Docker Build fails with "CA signature digest algorithm too weak"
Issue
-
When trying to build a custom container image for OpenShift, the build on the OpenShift Container Platform cluster fails with the following error message:
Updating Subscription Management repositories. Unable to read consumer identity Repository 'rhel-8-for-x86_64-appstream-rpms' is enabled for this system. Repository 'rhel-8-for-x86_64-baseos-rpms' is enabled for this system. Updating Subscription Management repositories. Unable to read consumer identity Red Hat Enterprise Linux 8 for x86_64 - AppStre 0.0 B/s | 0 B 00:00 Errors during downloading metadata for repository 'rhel-8-for-x86_64-appstream-rpms': - Curl error (60): Peer certificate cannot be authenticated with given CA certificates for https://cdn.redhat.com/content/dist/rhel8/8/x86_64/appstream/os/repodata/repomd.xml [SSL certificate problem: CA signature digest algorithm too weak] Error: Failed to download metadata for repo 'rhel-8-for-x86_64-appstream-rpms': Cannot download repomd.xml: Cannot download repodata/repomd.xml: All mirrors were tried subprocess exited with status 1 subprocess exited with status 1 -
yum installin the Docker Build fails with the above error message. - After applying Solution 4244451, builds fail with the above error.
Environment
- Red Hat OpenShift Container Platform (OCP) 4.5
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.