# Cannot checkout a repository hosted on a gitea instance using self-signed certificate (\`server certificate verification failed\`)

**URL:** <https://forum.gitea.com/t/cannot-checkout-a-repository-hosted-on-a-gitea-instance-using-self-signed-certificate-server-certificate-verification-failed/7903>\
**Category:** Actions\
**Created:** [September 27, 2023, 5:50pm UTC](https://forum.gitea.com/t/cannot-checkout-a-repository-hosted-on-a-gitea-instance-using-self-signed-certificate-server-certificate-verification-failed/7903 "2023-09-27T17:50:12Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![nodiscc](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/nodiscc/32/4811_2.png) [@nodiscc](https://forum.gitea.com/u/nodiscc)\
**Post date:** [October 22, 2024, 10:45am UTC](https://forum.gitea.com/t/cannot-checkout-a-repository-hosted-on-a-gitea-instance-using-self-signed-certificate-server-certificate-verification-failed/7903/5 "2024-10-22T10:45:00Z")

</div>

@haydonryan check the solution above, there are two things at play:

- the host running act-runner must trust the certificate so it can register/communicate with the gitea instance (seems to work fine for you)
- the containers launched by act-runner, in which the `git clone` process take place, must trust the certificate - these containers have no knowledge of the host’s trust store - so you must have
  - `NODE_EXTRA_CA_CERTS: "/etc/ssl/certs/ca-certificates.crt"` in `/etc/act-runner/config.yaml`
  - `valid_volumes: ['/etc/act-runner/ca-certificates.crt']` and `options: --mount type=bind,source=/etc/act-runner/ca-certificates.crt,target=/etc/ssl/certs/ca-certificates.crt,readonly` in `/etc/act-runner/config.yaml`

Does this work for you?

---

_[View the full topic](https://forum.gitea.com/t/cannot-checkout-a-repository-hosted-on-a-gitea-instance-using-self-signed-certificate-server-certificate-verification-failed/7903)._
