You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps中Download Secure File任务报错:无法获取本地颁发者证书

Azure DevOps Download Secure File任务遇"unable to get local issuer certificate"错误解决思路

在Azure DevOps流水线中使用DownloadSecureFile@1任务时,无论下载PFX证书还是PDF文件,均会触发错误:##[error]Error: unable to get local issuer certificate,但普通PowerShell脚本流水线可正常运行。示例流水线配置如下:

steps:
- task: DownloadSecureFile@1
  displayName: 'Download File'
  inputs:
    secureFile: SelfSigned.pfx
steps:
- task: DownloadSecureFile@1
  displayName: 'Download File'
  inputs:
    secureFile: 'test.pdf'

已尝试以下方案但未解决问题:

  • 全局配置git config --global http.sslbackend schannel(始终处于启用状态)
  • 将TFS服务器所有证书复制到ca-bundle.crt文件(原文件仅包含根证书)
  • 全局配置git config --global http.sslVerify false(无效后已恢复)

针对性解决方法

  1. 给任务指定CA证书路径
    DownloadSecureFile任务基于Node.js开发,可通过添加环境变量指定CA证书文件路径,让任务信任企业内部证书:

    steps:
    - task: DownloadSecureFile@1
      displayName: 'Download File'
      inputs:
        secureFile: SelfSigned.pfx
      env:
        NODE_EXTRA_CA_CERTS: 'C:\代理机器路径\ca-bundle.crt'
    
  2. 配置自托管代理的系统证书存储
    若使用自托管代理,不要仅修改git的ca-bundle.crt,直接将企业根CA证书导入代理机器的系统信任存储:

    • Windows:打开证书管理器,将证书导入「受信任的根证书颁发机构」
    • Linux:将证书复制到/etc/ssl/certs目录,运行update-ca-certificates更新
  3. 检查企业代理的SSL拦截设置
    若企业使用带SSL拦截的代理,需将Azure DevOps的域名(如dev.azure.com或自定义TFS域名)添加到代理的SSL拦截白名单,避免代理替换证书导致信任失败。

  4. 验证代理的证书信任配置
    确保代理服务器本身已信任Azure DevOps的证书,或把企业根CA证书导入代理的信任存储,避免代理转发请求时出现证书验证问题。

内容的提问来源于stack exchange,提问作者Adrimus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 13:42:40