Commit ffb04c1
authored
fix(DM01-6122): register SAP Root CA via update-ca-certificates for BuildKit (#639)
The DM01-5956 fix appended saprootca.pem directly to ca-certificates.crt,
but this does not work for Docker 23's embedded BuildKit. BuildKit's Go TLS
client uses the system CA bundle rebuilt by update-ca-certificates, which
reads from /usr/local/share/ca-certificates/ — not from raw appends to the
bundle file.
Fix: copy the CA into /usr/local/share/ca-certificates/ and call
update-ca-certificates before dockerd starts. This properly rebuilds
ca-certificates.crt and creates the expected symlink in /etc/ssl/certs/,
which Go's crypto/tls picks up when verifying InfraBox registry TLS certs
during BuildKit --cache-from manifest imports.
Verified locally: update-ca-certificates increases ca-certificates.crt size
and creates ca-cert-saprootca.pem symlink in /etc/ssl/certs/.1 parent 37f9fba commit ffb04c1
1 file changed
Lines changed: 9 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
59 | | - | |
60 | | - | |
61 | | - | |
62 | | - | |
63 | | - | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
64 | 68 | | |
65 | 69 | | |
66 | 70 | | |
| |||
0 commit comments