Windows Server 2019上GitHub Action Runner无法建立SSL连接
Windows Server 2019 1809上GitHub Action Runner SSL连接错误解决指南
问题描述
在Windows Server 2019 Data Center(版本1809)执行GitHub Action Runner配置命令:
./config.cmd --url https://github.com/org/repo --token myPAT
出现错误:无法建立SSL连接,请查看内部异常。
此前已部署的Runner执行工作流时也突然出现相同错误,完整错误日志如下:
[2024-03-14 18:07:53Z ERR ConfigurationManager] System.Net.Http.HttpRequestException: 无法建立SSL连接,请查看内部异常。 ---> System.Security.Authentication.AuthenticationException: 身份验证失败,因为远程方发送了TLS警报: 'IllegalParameter'。 ---> System.ComponentModel.Win32Exception (0x80090326): 收到的消息意外或格式错误。 --- 内部异常堆栈跟踪结束 --- 在 System.Net.Security.SslStream.ForceAuthenticationAsync[TIOAdapter](TIOAdapter adapter, Boolean receiveFirst, Byte[] reAuthenticationData, Boolean isApm) 在 System.Net.Http.ConnectHelper.EstablishSslConnectionAsync(SslClientAuthenticationOptions sslOptions, HttpRequestMessage request, Boolean async, Stream stream, CancellationToken cancellationToken) --- 内部异常堆栈跟踪结束 --- 在 System.Net.Http.ConnectHelper.EstablishSslConnectionAsync(SslClientAuthenticationOptions sslOptions, HttpRequestMessage request, Boolean async, Stream stream, CancellationToken cancellationToken) 在 System.Net.Http.HttpConnectionPool.ConnectAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken) 在 System.Net.Http.HttpConnectionPool.CreateHttp11ConnectionAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken) 在 System.Net.Http.HttpConnectionPool.AddHttp11ConnectionAsync(HttpRequestMessage request) 在 System.Threading.Tasks.TaskCompletionSourceWithCancellation`1.WaitWithCancellationAsync(CancellationToken cancellationToken) 在 System.Net.Http.HttpConnectionPool.GetHttp11ConnectionAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken) 在 System.Net.Http.HttpConnectionPool.SendWithVersionDetectionAndRetryAsync(HttpRequestMessage request, Boolean async, Boolean doRequestAuth, CancellationToken cancellationToken) 在 System.Net.Http.RedirectHandler.SendAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken) 在 System.Net.Http.HttpClient.<SendAsync>g__Core|83_0(HttpRequestMessage request, HttpCompletionOption completionOption, CancellationTokenSource cts, Boolean disposeCts, CancellationTokenSource pendingRequestsCts, CancellationToken originalCancellationToken) 在 GitHub.Runner.Listener.Configuration.ConfigurationManager.GetTenantCredential(String githubUrl, String githubToken, String runnerEvent) [2024-03-14 18:07:53Z ERR ConfigurationManager] #####################################################
核心原因
错误根源是TLS握手阶段触发的IllegalParameter警报,结合Windows Server 2019 1809特性,主要诱因包括:
- 系统默认TLS版本、加密套件与GitHub服务器要求不匹配
- 系统缺少TLS/SSL相关的关键更新补丁
- 本地防火墙、代理或安全软件拦截并篡改了SSL连接
解决步骤
1. 安装系统累积更新
Windows Server 2019 1809需安装最新累积更新,尤其是涉及TLS协议和加密套件的补丁。打开Windows更新,检查并安装所有可用更新,重启服务器后重试Runner配置。
2. 启用兼容的TLS版本
通过注册表编辑器启用TLS 1.2和TLS 1.3(GitHub优先支持这两个版本):
- 打开
regedit,导航到路径:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols - 分别创建
TLS 1.2和TLS 1.3子项,每个子项内再创建Client子项 - 在每个
Client子项中添加两个DWORD值:DisabledByDefault:设置为0Enabled:设置为1
- 重启服务器使配置生效
3. 调整加密套件顺序
确保系统启用GitHub兼容的加密套件:
- 打开本地组策略编辑器(
gpedit.msc) - 导航到:
计算机配置 > 管理模板 > 网络 > SSL配置设置 - 启用
SSL加密套件顺序,设置为兼容列表(示例):TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 - 应用配置并重启服务器
4. 排查防火墙/代理干扰
- 临时关闭Windows Defender防火墙,测试Runner连接是否恢复正常
- 若使用代理服务器,确认代理配置了SSL直通,未拦截GitHub的HTTPS连接
- 检查第三方杀毒或安全软件,临时禁用后测试是否排除拦截问题
内容的提问来源于stack exchange,提问作者Maxx
相关产品推荐
相关产品推荐

