You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab Actions配置信任Maven服务器SSL证书分步指南

解决GitLab Actions中Maven PKIX证书错误的分步指南

背景

已在pom.xml中配置企业Maven仓库:

</build>
    <repositories>
        <repository>
            <id>profile-releases</id>
            <url>https://enterprise.com.uy/repository</url>
        </repository>
    </repositories>
  </project>

在GitLab Actions执行mvn clean install时出现PKIX证书错误:

[ERROR] Failed to execute goal on project web-user-test: Could not resolve dependencies for project uy.com.enterprise:web-user-test:jar:1.0.0: Failed to collect dependencies at uy.com.enterprise.ProxyISSO:jar:3.0.0: Failed to read artifact descriptor for uy.com.enterprise.ProxyISSO:jar:3.0.0: Could not transfer artifact uy.com.enterprise:ProxyISSO:pom:3.0.0 from/to desaint-releases (https://enterprise.com.uy/enterprise/repo): transfer failed for ...: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target -> [Help 1]

当前使用镜像为maven:3.8.1-jdk-11,本地持有cert001.crt证书,以下是无需环境变量的证书配置分步方案:


分步操作

1. 将证书上传至GitLab仓库

  • 在项目根目录创建certs文件夹
  • 将本地的cert001.crt文件放入该文件夹,提交并推送到GitLab仓库

2. 修改.gitlab-ci.yml配置

在Maven构建步骤前添加证书导入逻辑,示例配置如下:

build:
  image: maven:3.8.1-jdk-11
  script:
    # 导入证书到JDK信任库,默认密码为changeit
    - keytool -importcert -file ./certs/cert001.crt -alias enterprise-repo-cert -keystore /usr/local/openjdk-11/lib/security/cacerts -storepass changeit -noprompt
    # 执行Maven构建
    - mvn clean install

3. 关键说明

  • maven:3.8.1-jdk-11镜像中JDK信任库的固定路径为/usr/local/openjdk-11/lib/security/cacerts
  • -noprompt参数用于跳过证书确认步骤,适配CI/CD自动化场景
  • alias可自定义,只需保证在信任库中唯一即可

内容的提问来源于stack exchange,提问作者y.z

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 05:22:42