Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Geomix7
Collaborator

Harmony SASE - Issue with Docker Pulls – TLS Certificate Error

Hello Team , 

 when trying to fetch from docker we are receiveing the following error :

"failed to solve: php:8.1-apache-bullseye: failed to resolve source metadata for docker.io/library/php:8.1-apache-bullseye: failed to do request: Head "registry-1.docker.io/v2/library/php/manifests/8.1-apache-bullseye": tls: failed to verify certificate: x509: certificate signed by unknown authority"

 

I noticed that nothing appears in the logs. To make it work, I had to create a bypass rule for the following Docker-related domains:

  • registry-1.docker.io

  • auth.docker.io

  • production.cloudflare.docker.com

Could you please advise:

  1. Are there best practices we can apply to avoid this issue in the future (e.g., handling TLS inspection with Docker Hub traffic)?

  2. Why doesn’t this behavior appear in the logs, and is there a way to improve visibility for similar cases?

Thanks in advance for your guidance.

 

0 Kudos
2 Replies
G_W_Albrecht
Legend Legend
Legend

I would suggest to open SR# with CP TAC !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
PhoneBoy
Admin
Admin

Not sure if Docker has a mechanism to update the Trusted CAs (needed for HTTPS Inspection to work) or if they implement Certificate Pinning (in which case, HTTPS Inspection won't work and you will need to bypass as you've done).

0 Kudos
Upcoming Events

    CheckMates Events