# Rancher-compose and unknown CA

**URL:** <https://forums.suse.com/t/rancher-compose-and-unknown-ca/3642>\
**Category:** Rancher 1.x\
**Created:** [August 5, 2016, 9:59am UTC](https://forums.suse.com/t/rancher-compose-and-unknown-ca/3642 "2016-08-05T09:59:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jose\_Gato\_Luis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jose_gato_luis/32/6587_2.png) [@Jose\_Gato\_Luis](https://forums.suse.com/u/Jose_Gato_Luis)\
**Post date:** [August 5, 2016, 9:59am UTC](https://forums.suse.com/t/rancher-compose-and-unknown-ca/3642/1 "2016-08-05T09:59:28Z")

</div>

Hi there,

I am having problems using docker-compose against our Rancher Server with ssl and our certificate. It is not a self signed certificate, but it seems there is no a known CA in most of browsers and distributions. With Ranchger agents we solved the issue adding the full chain of the certificate bundled into a file, and now it is working ok.

Now the problem is with rancher-compose, that it seems it is not using the certificates registry of my system (for example Ubuntu 16.04). So, trying to use docker-compose:

```auto
$ rancher-compose up
ERRO[0000] Failed to open project deployment: Get https://iot-agents.atosresearch.eu/: x509: certificate signed by unknown authority 
FATA[0000] Failed to read project: Get https://iot-agents.atosresearch.eu/: x509: certificate signed by unknown authority

```

The certificate is correctly added to my Ubuntu System, I can test it with:

```auto
$ curl https://server_url/

{"id":"31f10389-d693-40e8-becf-bb7a50bf4adb","type":"error","links":{},"actions":{},"status":401,"code":"Unauthorized","message":"Unauthorized","detail":null}

```

How is taking certificates rancher-compose?

Many thanks

---

<div class="post-metadata">

**Author:** ![sra](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/sra/32/1514_2.png) [@sra](https://forums.suse.com/u/sra)\
**Post date:** [August 5, 2016, 1:31pm UTC](https://forums.suse.com/t/rancher-compose-and-unknown-ca/3642/2 "2016-08-05T13:31:04Z")

</div>

It may pay attention to the `DOCKER_TLS_VERIFY` environment variable because it uses `libcompose`. Try `export DOCKER_TLS_VERIFY=0`

---

<div class="post-metadata">

**Author:** ![Jose\_Gato\_Luis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jose_gato_luis/32/6587_2.png) [@Jose\_Gato\_Luis](https://forums.suse.com/u/Jose_Gato_Luis)\
**Post date:** [August 10, 2016, 9:57am UTC](https://forums.suse.com/t/rancher-compose-and-unknown-ca/3642/3 "2016-08-10T09:57:47Z")

</div>

Sorry, but still the same problem ☹

Ignoring TLS could be a good workaround by the moment, to continue with my objectives. But, I would like to have a way of including the CA which is validating my Cert. Because it is a valid one (rancher agents are using this certificate).

---

<div class="post-metadata">

**Author:** ![Jose\_Gato\_Luis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jose_gato_luis/32/6587_2.png) [@Jose\_Gato\_Luis](https://forums.suse.com/u/Jose_Gato_Luis)\
**Post date:** [August 11, 2016, 11:29am UTC](https://forums.suse.com/t/rancher-compose-and-unknown-ca/3642/4 "2016-08-11T11:29:55Z")

</div>

I have not solved the issue, because I dont know where GO is taking the certificates. But I have a better solution. Now I have configured correctly my server to provide correctly the certificates chain (including intermediate certificate). Now all the clients can identify the CA as known and trusted.

---

<div class="post-metadata">

**Author:** ![Sura\_Kr](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@Sura\_Kr](https://forums.suse.com/u/Sura_Kr)\
**Post date:** [September 20, 2016, 7:50pm UTC](https://forums.suse.com/t/rancher-compose-and-unknown-ca/3642/5 "2016-09-20T19:50:49Z")

</div>

Hey Jose May I know how you configured your server to provide proper certificate chain with intermediate certificates. It will help us more, can you tell me the order, thanks in advance.
