# X509 certificate signed by unknown authority

**URL:** <https://forums.suse.com/t/x509-certificate-signed-by-unknown-authority/268>\
**Category:** RancherOS\
**Created:** [August 19, 2015, 2:36pm UTC](https://forums.suse.com/t/x509-certificate-signed-by-unknown-authority/268 "2015-08-19T14:36:33Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![kiboro](https://avatars.discourse-cdn.com/v4/letter/k/7993a0/32.png) [@kiboro](https://forums.suse.com/u/kiboro)\
**Post date:** [August 19, 2015, 2:36pm UTC](https://forums.suse.com/t/x509-certificate-signed-by-unknown-authority/268/1 "2015-08-19T14:36:33Z")

</div>

We have a private docker registry and the certificate isn’t normally recognised. ['m getting the following message when trying to pull from it:  
v2 ping attempt failed with error: Get [https://docker.pibenchmark.com/v2/:](https://docker.pibenchmark.com/v2/:) x509: certificate signed by unknown authority

I know how to fix this on CentOS but how do I do that in RancherOS?

---

<div class="post-metadata">

**Author:** ![Stokkes](https://avatars.discourse-cdn.com/v4/letter/s/848f3c/32.png) [@Stokkes](https://forums.suse.com/u/Stokkes)\
**Post date:** [August 24, 2015, 10:33pm UTC](https://forums.suse.com/t/x509-certificate-signed-by-unknown-authority/268/2 "2015-08-24T22:33:45Z")

</div>

Hello,

I have the same issue here. Trying to run a private registry on top of RancherOS and not quite sure how to get around this issue.

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![ibuildthecloud](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/ibuildthecloud/32/8_2.png) [@ibuildthecloud](https://forums.suse.com/u/ibuildthecloud)\
**Post date:** [August 25, 2015, 4:52pm UTC](https://forums.suse.com/t/x509-certificate-signed-by-unknown-authority/268/3 "2015-08-25T16:52:54Z")

</div>

Rancher v0.4 should be out this week, in that release you just need to place the standard locations in /etc. In RancherOS v0.3.x this is unfortunately not possible. @denise Can we put a place holder to fill in docs for this, I’ll provide content tomorrow.

---

<div class="post-metadata">

**Author:** ![kiboro](https://avatars.discourse-cdn.com/v4/letter/k/7993a0/32.png) [@kiboro](https://forums.suse.com/u/kiboro)\
**Post date:** [August 26, 2015, 9:58am UTC](https://forums.suse.com/t/x509-certificate-signed-by-unknown-authority/268/4 "2015-08-26T09:58:04Z")

</div>

Ok, thanks. Saved me trying to poke around in there to do it. I’ve reverted to CentOS 7 based hosts for the short term but RancherOS seems a much slicker solution.

---

<div class="post-metadata">

**Author:** ![liyi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/liyi/32/4609_2.png) [@liyi](https://forums.suse.com/u/liyi)\
**Post date:** [February 19, 2016, 9:04pm UTC](https://forums.suse.com/t/x509-certificate-signed-by-unknown-authority/268/5 "2016-02-19T21:04:04Z")

</div>

Any update on this? Is it possible now?

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [February 21, 2016, 6:34am UTC](https://forums.suse.com/t/x509-certificate-signed-by-unknown-authority/268/6 "2016-02-21T06:34:22Z")

</div>

[http://docs.rancher.com/os/configuration/docker/#certificates-for-private-registries](http://docs.rancher.com/os/configuration/docker/#certificates-for-private-registries)

---

<div class="post-metadata">

**Author:** ![liyi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/liyi/32/4609_2.png) [@liyi](https://forums.suse.com/u/liyi)\
**Post date:** [February 21, 2016, 2:30pm UTC](https://forums.suse.com/t/x509-certificate-signed-by-unknown-authority/268/7 "2016-02-21T14:30:30Z")

</div>

Thanks Denise! The certificate will be valid for the system-docker and user-docker, right?

---

<div class="post-metadata">

**Author:** ![kuzhao](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/kuzhao/32/1675_2.png) [@kuzhao](https://forums.suse.com/u/kuzhao)\
**Post date:** [September 6, 2016, 8:05am UTC](https://forums.suse.com/t/x509-certificate-signed-by-unknown-authority/268/8 "2016-09-06T08:05:44Z")

</div>

Hi there, may I ask for the status of this issue? Looks like things are still where they are in the latest rancheros.  
From the wrestling done so far I found that system-docker uses ca cert other than the well-known /etc/ssl/certs/. Nor did I find any documentation dealing with this at [rancher.com](http://rancher.com).  
So the only viable way is to scp rancheros img tar and install locally in corporate network environment?
