You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

LibGit2Sharp报错unknown certificate lookup failure:16777280求解决

解决LibGit2Sharp克隆时的"unknown certificate lookup failure: 16777280"错误

这个错误的核心原因是目标机器未信任GitLab服务器的SSL证书,和你提供的用户名密码无关——用户名密码用于Git身份认证,而证书验证是HTTPS连接的安全校验环节,本地正常是因为你的机器已经信任了该证书(比如通过浏览器访问自动导入过),另一台机器缺少这个信任关系。

下面是具体解决方法:

方法一:信任GitLab服务器证书(安全推荐)

将GitLab的SSL证书导入到目标机器的系统根证书存储中:

  • 打开GitLab的HTTPS地址,在浏览器中导出该网站的SSL证书(通常在地址栏的锁图标里操作)
  • 打开目标机器的「证书管理器」,将导出的证书导入到「受信任的根证书颁发机构」存储中

完成后无需修改代码,即可正常克隆。

方法二:代码中指定信任证书(适合内部GitLab实例)

如果是内部部署的GitLab,证书是自签名或私有CA颁发的,可以在代码中直接加载并信任该证书:

public void Clone()
{
    this.OnUpdate?.Invoke(this, new OnUpdateEventArgs
    {
        Severity = LogType.Info,
        Message = $"Cloning the repository {this.RepositoryInfo.Name}"
    });

    try
    {
        var cloneOptions = new CloneOptions
        {
            FetchOptions = 
            {
                CredentialsProvider = (url, user, cred) => new UsernamePasswordCredentials 
                { 
                    Username = this.Author.Credentials.UserName, 
                    Password = this.Author.Credentials.Password 
                },
                // 指定信任的证书路径
                CertificateCheck = (cert, valid, host) => 
                {
                    // 加载本地的GitLab证书文件
                    var trustedCert = new X509Certificate2(@"path/to/your/gitlab-cert.crt");
                    // 对比证书是否匹配
                    return cert.Thumbprint.Equals(trustedCert.Thumbprint, StringComparison.OrdinalIgnoreCase);
                }
            }
        };

        Repository.Clone(this.RepositoryInfo.RemoteRepository, this.RepositoryInfo.LocalRepository.FullName, cloneOptions);

        this.OnUpdate?.Invoke(this, new OnUpdateEventArgs
        {
            Severity = LogType.Success,
            Message = "Repository cloned successfully."
        });
    }
    catch (Exception e)
    {
        this.OnUpdate?.Invoke(this, new OnUpdateEventArgs
        {
            Severity = LogType.Error,
            Message = Errors.GetErrorString(86) + " : " + e.Message
        });
    }
}

方法三:临时禁用证书验证(仅测试环境用,不安全)

如果只是临时测试,可以跳过证书验证,但会失去HTTPS的安全保障:

public void Clone()
{
    this.OnUpdate?.Invoke(this, new OnUpdateEventArgs
    {
        Severity = LogType.Info,
        Message = $"Cloning the repository {this.RepositoryInfo.Name}"
    });

    try
    {
        var cloneOptions = new CloneOptions
        {
            FetchOptions = 
            {
                CredentialsProvider = (url, user, cred) => new UsernamePasswordCredentials 
                { 
                    Username = this.Author.Credentials.UserName, 
                    Password = this.Author.Credentials.Password 
                },
                // 忽略证书验证
                CertificateCheck = (cert, valid, host) => true
            }
        };

        Repository.Clone(this.RepositoryInfo.RemoteRepository, this.RepositoryInfo.LocalRepository.FullName, cloneOptions);

        this.OnUpdate?.Invoke(this, new OnUpdateEventArgs
        {
            Severity = LogType.Success,
            Message = "Repository cloned successfully."
        });
    }
    catch (Exception e)
    {
        this.OnUpdate?.Invoke(this, new OnUpdateEventArgs
        {
            Severity = LogType.Error,
            Message = Errors.GetErrorString(86) + " : " + e.Message
        });
    }
}

内容的提问来源于stack exchange,提问作者scottdf93

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 09:49:56