You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows10主机Docker容器内.NET CLI的SSL证书信任问题

解决Docker容器内NuGet SSL证书信任问题及dotnet工具安装失败

问题根源

从Docker信息可知,当前Docker配置了HTTP/HTTPS代理(http.docker.internal:3128),容器内无法验证NuGet服务器的SSL证书,导致无法访问NuGet源,进而安装dotnet工具失败。

解决方案

1. 关闭不必要的Docker代理(优先尝试)

  • 打开Docker Desktop,进入Settings > Resources > Proxies
  • 选择No proxy选项,点击Apply & Restart重启Docker
  • 重新启动容器,执行dotnet tool install --global dotnet-sonarscanner验证

2. 导入代理CA证书到容器(必须使用代理时)

如果必须通过代理访问网络,需要将代理的CA证书导入容器的信任证书库:

方式一:通过Dockerfile构建镜像时导入

FROM mcr.microsoft.com/dotnet/sdk:6.0

# 将代理CA证书复制到容器证书目录
COPY proxy-ca.crt /usr/local/share/ca-certificates/proxy-ca.crt

# 更新系统信任证书
RUN update-ca-certificates

# 安装dotnet-sonarscanner工具
RUN dotnet tool install --global dotnet-sonarscanner

方式二:在运行中的容器内临时导入

  1. 将本地代理CA证书复制到容器内:
    docker cp proxy-ca.crt <容器ID>:/usr/local/share/ca-certificates/
    
  2. 进入容器终端:
    docker exec -it <容器ID> bash
    
  3. 更新证书存储:
    update-ca-certificates
    
  4. 重新执行工具安装命令:
    dotnet tool install --global dotnet-sonarscanner
    

3. 同步WSL2与Windows的CA证书

由于Docker Desktop运行在WSL2环境,可同步Windows的信任证书到WSL2:

  1. 打开WSL2终端(如Ubuntu)
  2. 执行以下命令同步证书并更新:
    sudo cp /mnt/c/Windows/System32/certificates/authroot/* /usr/local/share/ca-certificates/
    sudo update-ca-certificates
    
  3. 重启Docker Desktop,让容器使用更新后的证书环境

4. 临时绕过SSL验证(仅测试用,不推荐生产环境)

如果只是临时测试,可通过以下方式跳过证书验证:

  • 直接在安装命令中添加参数:
    dotnet tool install --global dotnet-sonarscanner --ignore-failed-sources
    
  • 或修改NuGet配置文件,添加忽略证书验证的设置:
    在容器内创建~/.nuget/NuGet/NuGet.Config,写入以下内容:
    <?xml version="1.0" encoding="utf-8"?>
    <configuration>
      <packageSources>
        <add key="nuget.org" value="https://api.nuget.org/v3/index.json" protocolVersion="3" />
      </packageSources>
      <config>
        <add key="http_proxy" value="http://http.docker.internal:3128" />
        <add key="https_proxy" value="http://http.docker.internal:3128" />
      </config>
      <settings>
        <add key="signatureValidationMode" value="accept" />
      </settings>
    </configuration>
    
    保存后重新执行安装命令。

内容的提问来源于stack exchange,提问作者Mukul Garg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 17:12:22