You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Docker容器内更新Let's Encrypt根CA证书 解决SSL过期报错

解决Debian 9 Docker容器内Let's Encrypt根证书过期问题

问题根因

Debian 9(Stretch)早已停止官方维护,默认源内的ca-certificates包未更新2021年9月后的Let's Encrypt根证书规则,仍默认信任已过期的DST Root CA X3根证书,且未优先启用新的ISRG Root X1根证书,所以仅执行update-ca-certificates --fresh无法生效。

永久修复方案(写入镜像即可避免每次重构)

  • 第一步:替换Debian 9归档源,获取最新的可用包更新
    执行以下命令替换软件源配置:
    cat > /etc/apt/sources.list << EOF
    deb http://archive.debian.org/debian stretch main contrib non-free
    deb http://archive.debian.org/debian-security stretch/updates main contrib non-free
    EOF
    
    执行更新命令忽略源过期警告:
    apt update -o Acquire::Check-Valid-Until=false
  • 第二步:升级证书管理包
    apt install -y ca-certificates
  • 第三步:禁用已过期的DST Root CA X3根证书信任
    sed -i 's/^mozilla\/DST_Root_CA_X3.crt/!mozilla\/DST_Root_CA_X3.crt/g' /etc/ca-certificates.conf
  • 第四步:重新生成根证书缓存
    update-ca-certificates --fresh

修复完成后可执行curl https://letsencrypt.org验证,不再抛出证书过期错误即为生效。

临时应急方案

如果无需修改镜像,启动容器时直接挂载宿主Ubuntu 20的正常证书目录即可:
docker run -v /etc/ssl/certs:/etc/ssl/certs:ro <你的镜像名称>

内容的提问来源于stack exchange,提问作者os11k

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.01 18:06:02