Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

access private registry: x509: certificate signed by unknown authority #8849

hustcat opened this issue Oct 30, 2014 · 41 comments

access private registry: x509: certificate signed by unknown authority #8849

hustcat opened this issue Oct 30, 2014 · 41 comments


Copy link

hustcat commented Oct 30, 2014

I setup docker-registry with nginx by following here.

I run 'docker login', get this error:

# docker login -u docker -p docker -e
2014/10/30 11:12:08 Error response from daemon: Server Error: Post x509: certificate signed by unknown authority

docker daemon's output:

[debug] server.go:1181 Calling POST /auth
[info] POST /v1.15/auth
[47687bb1] +job auth()
[debug] endpoint.go:109 Error unmarshalling the _ping RegistryInfo: json: cannot unmarshal bool into Go value of type registry.RegistryInfo
[debug] endpoint.go:113 Registry version header: '0.7.1'
[debug] endpoint.go:116 RegistryInfo.Version: "0.7.1"
[debug] endpoint.go:119 Registry standalone header: 'True'
[debug] endpoint.go:127 RegistryInfo.Standalone: true
[debug] endpoint.go:109 Error unmarshalling the _ping RegistryInfo: json: cannot unmarshal bool into Go value of type registry.RegistryInfo
[debug] endpoint.go:113 Registry version header: '0.7.1'
[debug] endpoint.go:116 RegistryInfo.Version: "0.7.1"
[debug] endpoint.go:119 Registry standalone header: 'True'
[debug] endpoint.go:127 RegistryInfo.Standalone: true
Server Error: Post x509: certificate signed by unknown authority
[47687bb1] -job auth() = ERR (1)
[error] server.go:1207 Handler for POST /auth returned error: Server Error: Post x509: certificate signed by unknown authority
[error] server.go:110 HTTP Error: statusCode=500 Server Error: Post x509: certificate signed by unknown authority

I checked the code. I think function Login may be need 'tlsConfig'

just like

# docker --version
Docker version 1.3.0, build c78088f
# curl --cacert ca.pem                 
# curl --cacert ca.pem -u docker:docker

# curl -u docker:docker                
curl: (60) Peer certificate cannot be authenticated with known CA certificates
More details here:

curl performs SSL certificate verification by default, using a "bundle"
 of Certificate Authority (CA) public keys (CA certs). If the default
 bundle file isn't adequate, you can specify an alternate file
 using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
 the bundle, the certificate verification probably failed due to a
 problem with the certificate (it might be expired, or the name might
 not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
 the -k (or --insecure) option.
Copy link

@hustcat As of Docker 1.3.1, you can do --insecure-registry you can replace 5000 with whichever port your registry is listening on.

I'm closing this now, but let us know in the comments if this did not solve your issue.

Copy link

behemphi commented Nov 4, 2014

I am leaving this here b/c it took me a few minutes to figure it out, and might save someone the time. The command would be:

%> docker login

Thanks for getting the switch put in place for 1.3!

Copy link

I am facing the same problem. The certificate validation works for the ping (and pushing/pulling), but not login.

The --insecure-registry flag is a workaround, not a fix. The certificate validation should work if the CA certificate is loaded into /etc/docker/certs.d/<registry>, but it doesn't.

Copy link

cdub50 commented Jan 19, 2015

I cant event get it to work by setting --insecure-registry I am on docker 1.3.2 on RedHat 7

[root@ip-10-2-20-209 ec2-user]# docker --insecure-registry=qa.docker.repo login https://qa.docker.repo
Username: qa
2015/01/19 14:26:40 Error response from daemon: Server Error: Post https://qa.docker.repo/v1/users/: x509: certificate signed by unknown authority

curl works fine when I use the generated ca.pem file.

curl --cacert /home/ec2-user/ca.pem -u qa:xxxxx https://qa.docker.repo/v1/users/

Copy link

I'm having the same issue on docker version 1.3.2 and opensuse 13.1. I even tried to statically pass --cafile cacert.pem to every curl call (since I assumed docker internally just uses curl), however, this also did not help.

Any help would be much appreciated.


Copy link

ghost commented Jan 19, 2015

Before I found this issue, I opened #10150. They appear to be the same issue.

Copy link

I seem to be having the same issue. Archlinux client 1.4.1 and the registry running from the official docker container. Anyone have any thoughts?

Copy link

grimmy commented Jan 20, 2015

If you've installed the cert globally (via ca-certificates) make sure you restart docker as it won't reload the global ssl certs. That said, mine still isn't working, but I ran into that at work :)

Copy link

Thank you grimmy, that did the trick on my end and it finally works. I did:

  1. Get cacert.pem from
  2. Copy the cacert.pem file to /etc/pki/trust/anchors/
  3. sudo update-ca-certificates
  4. sudo systemctl docker stop
  5. sudo systemctl docker start


Copy link

Thank you, that also worked for me. Equivalent steps on Ubuntu/Debian:

  1. Copy CA cert to /usr/local/share/ca-certificates.
  2. sudo update-ca-certificates
  3. sudo service docker restart

There is still a bug here, though. The docs say to install the CA cert in /etc/docker/certs.d/<registry>, and clearly that isn't sufficient. In fact, after installing the certificate globally, I removed the one in /etc/docker/certs.d, restarted Docker, and it still worked.

Copy link

GaretJax commented Jul 8, 2015

+1 for reopening this, as @rhasselbaum mentioned

Copy link

cjw296 commented Sep 16, 2015

Has --insecure-registry gone away?

$ docker --version
Docker version 1.8.2, build 0a8c2e3

$ docker --insecure-registry
flag provided but not defined: --insecure-registry
See 'docker --help'.

What should we use now?

Copy link

cdub50 commented Sep 16, 2015

that goes in the docker config file you can check if its set by looking at
the docker process you should see the --insecure-registry flag

On Wed, Sep 16, 2015 at 3:01 AM, Chris Withers

Has --insecure-registry gone away?

$ docker --version
Docker version 1.8.2, build 0a8c2e3

$ docker --insecure-registry
flag provided but not defined: --insecure-registry
See 'docker --help'.

What should we use now?

Reply to this email directly or view it on GitHub
#8849 (comment).

Copy link

I got the same error for docker pull command and I think the following should work.
Copy the SSL certificate which is the '.crt' file to the directory

sudo cp foo.crt /usr/share/ca-certificates/extra/foo.crt
Let Ubuntu add the '.crt' file's path relative to /usr/share/ca-certificates to /etc/ca-certificates.conf

sudo dpkg-reconfigure ca-certificates

Copy link

if your machine state is not important, so you can run docker-machine rm <machine-name> and create another one ;)

Copy link

If you use LetsEncrypt and you don't want to run anything without proper TLS, make sure to provide the full chain of the certificate including intermediates (ie REGISTRY_HTTP_TLS_CERTIFICATE=.../fullchain.pem) you may see green in Chrome while still getting this error from Docker.


Copy link

JazzDeben commented Sep 16, 2016

On Ubuntu. If you experience error:

  • x509: cannot validate certificate for [IP address or domain name] because it doesn't contain any IP SANs

On the Docker registry the certificate had to be compiled with the subjectAltName as described here:

Here is the code for convenience:
$ echo subjectAltName = IP:,IP: > extfile.cnf
$ openssl x509 -req -days 365 -sha256 -in server.csr -CA ca.pem -CAkey ca-key.pem
-CAcreateserial -out server-cert.pem -extfile extfile.cnf

Note, I was able to check the subject alternative name is present in the certificate using the following command:
openssl x509 -in certificate.crt -text -noout

However, on Ubuntu 14 client (i.e. Docker Engine)
This error was followed suit by
x509: certificate signed by unknown authority

For people using Ubuntu 14.
The config file that is used for the Docker engine (that I want to use to connect to the Docker Registry):

in there, you need to specify the docker options:

Then restart the daemon (add sudo if you user is not allowed to start a docker service):
$ [sudo] service docker restart

The value does not need to be a domain name, it simply has to match what you certificate is registered with; I have an IP address with a port and this works... (i.e. e.g.

All this took me a day, so, I am posting this hoping that it will be useful to other people...

Copy link

sallespro commented Oct 4, 2016

@JazzDeben Thanks for your remarks ! very useful ! i am not sure how to do it with a Let's Encript certbot generated certificate.
i get this error in the registry server

tls: client didn't provide a certificate

Chrome complains about ERR_BAD_SSL_CLIENT_AUTH_CERT
if i include

      - /path/to/ca.pem

Copy link

david-drinn commented Oct 6, 2016

@cjw296 For RHEL7.2, I edited the file, /usr/lib/systemd/docker.service, and in the ExecStart line added the

< ExecStart=/usr/bin/dockerd
> ExecStart=/usr/bin/dockerd

Then I ran sudo systemctl daemon-reload to pick up the configuration change, followed by sudo systemctl restart docker. And now it works.

To be honest, I'm still a systemd noob and there are probably better ways to do this more cleanly. But I struggled with this for too long, and wanted to post a workaround. Thanks to @cdub50 for leading me in the right direction.

Copy link

dovecode commented May 5, 2017

@david-drinn For Fedora 25, I did something similar, but since the docker daemon config (in /usr/lib/systemd/system/docker.service) sources setup from configuration files, I made the change in /etc/sysconfig/docker:

< # INSECURE_REGISTRY='--insecure-registry='

Copy link

FCA69 commented May 19, 2017

If curl is working and docker not, you can:
o create the "/etc/docker/certs.d//..." directory & files (valid for private registries only ?)
o add a "tlscert" entry in your "/etc/docker/daemon.json" file, so that dockerd uses the same certificates as curl does.

Copy link

To those that run into this issue and you have self signed certificates and you do not want to use the "insecure-registry" directive then you need to load your self signed certificates into /etc/docker/certs.d/{host}/. After loading them in remember to RESTART docker daemon. To elaborate some more.....

If your registry is hosted at you should have a directory called /etc/docker/certs.d/ with your self-signed certs inside. Now you will be able to do docker login with no x509 error.
Now here is a caveat to all this, lets say you want to for some reason explicitly define the port in your login command like this docker login would make no sense, but this is just an example) then you need to ensure that your self signed certificates are inside a folder called /etc/docker/certs.d/ Docker makes no assumptions about certs resolving based on hostname only when using a port. You have to actually provide certs on a per port basis by loading your self signed certs into a folder name that includes the port you are trying to access.

Hopefully this saves many of you guys a lot of debugging who are using ports to connect to your docker registry.

Copy link

abdasgupta commented Jul 18, 2017

This is not resolved in my case:
I want to use a self-signed certificate for nexus OSS repository. But I am getting this error: Error response from daemon: Get https://<>:10250/v1/users/: x509: certificate signed by unknown authority

I have placed the .crt file in /etc/docker/certs.d as well as /usr/share/ca-certificates on my ubuntu 16.04 om intel machine. I ran then update-ca-certificates and restarted docker. this is my cert file nexus.cert:
$ openssl x509 -in nexus.crt -text

        Version: 1 (0x0)
        Serial Number: 1 (0x1)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=IN, ST=State, L=City, O=XYZ, OU=x, CN=<>
            Not Before: Jul 17 20:28:26 2017 GMT
            Not After : Jul 17 20:28:26 2018 GMT
        Subject: C=IN, ST=State, L=City, O=XYZ, OU=x, CN=<>
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (4096 bit)
                Exponent: 65537 (0x10001)
    Signature Algorithm: sha256WithRSAEncryption

Copy link

FCA69 commented Jul 18, 2017

@abdasgupta : can you "curl" your repo ?
If so, check which certificates' file curl is using, and edit your daemon.json file in order to use that same file.
In my case, it was :
[root@localhost ]# cat /etc/docker/daemon.json
{ "insecure-registries":[""],
"tlscert": "/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem" <<<<======

Copy link

I didn't wanted to use that insecure-registries.. is it not possible to run without it?? moreover, certificate is same as repo's.. cz I copied from there.

Copy link

FCA69 commented Jul 20, 2017 via email

Copy link

@abdasgupta, I've noticed that 17.03.1~ce-0~ubuntu-xenialversion doesn't work, but the 17.06.0~ce-0~ubuntu version works.

I place a crt into /usr/local/share/ca-certificates/my-org/my-domain.crt, then do sudo update-ca-certificates and sudo systemctl restart docker.

Copy link

Can you try following the instructions in ? Docker 1.13 and up should also read certificates from the system defaults, otherwise;

A custom certificate is configured by creating a directory under /etc/docker/certs.d using the same name as the registry’s hostname (e.g., localhost). All *.crt files are added to this directory as CA roots.

After configuring the certificates, it may be needed to restart the daemon

Copy link

For anyone who struggles with /etc/docker/certs.d solution, make sure your directory name under there includes the registry port. So /etc/docker/certs.d/

Worked fine for me on Photon OS.

Copy link

heronrs commented Dec 9, 2017

I was struggling with this error until I figured I was naming the file /etc/docker/certs.d/myregistry/ca.pem instead of /etc/docker/certs.d/myregistry/ca.crt

Copy link

I was having the same problem on Windows, until I looked at the docs, which suggests using my certificate authority in Windows Explorer (ca.pem renamed as ca.crt) and Right-Click > Install Certificate and select Trusted Root Certificate Authorities for the current user. Restarted docker and it worked.

Copy link

visualex commented Feb 27, 2018

in coreos, I had to edit
{ "insecure-registries": ["registry:8443"] }
then sudo systemctl restart docker

Copy link

Hint: If you reach your private repo through a proxy you can experience same error message, disable proxy or configure an exception (NO_PROXY perhaps) for the private registry host.

Copy link

mhermosi commented Feb 20, 2019

I am running docker-registry as a Kubernetes POD on Rancher. I have configured a L7 Ingress and the SSL certificate is located there. when I access from Web browser I have no problem SSL fine, and login credentials works fine. but if I run docker login command I get the x509: certificate signed by unknown authority, which I believe is trying to get the default ingress backend with the fake SSL Self-signed certificate. I am restarting docker on my computer to see if that helps.

It used to work.... I made a small change on my ingress to support a new SSL cert for two hostname
after restarting docker on my laptop still same issue :(

pranav-patil referenced this issue in pranav-patil/spring-kubernetes-microservices Aug 22, 2019
Copy link

Hi Bro.. This issue same as with my problem.
Openshift cannot import-image for nexus repository, the sintax is
oc import-image nexus-coba:3.5 --from= --confirm
error: tag latest failed: Internal error occurred: Get x509: certificate signed by unknown authority imported with errors
This Solution only add --insecure after --confirm.

oc import-image nexus-coba:3.5 --from= --confirm --insecure

Copy link

Thank you, that also worked for me. Equivalent steps on Ubuntu/Debian:

1. Copy CA cert to `/usr/local/share/ca-certificates`.

2. sudo update-ca-certificates

3. sudo service docker restart

There is still a bug here, though. The docs say to install the CA cert in /etc/docker/certs.d/<registry>, and clearly that isn't sufficient. In fact, after installing the certificate globally, I removed the one in /etc/docker/certs.d, restarted Docker, and it still worked.

Such a big thank you ! I was doing exactly what you were describing, pulling my hair from the official documentation being wrong... :)

Copy link

jbsky commented Feb 11, 2020

I don't believe it! 5 years later, still true, thanks for the solution.

Thank you, that also worked for me. Equivalent steps on Ubuntu/Debian:

1. Copy CA cert to `/usr/local/share/ca-certificates`.

2. sudo update-ca-certificates

3. sudo service docker restart

There is still a bug here, though. The docs say to install the CA cert in /etc/docker/certs.d/<registry>, and clearly that isn't sufficient. In fact, after installing the certificate globally, I removed the one in /etc/docker/certs.d, restarted Docker, and it still worked.

Copy link

Is it means that I must install certificate in the registry docker image also in the nginx?

Copy link

Docker-Desktop Icon -> Preferences -> Daemon -> "Insecure registries", click + icon
Add your repo ""
click “Apply & Restart”


Refer for more info.

Copy link

On macOS 10.15 and docker version 20.10.5 the issue is still present. I attempted everything that I could find both here and elsewhere to no avail.

Copy link

ok thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
None yet
None yet

No branches or pull requests