Jenkins流水线构建微服务遇JFrog Artifactory证书路径错误求助
问题描述
在Jenkins流水线构建微服务时,pom.xml引用JFrog Artifactory上的logs依赖库,编译出现PKIX路径构建失败错误:
PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
相关配置及报错信息
Jenkins流水线配置
pipeline { agent { label 'microservicios'} stages { stage('Integración Continua'){ steps{ script{ container('maven'){ compile() } } } } } } def compile(){ configFileProvider([configFile(fileId: 'settings.xml', targetLocation: '.')]) { sh "mvn clean --settings settings.xml install -Prelease -X -Dmaven.wagon.http.ssl.insecure=true" } }
Jenkins配置文件管理中的settings.xml
<settings xmlns="http://maven.apache.org/SETTINGS/1.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/SETTINGS/1.0.0 http://maven.apache.org/xsd/settings-1.0.0.xsd"> <activeProfiles> <activeProfile>librerias</activeProfile> </activeProfiles> <profiles> <profile> <id>librerias</id> <repositories> <repository> <id>central</id> <url>https://repo1.maven.org/maven2</url> </repository> <repository> <id>artifactory-cloud</id> <url>https://devops/jfrog/librerias</url> <snapshots> <enabled>true</enabled> </snapshots> </repository> </repositories> </profile> </profiles> <servers> <server> <id>artifactory-cloud</id> <username>admin</username> <password>*****</password> </server> </servers> </settings>
编译报错信息
[INFO] ------------------------------------------------------------------------ [INFO] BUILD FAILURE [INFO] ------------------------------------------------------------------------ [INFO] Total time: 9.548 s [INFO] Finished at: 2024-03-25T13:29:22Z [INFO] ------------------------------------------------------------------------ [WARNING] The requested profile "release" could not be activated because it does not exist. [ERROR] Failed to execute goal on project prueba-mensajes-java: Could not resolve dependencies for project com.librerias:prueba-mensajes-java:jar:1.0-SNAPSHOT: Failed to collect dependencies at com.librerias:logs-java:jar:develop: Failed to read artifact descriptor for com.librerias:logs-java:jar:develop: Could not transfer artifact com.librerias:logs:pom:develop from/to artifactory-cloud (https://devops/jfrog/librerias): PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target -> [Help 1]
解决方案
这个错误核心是Maven使用的JVM未信任Artifactory服务器的SSL证书,以下是几种解决方式:
方式1:将Artifactory证书导入JVM全局信任库(推荐生产环境)
- 导出Artifactory证书:用浏览器访问
https://devops/jfrog/librerias,导出网站的根证书(格式选.crt或.pem) - 找到Jenkins容器中Maven使用的JDK路径,比如
/usr/lib/jvm/java-11-openjdk - 执行
keytool命令导入证书:
注:默认信任库密码为keytool -import -trustcacerts -keystore $JAVA_HOME/lib/security/cacerts -storepass changeit -noprompt -alias artifactory-cert -file /path/to/artifactory.crtchangeit,若修改过需替换为实际密码
方式2:Maven命令添加跳过SSL验证参数(临时测试用,不推荐生产)
你已添加-Dmaven.wagon.http.ssl.insecure=true,但需补充两个参数彻底跳过验证:
mvn clean --settings settings.xml install -Prelease -X -Dmaven.wagon.http.ssl.insecure=true -Dmaven.wagon.http.ssl.allowall=true -Dmaven.wagon.http.ssl.ignore.validity.dates=true
方式3:在settings.xml中配置自定义信任库
- 创建自定义信任库并导入证书:
keytool -import -trustcacerts -keystore ./artifactory-truststore.jks -storepass mypassword -noprompt -alias artifactory-cert -file /path/to/artifactory.crt - 在settings.xml的
<server>节点下添加SSL配置:
注:需确保Jenkins容器能访问到该信任库文件,可通过Jenkins配置文件管理上传<server> <id>artifactory-cloud</id> <username>admin</username> <password>*****</password> <configuration> <ssl> <trustStore>/path/to/artifactory-truststore.jks</trustStore> <trustStorePassword>mypassword</trustStorePassword> </ssl> </configuration> </server>
额外注意事项
- 命令中
-Prelease参数对应的profile不存在,建议检查pom.xml是否定义该profile,或直接移除该参数消除警告 - 确认Artifactory的URL
https://devops/jfrog/librerias可在Jenkins代理节点正常访问
内容的提问来源于stack exchange,提问作者llrichardll
相关产品推荐
相关产品推荐

