Kubernetes: x509 certificate signed by unknown authority, possibly because of ECDSA verification failure

Viewed 5545

I am new in Kubernetes and stuck on the issue. I was trying to renew letsencrypt SSL certificate. But when I try to get certificate by running following command

kubectl get certificate

System throwing this exception

Error from server: conversion webhook for cert-manager.io/v1alpha2, Kind=Certificate failed: Post https://cert-manager-webhook.default.svc:443/convert?timeout=30s: x509: certificate signed by unknown authority (possibly because of "x509: ECDSA verification failure" while trying to verify candidate authority certificate "cert-manager-webhook-ca")

I have checked the pods also

enter image description here

The "cert-manager-webhook" is in running state. When I check logs of this pod, I get the following response

enter image description here

I have also tried to apply cluster-issuer after deleting it but face same issue

kubectl apply -f cluster-issuer.yaml

enter image description here

I also have done R&D about this but could not find any suitable solution. Whats the issue here? Can someone please help me regarding this? Thanks.

2 Answers

The problem was with "cert-manager-cainjector" pod status which was "CrashLoopBackOff" due to FailedMount as secret was not found for mounting. I have created that secret and after that it start working fine.

if you are using webhook, check if you have injected the ca, if not you could do it using:

apiVersion: admissionregistration.k8s.io/v1
kind: MutatingWebhookConfiguration
metadata:
...
  annotations:
    cert-manager.io/inject-ca-from: "<namespace>/<certificate_name>"
Related