Cmder SSL验证:如何将指定Zscaler根CA添加到本地信任存储?
vagrant up in Cmder Got it, let's tackle that SSL verification problem you're hitting when running vagrant up in Cmder with the Zscaler Root CA. Here's a step-by-step guide to get that certificate trusted properly:
1. Get the Zscaler Root CA Certificate File
First, you need a local copy of the Zscaler Root CA certificate (in .crt or .pem format):
- If you don't already have it, export it from your browser:
- Open Chrome/Firefox, visit any HTTPS site, click the lock icon in the address bar.
- Go to Certificate > Find the
Zscaler Root CAentry in the certificate chain. - Export it as a Base64-encoded X.509 (.crt) file, save it to a simple path like
C:\certs\zscaler-root.crt.
2. Install the Certificate to Windows System Trust Store
You need to add this certificate to your Windows trusted root store (run Cmder as Administrator for this):
Command Line Method
Run this in Cmder:
certutil -addstore -f "Root" C:\certs\zscaler-root.crt
-addstore Roottells Windows to add it to the system-wide trusted root authorities.-fforces overwrite if the certificate already exists (avoids duplicate errors).
Graphical Method (Alternative)
- Double-click the saved
.crtfile. - Click Install Certificate > Select Local Machine > Next.
- Choose Place all certificates in the following store > Click Browse.
- Select Trusted Root Certification Authorities > OK > Finish.
- Confirm the security prompt to complete the installation.
3. Configure Vagrant/OpenSSL to Use the Certificate
Vagrant relies on OpenSSL for SSL checks, so you need to point it to the trusted certificate:
Temporary Fix (Per Cmder Session)
Run these commands in Cmder before vagrant up:
set VAGRANT_CAFILE=C:\certs\zscaler-root.crt set SSL_CERT_FILE=C:\certs\zscaler-root.crt
Permanent Fix (All Cmder Sessions)
- Open Cmder's settings (press
Win + Alt + P). - Go to Startup > Environment.
- Add these two lines to the environment variables list:
VAGRANT_CAFILE=C:\certs\zscaler-root.crt SSL_CERT_FILE=C:\certs\zscaler-root.crt - Save settings and restart Cmder.
Project-Specific Fix (Vagrantfile)
If you want to apply this only to your Drupal VM project, add these lines at the top of your Vagrantfile:
ENV['VAGRANT_CAFILE'] = 'C:\certs\zscaler-root.crt' ENV['SSL_CERT_FILE'] = 'C:\certs\zscaler-root.crt'
4. Verify the Fix
Restart Cmder to ensure all environment changes take effect, then run:
vagrant up
The SSL verification error should no longer appear, and Vagrant should proceed to provision your Drupal VM.
Troubleshooting Tips
- Double-check the certificate path: if it has spaces, wrap it in quotes (e.g.,
"C:\My Certificates\zscaler-root.crt"). - Update Vagrant to the latest version if you're running an older release—some older versions have issues with custom CA certificates.
- Confirm the Zscaler certificate isn't expired (check the validity period in the certificate details).
内容的提问来源于stack exchange,提问作者Ramesh

