在Postman中配置证书以连接Go服务器时遇SSL证书验证错误的求助
Hey there, let's work through this SSL issue step by step—no need to turn off validation to make it work. That error usually points to a problem with the server's certificate chain or Postman not trusting your server's cert. Here are the most likely fixes:
1. Ensure your Go server serves a complete certificate chain
Go's RunTLS function requires the certificate file you pass to include the full chain: your server certificate (server.crt) plus any intermediate CA certificates that connect it to a trusted root. If your server.crt only contains the server's leaf cert (like a self-signed cert, or one from a CA that didn't provide the intermediate chain), you'll need to combine them:
# If you have an intermediate CA cert, merge it with your server cert (server cert first!) cat server.crt intermediate.crt > full_chain.crt
Then update your Go code to use this combined file:
err = r.RunTLS(":8080", "/users/myuser/full_chain.crt", "/users/myuser/server.key")
If you're using a self-signed cert, the server.crt itself is the root, so you can skip merging—just double-check it's properly formatted as PEM.
2. Trust your server's root CA in Postman
If your server uses a self-signed cert or one from a CA Postman doesn't trust by default, Postman will reject the server's identity. To fix this, import the root CA cert (or your self-signed server.crt) into Postman's trusted list:
- Open Postman, click the gear icon in the top right to open Settings
- Go to the Certificates tab on the left
- Scroll down to CA Certificates, then click Add Certificate
- Enter the host (just
localhost, no port number) and select your root CA cert file (orserver.crtif it's self-signed) - Save the settings, restart Postman, and try your request again
3. Double-check your client certificate setup (if using mutual TLS)
While the error is about verifying the server's cert, it's worth confirming your client cert is set up correctly if your server requires mutual TLS:
- Make sure
client.crtandclient.keyare valid PEM-formatted files - Confirm the client cert was issued by a CA that your Go server trusts (if your server is configured to validate client certs)
- In Postman, ensure you've entered the correct paths and password for the client cert—sometimes typos here can cause unexpected SSL issues
4. Verify your server cert matches the hostname
Check that your server certificate's Common Name (CN) or Subject Alternative Name (SAN) includes localhost (since that's the host you're accessing). If the cert is issued for a different domain, Postman will fail verification. You can inspect the cert with this command:
openssl x509 -in server.crt -text -noout | grep -A 1 -B 1 "CN\|Subject Alternative Name"
Give these steps a try—one of them should resolve the SSL verification error without disabling it.
内容的提问来源于stack exchange,提问作者Sergei Mikhailovskii

