You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE集群Ingress Controller SSL证书验证失败求助

GKE集群Nginx Ingress SSL证书信任问题解决

问题背景

在GKE集群中配置Nginx Ingress Controller的SSL证书,已创建对应的Ingress资源及名为ingress-cert的kubernetes.io/tls类型Secret,但执行curl -vvI https://www.ingress-tls.com请求时,返回SEC_ERROR_UNTRUSTED_ISSUER错误,提示证书发行方不被信任。

相关配置信息

Ingress配置

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: sample-app-ingress
spec:
  ingressClassName: nginx
  tls:
  - hosts:
    - www.ingress-tls.com
    secretName: ingress-cert
  rules:
  - host: "www.ingress-tls.com"
    http:
      paths:
        - pathType: Prefix
          path: "/"
          backend:
            service:
              name: sample-app-service
              port:
                number: 80

TLS Secret信息

NAME                      TYPE                DATA   AGE
ingress-cert              kubernetes.io/tls   2      10m
ingress-nginx-admission   Opaque              3      18m

curl错误输出

* About to connect() to www.ingress-tls.com port 443 (#0)
*   Trying 10.218.149.28...
* Connected to www.ingress-tls.com (10.218.149.28) port 443 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
*   CAfile: /etc/pki/tls/certs/ca-bundle.crt
  CApath: none
* Server certificate:
*       subject: E=some@gmail.com,CN=www.ingress-tls.com,OU=test,O=test,L=Cal,ST=CA,C=US
*       start date: Sep 06 14:08:46 2024 GMT
*       expire date: Jan 22 14:08:46 2052 GMT
*       common name: www.ingress-tls.com
*       issuer: E=some@gmail.com,CN=www.ingress-tls.com,OU=test,O=test,L=Cal,ST=CA,C=US
* NSS error -8172 (SEC_ERROR_UNTRUSTED_ISSUER)
* Peer's certificate issuer has been marked as not trusted by the user.
* Closing connection 0
curl: (60) Peer's certificate issuer has been marked as not trusted by the user.
More details here: http://curl.haxx.se/docs/sslcerts.html

curl performs SSL certificate verification by default, using a "bundle"
 of Certificate Authority (CA) public keys (CA certs). If the default
 bundle file isn't adequate, you can specify an alternate file
 using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
 the bundle, the certificate verification probably failed due to a
 problem with the certificate (it might be expired, or the name might
 not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
 the -k (or --insecure) option.

问题分析

从curl输出的证书信息可以看到,证书的签发者(issuer)和主体(subject)完全一致,说明这是一个自签名证书。自签名证书未被系统默认信任根CA集合收录,因此会触发SEC_ERROR_UNTRUSTED_ISSUER错误。

解决方法

1. 使用可信CA签发证书(生产环境首选)

  • 从Let's Encrypt等公共可信CA申请免费证书,或使用企业内部可信CA签发证书
  • 重新创建TLS Secret,注意要包含完整的证书链(fullchain文件,包含根CA和中间CA):
    kubectl create secret tls ingress-cert --cert=./fullchain.pem --key=./privkey.pem
    
  • 等待Ingress Controller重新加载配置后,再次验证请求即可

2. 将自签名CA添加到系统信任列表(测试环境适用)

如果是测试环境使用自签名证书,可将签发该证书的CA公钥添加到系统信任根目录:

  • RHEL/CentOS系统:
    sudo cp ca.crt /etc/pki/ca-trust/source/anchors/
    sudo update-ca-trust extract
    
  • Debian/Ubuntu系统:
    sudo cp ca.crt /usr/local/share/ca-certificates/
    sudo update-ca-certificates
    
  • 完成后重新执行curl请求,证书验证即可通过

3. 临时跳过证书验证(仅用于临时测试)

执行curl时添加-k参数强制跳过证书检查:

curl -vvIk https://www.ingress-tls.com

⚠️ 注意:此方法仅用于临时调试,生产环境绝对禁止使用,会带来严重安全风险

额外验证步骤

  • 检查Ingress资源是否正确关联Secret:
    kubectl describe ingress sample-app-ingress
    
    查看输出中TLS字段是否显示正确的host和secretName
  • 确认Nginx Ingress Controller Pod运行正常:
    kubectl get pods -n ingress-nginx
    
    确保所有Pod处于Running状态,无异常重启或日志报错

内容的提问来源于stack exchange,提问作者pythonhmmm

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 21:20:03