# Git Helm Catalog untrusted certificate

**URL:** <https://forums.suse.com/t/git-helm-catalog-untrusted-certificate/16019>\
**Category:** SUSE Rancher Prime\
**Created:** [December 5, 2019, 11:49am UTC](https://forums.suse.com/t/git-helm-catalog-untrusted-certificate/16019 "2019-12-05T11:49:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![laep](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@laep](https://forums.suse.com/u/laep)\
**Post date:** [December 5, 2019, 11:49am UTC](https://forums.suse.com/t/git-helm-catalog-untrusted-certificate/16019/1 "2019-12-05T11:49:04Z")

</div>

I installed rancher with a custom CA certificate.

That certificates exists in the cluster and the installation been working fine.

Now when i try to add a git catalog that uses the same CA it says the CA is untrusted.  
I ve checked the rancher nodes can connect do the catalog without a problem but inside the pods the CA isnt trusted

---

<div class="post-metadata">

**Author:** ![shubbard343](https://avatars.discourse-cdn.com/v4/letter/s/47e85d/32.png) [@shubbard343](https://forums.suse.com/u/shubbard343)\
**Post date:** [December 6, 2019, 6:52pm UTC](https://forums.suse.com/t/git-helm-catalog-untrusted-certificate/16019/2 "2019-12-06T18:52:20Z")

</div>

> [@laep](#):
>
> That certificates exists in the cluster

What do you mean by this? Did you add the certificate secret `tls-ca-additional` to the `cattle-system` namespace? That is what I had to do to get Helm charts to work.

---

<div class="post-metadata">

**Author:** ![laep](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@laep](https://forums.suse.com/u/laep)\
**Post date:** [December 10, 2019, 12:04pm UTC](https://forums.suse.com/t/git-helm-catalog-untrusted-certificate/16019/3 "2019-12-10T12:04:36Z")

</div>

My english there was rather bad…

I meant those certificates are insade the rancher pods.

But dont worry i was able to solve my problem.

I already had placed the main CA but it wasnt enough. Seems like rancher was having some problems with the sub-ca. So i changed the tls-ca-additional secret to contain the full CA chain
