You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Podman拉取镜像报错x509: certificate signed by unknown authority求助

解决M1 Mac上Podman拉取镜像时的x509证书未知权威问题

直接上针对性解决方案,适配M1 Mac的Podman虚拟机环境:

  1. 进入Podman虚拟机的命令行:
    podman machine ssh
    
  2. 更新虚拟机的证书信任池:
    • 若Podman虚拟机为Alpine系统(早期版本默认):
      sudo apk add --no-cache ca-certificates
      sudo update-ca-certificates
      
    • 若为Fedora系统(当前Podman Machine默认):
      sudo dnf install -y ca-certificates
      sudo update-ca-trust extract
      
  3. 确认镜像仓库配置:
    在虚拟机内编辑/etc/containers/registries.conf,确保包含以下配置(缺失则添加):
    unqualified-search-registries = ["docker.io"]
    [[registry]]
    prefix = "docker.io"
    location = "registry-1.docker.io"
    
  4. 重启Podman虚拟机生效:
    podman machine restart
    

额外处理:使用代理的场景

如果本地有HTTP/HTTPS代理,需将代理CA证书导入虚拟机信任池:

  1. 把代理CA证书(如proxy-ca.crt)传到虚拟机:
    podman machine scp /本地路径/proxy-ca.crt localhost:/tmp/
    
  2. 进入虚拟机完成证书配置:
    podman machine ssh
    sudo cp /tmp/proxy-ca.crt /usr/local/share/ca-certificates/
    # Alpine系统执行:sudo update-ca-certificates
    # Fedora系统执行:sudo update-ca-trust extract
    
  3. 重启Podman虚拟机。

验证:执行podman pull nginx:latest,无需添加--tls-verify=false即可正常拉取镜像。

内容的提问来源于stack exchange,提问作者stephen newman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 07:05:24