如何在GitHub Actions中禁用Java应用SSL证书以解决Nexus上传失败
上传Java制品至Nexus仓库的SSL握手错误解决方案
问题背景
将Java制品通过GitHub Actions上传至Nexus仓库时遭遇SSL握手失败,无法完成上传。
相关信息
GitHub Actions工作流代码
uses: sonatype-nexus-community/nexus-repo-github-action@master with: serverUrl: https://test.xyz/repository/maven-testreleases/ username: test password: ${{ secrets.pwd }} format: maven3 repository: maven-test-releases coordinates: groupId=com.exampleartifactId=app version=1.0.0 assets: extension=jar filename: target/*.jar
报错信息
com.sonatype.nexus.api.exception.RepositoryManagerException: Upload component was unable to complete at com.sonatype.nexus.api.zz.fg.a(SourceFile:96) at com.sonatype.nexus.api.zz.fg.a(SourceFile:65) at com.sonatype.nexus.api.zz.ff.upload(SourceFile:157) at com.sonatype.nexus.api.zz.ff.upload(SourceFile:140) at com.sonatype.nexus.api.repository.v3.RepositoryManagerV3Client$upload.call(Unknown Source) at NexusPublisher.run(NexusPublisher.groovy:64) Caused by: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at org.apache.http.conn.ssl.SSLConnectionSocketFactory.createLayeredSocket(SourceFile:396) at org.apache.http.conn.ssl.SSLConnectionSocketFactory.connectSocket(SourceFile:355) at org.apache.http.impl.conn.DefaultHttpClientConnectionOperator.connect(SourceFile:142) at org.apache.http.impl.conn.PoolingHttpClientConnectionManager.connect(SourceFile:359) at org.apache.http.impl.execchain.MainClientExec.establishRoute(SourceFile:381) at org.apache.http.impl.execchain.MainClientExec.execute(SourceFile:237) at org.apache.http.impl.execchain.ProtocolExec.execute(SourceFile:185) at org.apache.http.impl.execchain.RetryExec.execute(SourceFile:89) at org.apache.http.impl.execchain.RedirectExec.execute(SourceFile:111) at org.apache.http.impl.client.InternalHttpClient.doExecute(SourceFile:185) at org.apache.http.impl.client.CloseableHttpClient.execute(SourceFile:72) at org.apache.http.impl.client.CloseableHttpClient.execute(SourceFile:221) at org.apache.http.impl.client.CloseableHttpClient.execute(SourceFile:165) at com.sonatype.nexus.api.zz.fg.a(SourceFile:84) Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
已尝试的无效操作
曾在工作流中添加以下命令尝试禁用SSL证书验证,但未生效:
- name: Disable the ssl certificates run: mvn -Dmaven.resolver.transport=wagon -Dmaven.wagon.http.ssl.insecure=true -Dmaven.wagon.http.ssl.allowall=true -Dmaven.wagon.http.ssl.ignore.validity.dates=true clean package
可行解决建议
方案1:为GitHub Actions Runner导入Nexus服务器SSL证书
- 下载Nexus服务器的SSL证书:
- name: Download Nexus SSL certificate run: | openssl s_client -connect test.xyz:443 </dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > nexus.crt
- 将证书导入Java信任存储区:
- name: Import certificate to Java truststore run: | keytool -importcert -file nexus.crt -alias nexus -keystore $JAVA_HOME/lib/security/cacerts -storepass changeit -noprompt
方案2:修改Nexus GitHub Action的SSL验证配置
该Action基于Apache HttpClient实现,可通过环境变量禁用SSL验证,同时修正坐标格式错误:
- name: Upload to Nexus uses: sonatype-nexus-community/nexus-repo-github-action@master env: javax.net.ssl.trustStore: /dev/null javax.net.ssl.trustStorePassword: changeit org.apache.http.ssl.insecure: true org.apache.http.ssl.allowall: true with: serverUrl: https://test.xyz/repository/maven-testreleases/ username: test password: ${{ secrets.pwd }} format: maven3 repository: maven-test-releases coordinates: groupId=com.example artifactId=app version=1.0.0 assets: extension=jar filename: target/*.jar
注意:原
coordinates参数中groupId=com.exampleartifactId=app缺少空格,会导致坐标解析失败,需修正为groupId=com.example artifactId=app。
方案3:使用HTTP协议(仅测试环境)
若为测试环境且允许,可将serverUrl从HTTPS改为HTTP,直接绕过SSL验证:
serverUrl: http://test.xyz/repository/maven-testreleases/
内容的提问来源于stack exchange,提问作者Sudhir Goswami
相关产品推荐
相关产品推荐

