Unable to login to docker registry using podman on macOS - x509: certificate signed by unknown authority

Viewed 4730

I am trying to use podman (version: 3.2.3) to login to a private docker registry.

I am using the default VM installed when doing podman machine init

The certificate (i.e. .pem file) is installed in macOS’s keychain.

When I run:

podman login myhost.io

After entering my username and password, I get:

Error: authenticating creds for "myhost.io": error pinging docker registry myhost.io: Get "https://myhost.io/v2/": x509: certificate signed by unknown authority

Am I doing anything wrong? Can I use the certificate saved in keychain? Or can I use the .pem file with —-authfile?

Thanks for help and suggestions.

5 Answers

I don't believe podman can read macos keychain properly (yet).

As a workaround, try not verifying the certificate.

podman login --tls-verify=false myhost.io

You do not state what registry you have deployed, but depending on how you've set it up or if you picked something like harbor then the option you are probably looking for is --cert=path as described in the podman login documentation. The certificate you are looking for is the Certificate Authority for the registry; in the case of harbor can be downloaded from the web interface.

The documentation also states a user friendly location to store such certificates under the following path:

# Default path
/etc/containers/certs.d

# Example
/etc/containers/certs.d/myhost.io

Alternatively, use the option: --cert.

Please note that the option --tls-verify=false option is used typically for self-signed certificates.

put your self signed certificate to

/etc/containers/certs.d/

and use podman login command with tag --tls-verify

I got the same issue when deploying a private registry in rhel8; the reason for this is the self-signed cert; You have to copy the cert from server to the client: step1. scp server:/opt/registry/cert/xxx.crt client:/etc/pki/ca-trust/source/anchors/ step2. update-ca-trust

/etc/docker/daemon.json Add

{
  "insecure-registries" : ["myhost.io"]
}

Restart docker instance.

References

Related