# Adding local catalog fails?

**URL:** <https://forums.suse.com/t/adding-local-catalog-fails/2144>\
**Category:** Rancher 1.x\
**Created:** [March 24, 2016, 7:23am UTC](https://forums.suse.com/t/adding-local-catalog-fails/2144 "2016-03-24T07:23:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![gflwqs](https://avatars.discourse-cdn.com/v4/letter/g/6a8cbe/32.png) [@gflwqs](https://forums.suse.com/u/gflwqs)\
**Post date:** [March 24, 2016, 7:23am UTC](https://forums.suse.com/t/adding-local-catalog-fails/2144/1 "2016-03-24T07:23:35Z")

</div>

Hi,  
I am trying to add a local catalog.  
But i get this error in the server container log:  
fatal: unable to access ‘https:///lab/rancher-compose.git/’: server certificate verification failed. CAfile: /etc/ssl/certs/ca-certificates.crt CRLfile: none  
time=“2016-03-24T07:20:12Z” level=error msg=“Failed to clone the catalog from git err: exit status 128”

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [March 31, 2016, 9:27pm UTC](https://forums.suse.com/t/adding-local-catalog-fails/2144/2 "2016-03-31T21:27:12Z")

</div>

What version of Rancher are you running?

From the [docs](http://docs.rancher.com/rancher/catalog/):

Adding a catalog is as simple as adding a catalog name and a URL. The URL needs to one that git clone [can handle](https://git-scm.com/docs/git-clone#_git_urls_a_id_urls_a). Whenever you add a catalog entry, it will be immediately available in your catalog.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [March 31, 2016, 10:08pm UTC](https://forums.suse.com/t/adding-local-catalog-fails/2144/3 "2016-03-31T22:08:23Z")

</div>

`git clone` fails if it can’t verify the certificate and your server has a self-signed cert (or you’re not asking for the right domain name, because you can’t get a real cert for `lab`). If that server is available without SSL you can use `http://lab/rancher-compose.git/`, otherwise you need to add the certificate to the trusted list in the container with something like this (the docs are for registries, but same concept): [http://docs.rancher.com/rancher/configuration/registries/#self-signed-certificates](http://docs.rancher.com/rancher/configuration/registries/#self-signed-certificates)

---

<div class="post-metadata">

**Author:** ![gflwqs](https://avatars.discourse-cdn.com/v4/letter/g/6a8cbe/32.png) [@gflwqs](https://forums.suse.com/u/gflwqs)\
**Post date:** [April 1, 2016, 9:41am UTC](https://forums.suse.com/t/adding-local-catalog-fails/2144/4 "2016-04-01T09:41:57Z")

</div>

Hi denise,

We are using 1.0.0 now but i had the same problem with 0.63.1.

We have our own CA which the git repository (bitbucket) have a certficate created from so it is not self signed but it is not an official CA.

I have added the PEM formatted CA chain to /etc/ssl/certs/ca-certificates.crt according to [http://docs.rancher.com/rancher/configuration/registries/#self-signed-certificates](http://docs.rancher.com/rancher/configuration/registries/#self-signed-certificates)  
I have also added it to /etc/docker/certs.d/${DOMAIN}/ca.crt according to [http://docs.rancher.com/rancher/configuration/registries/#self-signed-certificates](http://docs.rancher.com/rancher/configuration/registries/#self-signed-certificates)  
Also added it to /etc/docker/certs.d/${DOMAIN}:${PORT}/ca.crt (as you would with private registrys)

And restarted docker.

However still the same in the server log:

time=“2016-04-01T09:36:24Z” level=info msg="Cloning the catalog from git URL [https://myhost.example.com/scm/lab/rancher-compose.git](https://myhost.example.com/scm/lab/rancher-compose.git)"  
Cloning into ‘./DATA/bla’…  
fatal: unable to access ‘[https://myhost.example.com/scm/lab/rancher-compose.git/](https://myhost.example.com/scm/lab/rancher-compose.git/)’: server certificate verification failed. CAfile: /etc/ssl/certs/ca-certificates.crt CRLfile: none  
time=“2016-04-01T09:36:24Z” level=error msg=“Failed to clone the catalog from git err: exit status 128”

I have replaced our domain names with fake ones…

Regards  
Christian

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [April 4, 2016, 6:04pm UTC](https://forums.suse.com/t/adding-local-catalog-fails/2144/5 "2016-04-04T18:04:26Z")

</div>

Where did you add the certificates? On your host that is running Rancher server? Inside the rancher server container?

---

<div class="post-metadata">

**Author:** ![gflwqs](https://avatars.discourse-cdn.com/v4/letter/g/6a8cbe/32.png) [@gflwqs](https://forums.suse.com/u/gflwqs)\
**Post date:** [April 5, 2016, 6:27am UTC](https://forums.suse.com/t/adding-local-catalog-fails/2144/6 "2016-04-05T06:27:54Z")

</div>

On the host.

I can also tell you that we have a working local registry using the same CA chain.

/Christian

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [April 7, 2016, 6:57pm UTC](https://forums.suse.com/t/adding-local-catalog-fails/2144/7 "2016-04-07T18:57:01Z")

</div>

Based on @vincent’s comment, it sounds like you’d need to add the certificates inside the rancher server container.

---

<div class="post-metadata">

**Author:** ![Ray](https://avatars.discourse-cdn.com/v4/letter/r/e9a140/32.png) [@Ray](https://forums.suse.com/u/Ray)\
**Post date:** [September 26, 2017, 2:14am UTC](https://forums.suse.com/t/adding-local-catalog-fails/2144/8 "2017-09-26T02:14:56Z")

</div>

I’m having the same issue and tried adding it as per the self signed certificate process for a registry without any success. Also tried setting up SSH clone of a repo with no auth and that fails, Has anyone gotten it to work and can share what steps they used?
