You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker Desktop Linux容器配置自签名HTTPS证书失败求助

Windows下Linux容器配置ASP.NET Core HTTPS自签名证书失败解决方法

问题场景

在Windows环境使用Linux容器部署ASP.NET Core应用,配置SSL自签名证书时始终失败,报错信息:

Hosting failed to start
System.InvalidOperationException: Unable to configure HTTPS endpoint. No server certificate was specified, and the default developer certificate could not be found or is out of date.
To generate a developer certificate run 'dotnet dev-certs https'. To trust the certificate (Windows and macOS only) run 'dotnet dev-certs https --trust'.
For more information on configuring HTTPS see https://go.microsoft.com/fwlink/?linkid=848054.
at Microsoft.AspNetCore.Hosting.ListenOptionsHttpsExtensions.UseHttps(ListenOptions listenOptions, Action`1 configureOptions)
....

已执行的证书创建及容器启动命令:

dotnet dev-certs https -ep $env:USERPROFILE\.aspnet\https\WeatherApi.pfx -p password

dotnet dev-certs https --trust

dotnet user-secrets -p WeatherApi.csproj set "Kestrel:Certificates:Development:Password" "password"

docker run --rm -it -p 8001:8001 -e ASPNETCORE_HTTPS_PORTS=8001 -e ASPNETCORE_ENVIRONMENT=Development -v $env:APPDATA\microsoft\UserSecrets\:/root/.microsoft/usersecrets -v $env:USERPROFILE\.aspnet\https:/root/.aspnet/https/ weatherapi

使用的Dockerfile:

#See https://aka.ms/customizecontainer to learn how to customize your debug container and how Visual Studio uses this Dockerfile to build your images for faster debugging.

FROM mcr.microsoft.com/dotnet/aspnet:8.0 AS base
USER app
WORKDIR /app
EXPOSE 8080
EXPOSE 8081

FROM mcr.microsoft.com/dotnet/sdk:8.0 AS build
ARG BUILD_CONFIGURATION=Release
WORKDIR /src
COPY ["AV.Identity.A/AV.Identity.A.csproj", "AV.Identity.A/"]
COPY ["AV.Identity.B/AV.Identity.B.csproj", "AV.Identity.B/"]
COPY ["AV.Identity.D/AV.Identity.D.csproj", "AV.Identity.D/"]
COPY ["AV.Identity.C/AV.Identity.C.csproj", "AV.Identity.C/"]
RUN dotnet restore "./AV.Identity.A/./AV.Identity.A.csproj"
COPY . .
WORKDIR "/src/AV.Identity.A"
RUN dotnet build "./AV.Identity.A.csproj" -c $BUILD_CONFIGURATION -o /app/build

FROM build AS publish
ARG BUILD_CONFIGURATION=Release
RUN dotnet publish "./AV.Identity.A.csproj" -c $BUILD_CONFIGURATION -o /app/publish /p:UseAppHost=false

FROM base AS final
WORKDIR /app
COPY --from=publish /app/publish .
ENTRYPOINT ["dotnet", "AV.Identity.A.dll"]

排查与修复步骤

1. 修正证书文件名匹配

Linux容器中Kestrel默认寻找与项目DLL文件名一致的PFX证书。你的项目DLL是AV.Identity.A.dll,但生成的证书是WeatherApi.pfx,文件名不匹配导致容器无法识别。重新生成匹配证书:

dotnet dev-certs https -ep $env:USERPROFILE\.aspnet\https\AV.Identity.A.pfx -p password

2. 调整用户机密配置路径

之前的命令使用了错误的项目文件(WeatherApi.csproj),需替换为实际项目文件:

dotnet user-secrets -p AV.Identity.A.csproj set "Kestrel:Certificates:Development:Password" "password"

3. 统一容器端口映射

Dockerfile暴露的HTTPS端口是8081,但启动命令映射的是8001,需保持端口一致:

docker run --rm -it -p 8080:8080 -p 8081:8081 -e ASPNETCORE_HTTPS_PORTS=8081 -e ASPNETCORE_ENVIRONMENT=Development -v $env:APPDATA\microsoft\UserSecrets\:/root/.microsoft/usersecrets -v $env:USERPROFILE\.aspnet\https:/root/.aspnet/https/ weatherapi

4. 配置容器证书权限

Linux容器中app用户需要证书文件读取权限,在Dockerfile的base阶段添加权限设置:

FROM mcr.microsoft.com/dotnet/aspnet:8.0 AS base
USER root
RUN mkdir -p /root/.aspnet/https && chown -R app:app /root/.aspnet/https
USER app
WORKDIR /app
EXPOSE 8080
EXPOSE 8081

5. 验证用户机密挂载有效性

确认Windows下$env:APPDATA\microsoft\UserSecrets路径下存在对应项目的机密文件夹(以项目UserSecretsId命名),可通过以下命令查看UserSecretsId:

dotnet user-secrets -p AV.Identity.A.csproj list

若文件夹不存在,重新执行用户机密设置命令即可生成。

内容的提问来源于stack exchange,提问作者Abhishek Vyas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 00:16:00