You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Kubernetes集群中DotnetCore Linux容器调用外部API报SSL异常问题

Azure Kubernetes集群DotnetCore应用调用外部API SSL验证失败问题排查

环境信息

  • 集群资源:Azure Kubernetes Cluster
  • 业务运行容器:DotnetCore 2.2 Linux

问题现象

原先可正常调用外部合作方API端点的DotnetCore应用突发报错,异常信息如下:

ExceptionId: c6c603bb-91cc-4556-98bf-d747903f522a. Error Message: The SSL connection could not be established, see inner exception.. Error Details: System.Security.Authentication.AuthenticationException: The remote certificate is invalid according to the validation procedure.

排查测试结果

在集群的busybox Pod内执行如下curl命令测试,可复现错误:
curl --location --request GET 'external url' --header 'Authorization: token'
返回错误信息:

curl: (60) SSL certificate problem: certificate has expired
curl默认使用CA证书包执行SSL证书验证,若默认包不适用可通过--cacert参数指定替代文件。若HTTPS服务器使用的证书由证书包内的CA签发,验证失败大概率是证书本身问题(可能过期、或名称与URL域名不匹配)。如需关闭curl的证书验证,可使用-k(或--insecure)参数。

补充说明

  • 调用其他合作方API均正常,仅该特定合作方出现SSL验证问题
  • 本地环境执行相同curl请求可正常访问对应接口
  • 合作方官方反馈其SSL证书未过期

待排查方向

  • 外部合作方SSL证书实际已过期,但对方未同步正确信息
  • Kubernetes集群缓存了该合作方的失效SSL证书
  • Kubernetes集群根CA证书配置存在问题,需核实正确配置方案

内容的提问来源于stack exchange,提问作者naga bhushana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.01 07:09:03