x509: certificate signed by unknown authority (docker pull/login)
The registry’s TLS certificate isn’t trusted by the Docker daemon — a private CA, self-signed certificate, or a TLS-inspecting corporate proxy.
Seen on:
Docker
Meaning
Docker verifies registry certificates using the host’s CA store plus /etc/docker/certs.d/<registry>/. Private registries with internal CAs, and proxies like Zscaler that re-sign traffic, need their CA installed where the daemon can see it.
Common causes
- Self-signed or internal-CA registry certificate
- Corporate proxy re-signing HTTPS (Zscaler, Netskope)
- Missing intermediate certificate on the registry
- CA installed for the browser/OS but not for Docker
⚡ Quick fix
- Put the CA in /etc/docker/certs.d/<host:port>/ca.crt
- Install the proxy root CA into the OS trust store and restart Docker
- Fix the registry to serve the full chain
Detailed fix by platform
Linux
- bash
sudo mkdir -p /etc/docker/certs.d/registry.local:5000 sudo cp company-ca.crt /etc/docker/certs.d/registry.local:5000/ca.crt
Docker Desktop
# macOS: add the CA to the System keychain (Always Trust), then restart Docker Desktop
How to diagnose
- Chain — openssl s_client -connect registry:443 -showcerts
- Proxy — Is HTTPS inspected?
- Location — certs.d folder name matches host:port exactly?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Docker
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026