN apt-get install -y sudo curl rclone cron rsyslog procps systemd \ libcurl4-openssl-dev libssl-dev \ libxml2-dev libfontconfig1-dev libharfbuzz-dev libfribidi-dev \ libfreetype6-dev libpng-dev libtiff5-dev libjpeg-dev RUN curl https://rclone.org/install.sh | bash # Install library for R RUN R -e "options(repos = \ list(CRAN = 'https://packagemanager.posit.co/cran/${WHEN}/')); \ if (!require('pacman')) install.packages('pacman'); \ pacman::p_load(tidyverse, ggplot2, dplyr, httr2, glue, stats, readr, \ lubridate, jsonlite, qualtRics, here, rmarkdown, \ formattable, tidyr, shiny, DT, knitr, kableExtra, data.table, \ tinytex, flextable, officer, stringr, rlang, mailR, geometry, install = T, update = F); \ tinytex::install_tinytex();"
Kubernetes部署YAML
当前未配置服务组件(如LoadBalancer/NodePort),部署文件如下:
apiVersion: apps/v1 kind: Deployment metadata: name: test-rwmain spec: replicas: 1 selector: matchLabels: app: rwmain-app template: metadata: labels: app: rwmain-app spec: containers: - name: rwmain image: rwmain:latest imagePullPolicy: Never
错误日志示例
执行curl -vvv https://example.net返回以下SSL错误:
# curl -vvv https://example.net * Trying 192.168.1.1:443... * Connected to example.net (192.168.1.1) port 443 (#0) * ALPN, offering h2 * ALPN, offering http/1.1 * CAfile: /etc/ssl/certs/ca-certificates.crt * CApath: /etc/ssl/certs * TLSv1.0 (OUT), TLS header, Certificate Status (22): * TLSv1.3 (OUT), TLS handshake, Client hello (1): * TLSv1.2 (IN), TLS header, Certificate Status (22): * TLSv1.3 (IN), TLS handshake, Server hello (2): * TLSv1.2 (IN), TLS header, Finished (20): * TLSv1.2 (IN), TLS header, Supplemental data (23): * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): * TLSv1.2 (IN), TLS header, Supplemental data (23): * TLSv1.3 (IN), TLS handshake, Certificate (11): * TLSv1.2 (OUT), TLS header, Unknown (21): * TLSv1.3 (OUT), TLS alert, bad certificate (554): * SSL certificate problem: EE certificate key too weak * Closing connection 0 curl: (60) SSL certificate problem: EE certificate key too weak More details here: https://curl.se/docs/sslcerts.html curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the web page mentioned above.
补充信息
- 系统环境:Minikube v1.34.0,Linux Mint 22(Cinnamon),Kubernetes v1.31.0,Docker 27.2.0
- 调试发现:在Linux Mint的Pod内执行
openssl s_client -connect example.net:443 -showcerts,返回的是1024位Sagemcom RSA密钥(推测为错误根源);但Linux宿主机、Windows机器及Windows Minikube Pod均返回Digicert 2048位密钥。
待解决问题
- 如何进一步调试该SSL证书验证失败问题?
- 为何相同配置在Windows环境正常,却在Linux Mint上失败?
内容的提问来源于stack exchange,提问作者silverfox
相关产品推荐
相关产品推荐

