You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

连接Azure Kubernetes API服务器遇SSL/TLS错误,求证书获取路径

AKS API端点SSL/TLS信任问题解决指南

问题描述

我能成功访问AKS服务器,执行kubectl get nodes命令输出如下:

kubectl get nodes
NAME                                STATUS   ROLES   AGE   VERSION
aks-agentpool-27764677-vmss000000   Ready    agent   11m   v1.25.6
aks-userpool-27764677-vmss000000    Ready    agent   11m   v1.25.6

但通过curl访问AKS API端点时因SSL/TLS错误失败,报错信息如下:

curl https://di-poc-dns-89f8361f.hcp.centralus.azmk8s.io:443/
curl : The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.
At line:1 char:1
+ curl https://di-poc-dns-89f8361f.hcp.centralus.azmk8s.io:443/
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-WebRequest], WebException
    + FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeWebRequestCommand

受此连接问题影响,PowerShell中的大部分helm安装命令也失败了,示例报错如下:

helm upgrade --install appgw-ingress-internet -f helm-config-internet.yaml application-gateway-kubernetes-ingress/ingress-azure
Release "appgw-ingress-internet" does not exist. Installing it now.
E0626 12:25:44.907210   12260 memcache.go:238] couldn't get current server API group list: Get "https://dian-poc-dns-89f8361f.hcp.centralus.azmk8s.io:443/apis?timeout=32s": read tcp 192.168.19.32:64663->52.143.251.102:443: wsarecv: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.
Error: failed to install CRD crds/azureapplicationgatewayrewrite.yaml: unable to recognize "": Get "https://dian-poc-dns-89f8361f.hcp.centralus.azmk8s.io:443/apis?timeout=32s": read tcp 192.168.19.32:64663->52.143.251.102:443: wsarecv: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.

请问我应该从哪里下载证书并添加到Windows信任存储来解决该错误?

解决方案

1. 获取AKS API服务器CA证书

直接从本地kubeconfig文件提取,默认路径为%USERPROFILE%\.kube\config。打开文件后,找到对应AKS集群配置中的certificate-authority-data字段,该字段值是Base64编码的CA证书内容。

2. 解码并导出证书文件

使用PowerShell执行以下命令(替换占位符为实际的编码值):

$encodedCert = "你的certificate-authority-data字段值"
$decodedCert = [System.Convert]::FromBase64String($encodedCert)
[System.IO.File]::WriteAllBytes("C:\temp\aks-ca.crt", $decodedCert)

执行完成后,C:\temp\aks-ca.crt就是可导入的证书文件。

3. 添加到Windows信任存储

  • 右键点击aks-ca.crt文件,选择「安装证书」。
  • 在导入向导中选择「本地计算机」,点击「下一步」。
  • 选择「将所有证书放入下列存储」,点击「浏览」,选中「受信任的根证书颁发机构」,点击「确定」。
  • 完成剩余步骤,确认证书导入。

额外提示

注意到helm报错中的API端点域名(dian-poc-dns)与curl使用的域名(di-poc-dns)不一致,请同步检查kubeconfig中的集群API地址是否正确,避免因域名拼写错误导致的连接失败。

内容的提问来源于stack exchange,提问作者priyam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 19:37:58