.NET Core 6 Docker容器启用HTTPS时遭遇证书错误求助
项目背景
基于.NET 6构建的REST API,计划部署到Linux Docker环境,当前在Windows 10的Docker Desktop上进行测试验证。
Dockerfile内容
FROM mcr.microsoft.com/dotnet/aspnet:6.0 AS base WORKDIR /app #EXPOSE 80 #EXPOSE 443 FROM mcr.microsoft.com/dotnet/sdk:6.0 AS build WORKDIR /src COPY ./TTKDS.Web/TTKDS.Web.csproj ./TTKDS.Web/ COPY ./TTKDS.Infra/TTKDS.Infra.csproj ./TTKDS.Infra/ COPY ./TTKDS.Core/TTKDS.Core.csproj ./TTKDS.Core/ COPY . . RUN dotnet restore ./TTKDS.Web/TTKDS.Web.csproj --disable-parallel RUN dotnet build ./TTKDS.Web/TTKDS.Web.csproj -c Release -o /app/build FROM build AS publish RUN dotnet publish ./TTKDS.Web/TTKDS.Web.csproj -c Release -o /app/publish /p:UseAppHost=false FROM base AS final WORKDIR /app COPY --from=publish /app/publish . EXPOSE 7245 EXPOSE 7345 ENV ASPNETCORE_URLS=http://*:7245;https://*:7345 ENTRYPOINT ["dotnet", "TTKDS.Web.dll"]
HTTP模式验证正常
执行以下命令后,访问http://localhost:7245/api/Item/1可正常响应,说明Dockerfile及代码逻辑无问题:
docker run --rm -p 7245:7245 -e ASPNETCORE_URLS=http://*:7245 ttkds.web:v1
HTTPS配置步骤
已执行以下HTTPS证书配置操作:
PS D:\Projects\TTKDS Core> dotnet dev-certs https --clean Cleaning HTTPS development certificates from the machine. A prompt might get displayed to confirm the removal of some of the certificates. HTTPS development certificates successfully removed from the machine. PS D:\Projects\TTKDS Core> dotnet dev-certs https -ep %USERPROFILE%\.aspnet\https\aspnetapp.pfx -p demoapp The HTTPS developer certificate was generated successfully. PS D:\Projects\TTKDS Core> dotnet dev-certs https --trust Trusting the HTTPS development certificate was requested. A confirmation prompt will be displayed if the certificate was not previously trusted. Click yes on the prompt to trust the certificate. Successfully trusted the existing HTTPS certificate. PS D:\Projects\TTKDS Core> dotnet user-secrets init -p .\TTKDS.Web\TTKDS.Web.csproj The MSBuild project 'D:\Projects\TTKDS Core\.\TTKDS.Web\TTKDS.Web.csproj' has already been initialized with a UserSecretsId. PS D:\Projects\TTKDS Core> dotnet user-secrets -p .\TTKDS.Web\TTKDS.Web.csproj set "Kestrel:Certificates:Development:Password" "demoapp" Successfully saved Kestrel:Certificates:Development:Password = demoapp to the secret store.
两种HTTPS启动命令均报错
命令1及报错
PS D:\Projects\TTKDS Core> docker run --rm -it -p 7245:7245 -p 7345:7345 -e ASPNETCORE_URLS="https://*:7345;http://*:7245" -e ASPNETCORE_ENVIRONMENT=Development -v $env:APPDATA\microsoft\UserSecrets\:/root/.microsoft/usersecrets -v $env:USERPROFILE\.aspnet\https:/root/.aspnet/https/ ttkds.web:v1
Unhandled exception. System.InvalidOperationException: Unable to configure HTTPS endpoint. No server certificate was specified, and the default developer certificate could not be found or is out of date.
To generate a developer certificate run 'dotnet dev-certs https'. To trust the certificate (Windows and macOS only) run 'dotnet dev-certs https --trust'.
命令2及报错
PS D:\Projects\TTKDS Core> docker run --rm -p 7245:7245 -p 7345:7345 -e ASPNETCORE_URLS=https://localhost:7345 -e ASPNETCORE_Kestrel__Certificates__Default__Password=demoapp -e ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx -v C:\Users\BVSim\.aspnet\https:/https/ ttkds.web:v1
Unhandled exception.
System.Security.Cryptography.CryptographicException: The certificate data cannot be read with the provided password, the password may be incorrect.
System.Security.Cryptography.CryptographicException: The certificate data cannot be read with the provided password, the password may be incorrect.
问题排查与解决方案
针对命令1的问题
Linux容器区分路径大小写,你映射的UserSecrets路径为全小写/root/.microsoft/usersecrets,但容器内实际读取路径是/root/.microsoft/UserSecrets(首字母大写),导致无法读取密码配置。
修正后的命令1:
docker run --rm -it -p 7245:7245 -p 7345:7345 ` -e ASPNETCORE_URLS="https://*:7345;http://*:7245" ` -e ASPNETCORE_ENVIRONMENT=Development ` -v "$($env:APPDATA)\microsoft\UserSecrets\:/root/.microsoft/UserSecrets" ` -v "$($env:USERPROFILE)\.aspnet\https:/root/.aspnet/https" ttkds.web:v1
针对命令2的问题
- 路径与访问权限:Linux容器区分大小写,确保映射路径和证书文件名无拼写错误,同时确认Windows侧的
aspnetapp.pfx文件确实存在于C:\Users\BVSim\.aspnet\https目录下。 - 端口配置修正:
ASPNETCORE_URLS设置为https://localhost:7345会导致容器外无法访问,需改为https://*:7345,如需保留HTTP端口可写成https://*:7345;http://*:7245。 - 密码一致性检查:确认生成证书时的密码
demoapp与环境变量中的密码完全一致,无空格或大小写差异。
修正后的命令2:
docker run --rm -p 7245:7245 -p 7345:7345 ` -e ASPNETCORE_URLS="https://*:7345;http://*:7245" ` -e ASPNETCORE_Kestrel__Certificates__Default__Password=demoapp ` -e ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx ` -v "C:\Users\BVSim\.aspnet\https:/https" ttkds.web:v1
额外建议:使用Docker Compose简化配置
提供基础docker-compose.yml配置,便于管理容器启动参数:
version: '3.8' services: ttkds-api: image: ttkds.web:v1 ports: - "7245:7245" - "7345:7345" environment: - ASPNETCORE_URLS=https://*:7345;http://*:7245 - ASPNETCORE_ENVIRONMENT=Development - ASPNETCORE_Kestrel__Certificates__Default__Password=demoapp - ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx volumes: - ${USERPROFILE}\.aspnet\https:/https - ${APPDATA}\microsoft\UserSecrets:/root/.microsoft/UserSecrets
启动命令:
docker-compose up
内容的提问来源于stack exchange,提问作者Balaji V

