Quick'n'dirty until documented:
- http://serverfault.com/questions/611120/failed-tls-handshake-does-not-contain-any-ip-sans#611121
- create self-signed SSL cert (see Docker guide)
- mkdir -p /etc/docker/certs.d/192.168.0.1:5000
-> copy domain.crt from master into that directory as ca.crt
- ln -s /etc/docker/certs.d/192.168.0.1:5000/ca.crt /usr/local/share/ca-certificates/192.168.0.1.crt
- update-ca-certificates
- service docker stop && service docker start