x509: certificate signed by unknown authority 🐳 Docker

x509: certificate signed by unknown authority (docker pull/login)

The registry’s TLS certificate isn’t trusted by the Docker daemon — a private CA, self-signed certificate, or a TLS-inspecting corporate proxy.

Seen on: Docker

Meaning

Docker verifies registry certificates using the host’s CA store plus /etc/docker/certs.d/<registry>/. Private registries with internal CAs, and proxies like Zscaler that re-sign traffic, need their CA installed where the daemon can see it.

Common causes

  • Self-signed or internal-CA registry certificate
  • Corporate proxy re-signing HTTPS (Zscaler, Netskope)
  • Missing intermediate certificate on the registry
  • CA installed for the browser/OS but not for Docker

⚡ Quick fix

  1. Put the CA in /etc/docker/certs.d/<host:port>/ca.crt
  2. Install the proxy root CA into the OS trust store and restart Docker
  3. Fix the registry to serve the full chain

Detailed fix by platform

Linux

  1. bash
    sudo mkdir -p /etc/docker/certs.d/registry.local:5000
    sudo cp company-ca.crt /etc/docker/certs.d/registry.local:5000/ca.crt

Docker Desktop

  1. # macOS: add the CA to the System keychain (Always Trust), then restart Docker Desktop

How to diagnose

  1. Chain — openssl s_client -connect registry:443 -showcerts
  2. Proxy — Is HTTPS inspected?
  3. Location — certs.d folder name matches host:port exactly?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.