GKE集群Ingress Controller SSL证书验证失败求助
GKE集群Nginx Ingress SSL证书信任问题解决
问题背景
在GKE集群中配置Nginx Ingress Controller的SSL证书,已创建对应的Ingress资源及名为ingress-cert的kubernetes.io/tls类型Secret,但执行curl -vvI https://www.ingress-tls.com请求时,返回SEC_ERROR_UNTRUSTED_ISSUER错误,提示证书发行方不被信任。
相关配置信息
Ingress配置
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: sample-app-ingress spec: ingressClassName: nginx tls: - hosts: - www.ingress-tls.com secretName: ingress-cert rules: - host: "www.ingress-tls.com" http: paths: - pathType: Prefix path: "/" backend: service: name: sample-app-service port: number: 80
TLS Secret信息
NAME TYPE DATA AGE ingress-cert kubernetes.io/tls 2 10m ingress-nginx-admission Opaque 3 18m
curl错误输出
* About to connect() to www.ingress-tls.com port 443 (#0) * Trying 10.218.149.28... * Connected to www.ingress-tls.com (10.218.149.28) port 443 (#0) * Initializing NSS with certpath: sql:/etc/pki/nssdb * CAfile: /etc/pki/tls/certs/ca-bundle.crt CApath: none * Server certificate: * subject: E=some@gmail.com,CN=www.ingress-tls.com,OU=test,O=test,L=Cal,ST=CA,C=US * start date: Sep 06 14:08:46 2024 GMT * expire date: Jan 22 14:08:46 2052 GMT * common name: www.ingress-tls.com * issuer: E=some@gmail.com,CN=www.ingress-tls.com,OU=test,O=test,L=Cal,ST=CA,C=US * NSS error -8172 (SEC_ERROR_UNTRUSTED_ISSUER) * Peer's certificate issuer has been marked as not trusted by the user. * Closing connection 0 curl: (60) Peer's certificate issuer has been marked as not trusted by the user. More details here: http://curl.haxx.se/docs/sslcerts.html curl performs SSL certificate verification by default, using a "bundle" of Certificate Authority (CA) public keys (CA certs). If the default bundle file isn't adequate, you can specify an alternate file using the --cacert option. If this HTTPS server uses a certificate signed by a CA represented in the bundle, the certificate verification probably failed due to a problem with the certificate (it might be expired, or the name might not match the domain name in the URL). If you'd like to turn off curl's verification of the certificate, use the -k (or --insecure) option.
问题分析
从curl输出的证书信息可以看到,证书的签发者(issuer)和主体(subject)完全一致,说明这是一个自签名证书。自签名证书未被系统默认信任根CA集合收录,因此会触发SEC_ERROR_UNTRUSTED_ISSUER错误。
解决方法
1. 使用可信CA签发证书(生产环境首选)
- 从Let's Encrypt等公共可信CA申请免费证书,或使用企业内部可信CA签发证书
- 重新创建TLS Secret,注意要包含完整的证书链(fullchain文件,包含根CA和中间CA):
kubectl create secret tls ingress-cert --cert=./fullchain.pem --key=./privkey.pem - 等待Ingress Controller重新加载配置后,再次验证请求即可
2. 将自签名CA添加到系统信任列表(测试环境适用)
如果是测试环境使用自签名证书,可将签发该证书的CA公钥添加到系统信任根目录:
- RHEL/CentOS系统:
sudo cp ca.crt /etc/pki/ca-trust/source/anchors/ sudo update-ca-trust extract - Debian/Ubuntu系统:
sudo cp ca.crt /usr/local/share/ca-certificates/ sudo update-ca-certificates - 完成后重新执行curl请求,证书验证即可通过
3. 临时跳过证书验证(仅用于临时测试)
执行curl时添加-k参数强制跳过证书检查:
curl -vvIk https://www.ingress-tls.com
⚠️ 注意:此方法仅用于临时调试,生产环境绝对禁止使用,会带来严重安全风险
额外验证步骤
- 检查Ingress资源是否正确关联Secret:
查看输出中kubectl describe ingress sample-app-ingressTLS字段是否显示正确的host和secretName - 确认Nginx Ingress Controller Pod运行正常:
确保所有Pod处于kubectl get pods -n ingress-nginxRunning状态,无异常重启或日志报错
内容的提问来源于stack exchange,提问作者pythonhmmm
相关产品推荐
相关产品推荐

