You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core 6 Docker容器启用HTTPS时遭遇证书错误求助

.NET 6 Docker HTTPS配置问题排查

项目背景

基于.NET 6构建的REST API,计划部署到Linux Docker环境,当前在Windows 10的Docker Desktop上进行测试验证。

Dockerfile内容

FROM mcr.microsoft.com/dotnet/aspnet:6.0 AS base
WORKDIR /app
#EXPOSE 80
#EXPOSE 443

FROM mcr.microsoft.com/dotnet/sdk:6.0 AS build
WORKDIR /src
COPY ./TTKDS.Web/TTKDS.Web.csproj ./TTKDS.Web/
COPY ./TTKDS.Infra/TTKDS.Infra.csproj ./TTKDS.Infra/
COPY ./TTKDS.Core/TTKDS.Core.csproj ./TTKDS.Core/
COPY . .
RUN dotnet restore ./TTKDS.Web/TTKDS.Web.csproj --disable-parallel
RUN dotnet build ./TTKDS.Web/TTKDS.Web.csproj  -c Release -o /app/build

FROM build AS publish
RUN dotnet publish ./TTKDS.Web/TTKDS.Web.csproj  -c Release -o /app/publish /p:UseAppHost=false

FROM base AS final
WORKDIR /app
COPY --from=publish /app/publish .

EXPOSE 7245
EXPOSE 7345
ENV ASPNETCORE_URLS=http://*:7245;https://*:7345

ENTRYPOINT ["dotnet", "TTKDS.Web.dll"]

HTTP模式验证正常

执行以下命令后,访问http://localhost:7245/api/Item/1可正常响应,说明Dockerfile及代码逻辑无问题:

docker run --rm -p 7245:7245 -e ASPNETCORE_URLS=http://*:7245 ttkds.web:v1

HTTPS配置步骤

已执行以下HTTPS证书配置操作:

PS D:\Projects\TTKDS Core> dotnet dev-certs https --clean
Cleaning HTTPS development certificates from the machine. A prompt might get displayed to confirm the removal of some of the certificates.
HTTPS development certificates successfully removed from the machine.

PS D:\Projects\TTKDS Core> dotnet dev-certs https -ep %USERPROFILE%\.aspnet\https\aspnetapp.pfx -p demoapp
The HTTPS developer certificate was generated successfully.

PS D:\Projects\TTKDS Core> dotnet dev-certs https --trust
Trusting the HTTPS development certificate was requested. A confirmation prompt will be displayed if the certificate was not previously trusted. Click yes on the prompt to trust the certificate.
Successfully trusted the existing HTTPS certificate.

PS D:\Projects\TTKDS Core> dotnet user-secrets init -p .\TTKDS.Web\TTKDS.Web.csproj
The MSBuild project 'D:\Projects\TTKDS Core\.\TTKDS.Web\TTKDS.Web.csproj' has already been initialized with a UserSecretsId.

PS D:\Projects\TTKDS Core> dotnet user-secrets -p .\TTKDS.Web\TTKDS.Web.csproj set "Kestrel:Certificates:Development:Password" "demoapp"
Successfully saved Kestrel:Certificates:Development:Password = demoapp to the secret store.

两种HTTPS启动命令均报错

命令1及报错

PS D:\Projects\TTKDS Core> docker run --rm -it -p 7245:7245 -p 7345:7345 
    -e ASPNETCORE_URLS="https://*:7345;http://*:7245" 
    -e ASPNETCORE_ENVIRONMENT=Development 
    -v $env:APPDATA\microsoft\UserSecrets\:/root/.microsoft/usersecrets 
    -v $env:USERPROFILE\.aspnet\https:/root/.aspnet/https/ ttkds.web:v1

Unhandled exception. System.InvalidOperationException: Unable to configure HTTPS endpoint. No server certificate was specified, and the default developer certificate could not be found or is out of date.

To generate a developer certificate run 'dotnet dev-certs https'. To trust the certificate (Windows and macOS only) run 'dotnet dev-certs https --trust'.

命令2及报错

PS D:\Projects\TTKDS Core> docker run --rm -p 7245:7245 -p 7345:7345 
     -e ASPNETCORE_URLS=https://localhost:7345 
     -e ASPNETCORE_Kestrel__Certificates__Default__Password=demoapp 
     -e ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx 
     -v C:\Users\BVSim\.aspnet\https:/https/  ttkds.web:v1

Unhandled exception.

System.Security.Cryptography.CryptographicException: The certificate data cannot be read with the provided password, the password may be incorrect.

System.Security.Cryptography.CryptographicException: The certificate data cannot be read with the provided password, the password may be incorrect.


问题排查与解决方案

针对命令1的问题

Linux容器区分路径大小写,你映射的UserSecrets路径为全小写/root/.microsoft/usersecrets,但容器内实际读取路径是/root/.microsoft/UserSecrets(首字母大写),导致无法读取密码配置。

修正后的命令1:

docker run --rm -it -p 7245:7245 -p 7345:7345 `
    -e ASPNETCORE_URLS="https://*:7345;http://*:7245" `
    -e ASPNETCORE_ENVIRONMENT=Development `
    -v "$($env:APPDATA)\microsoft\UserSecrets\:/root/.microsoft/UserSecrets" `
    -v "$($env:USERPROFILE)\.aspnet\https:/root/.aspnet/https" ttkds.web:v1

针对命令2的问题

  1. 路径与访问权限:Linux容器区分大小写,确保映射路径和证书文件名无拼写错误,同时确认Windows侧的aspnetapp.pfx文件确实存在于C:\Users\BVSim\.aspnet\https目录下。
  2. 端口配置修正:ASPNETCORE_URLS设置为https://localhost:7345会导致容器外无法访问,需改为https://*:7345,如需保留HTTP端口可写成https://*:7345;http://*:7245。
  3. 密码一致性检查:确认生成证书时的密码demoapp与环境变量中的密码完全一致,无空格或大小写差异。

修正后的命令2:

docker run --rm -p 7245:7245 -p 7345:7345 `
     -e ASPNETCORE_URLS="https://*:7345;http://*:7245" `
     -e ASPNETCORE_Kestrel__Certificates__Default__Password=demoapp `
     -e ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx `
     -v "C:\Users\BVSim\.aspnet\https:/https" ttkds.web:v1

额外建议:使用Docker Compose简化配置

提供基础docker-compose.yml配置,便于管理容器启动参数:

version: '3.8'

services:
  ttkds-api:
    image: ttkds.web:v1
    ports:
      - "7245:7245"
      - "7345:7345"
    environment:
      - ASPNETCORE_URLS=https://*:7345;http://*:7245
      - ASPNETCORE_ENVIRONMENT=Development
      - ASPNETCORE_Kestrel__Certificates__Default__Password=demoapp
      - ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx
    volumes:
      - ${USERPROFILE}\.aspnet\https:/https
      - ${APPDATA}\microsoft\UserSecrets:/root/.microsoft/UserSecrets

启动命令:

docker-compose up

内容的提问来源于stack exchange,提问作者Balaji V

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 21:44:52