# Kubectl with TLS inspection

**URL:** <https://discuss.kubernetes.io/t/kubectl-with-tls-inspection/27410>\
**Category:** General Discussions\
**Tags:** security, network\
**Created:** [March 11, 2024, 8:47am UTC](https://discuss.kubernetes.io/t/kubectl-with-tls-inspection/27410 "2024-03-11T08:47:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dhimant](https://avatars.discourse-cdn.com/v4/letter/d/6f9a4e/32.png) [@dhimant](https://discuss.kubernetes.io/u/dhimant)\
**Post date:** [March 11, 2024, 8:47am UTC](https://discuss.kubernetes.io/t/kubectl-with-tls-inspection/27410/1 "2024-03-11T08:47:04Z")

</div>

Hi  
I am running kubectl commands from powershell and we also use a network tool for TLS inspection. TLS inspection application uses its own certificate to perform its functions. This certificate is also installed in the Windows Trusted Root Certificate Authorities as well. Still kubectl shows the following error:  
“Unable to connect to the server: tls: failed to verify certificate: x509: certificate signed by unknown authority”

Now I know I can add trusted certificates to a specific cluster in the kubectl config file but I have to do that for each cluster I add which is not ideal. Is there a solution where I can add this certificate globally or get kubectl to recognise Windows Trusted Root Certificate Authorities so it doesn’t show this above error.

I DON’T want to skip TLS inspection with the --insecure-skip-tls-verify option.

I am running this through Docker or any other virtualized container. The operating system is Windows 11 Pro.

---

<div class="post-metadata">

**Author:** ![brnl](https://avatars.discourse-cdn.com/v4/letter/b/b19c9b/32.png) [@brnl](https://discuss.kubernetes.io/u/brnl)\
**Post date:** [March 12, 2024, 12:21pm UTC](https://discuss.kubernetes.io/t/kubectl-with-tls-inspection/27410/2 "2024-03-12T12:21:02Z")

</div>

> [@dhimant](#):
>
> I am running this through Docker or any other virtualized container. The operating system is Windows 11 Pro.

I think you need to inject the root certificate into the docker image in that case.
