You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在GitHub Actions中禁用Java应用SSL证书以解决Nexus上传失败

上传Java制品至Nexus仓库的SSL握手错误解决方案

问题背景

将Java制品通过GitHub Actions上传至Nexus仓库时遭遇SSL握手失败,无法完成上传。

相关信息

GitHub Actions工作流代码

uses: sonatype-nexus-community/nexus-repo-github-action@master
        with:
          serverUrl: https://test.xyz/repository/maven-testreleases/
          username: test
          password: ${{ secrets.pwd }}
          format: maven3
          repository: maven-test-releases
          coordinates: groupId=com.exampleartifactId=app version=1.0.0
          assets: extension=jar
          filename: target/*.jar

报错信息

com.sonatype.nexus.api.exception.RepositoryManagerException: Upload component was unable to complete
    at com.sonatype.nexus.api.zz.fg.a(SourceFile:96)
    at com.sonatype.nexus.api.zz.fg.a(SourceFile:65)
    at com.sonatype.nexus.api.zz.ff.upload(SourceFile:157)
    at com.sonatype.nexus.api.zz.ff.upload(SourceFile:140)
    at com.sonatype.nexus.api.repository.v3.RepositoryManagerV3Client$upload.call(Unknown Source)
    at NexusPublisher.run(NexusPublisher.groovy:64)
Caused by: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
    at org.apache.http.conn.ssl.SSLConnectionSocketFactory.createLayeredSocket(SourceFile:396)
    at org.apache.http.conn.ssl.SSLConnectionSocketFactory.connectSocket(SourceFile:355)
    at org.apache.http.impl.conn.DefaultHttpClientConnectionOperator.connect(SourceFile:142)
    at org.apache.http.impl.conn.PoolingHttpClientConnectionManager.connect(SourceFile:359)
    at org.apache.http.impl.execchain.MainClientExec.establishRoute(SourceFile:381)
    at org.apache.http.impl.execchain.MainClientExec.execute(SourceFile:237)
    at org.apache.http.impl.execchain.ProtocolExec.execute(SourceFile:185)
    at org.apache.http.impl.execchain.RetryExec.execute(SourceFile:89)
    at org.apache.http.impl.execchain.RedirectExec.execute(SourceFile:111)
    at org.apache.http.impl.client.InternalHttpClient.doExecute(SourceFile:185)
    at org.apache.http.impl.client.CloseableHttpClient.execute(SourceFile:72)
    at org.apache.http.impl.client.CloseableHttpClient.execute(SourceFile:221)
    at org.apache.http.impl.client.CloseableHttpClient.execute(SourceFile:165)
    at com.sonatype.nexus.api.zz.fg.a(SourceFile:84)

Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

已尝试的无效操作

曾在工作流中添加以下命令尝试禁用SSL证书验证,但未生效:

- name: Disable the ssl certificates
  run: mvn -Dmaven.resolver.transport=wagon -Dmaven.wagon.http.ssl.insecure=true -Dmaven.wagon.http.ssl.allowall=true -Dmaven.wagon.http.ssl.ignore.validity.dates=true clean package

可行解决建议

方案1:为GitHub Actions Runner导入Nexus服务器SSL证书

  1. 下载Nexus服务器的SSL证书:
- name: Download Nexus SSL certificate
  run: |
    openssl s_client -connect test.xyz:443 </dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > nexus.crt
  1. 将证书导入Java信任存储区:
- name: Import certificate to Java truststore
  run: |
    keytool -importcert -file nexus.crt -alias nexus -keystore $JAVA_HOME/lib/security/cacerts -storepass changeit -noprompt

方案2:修改Nexus GitHub Action的SSL验证配置

该Action基于Apache HttpClient实现,可通过环境变量禁用SSL验证,同时修正坐标格式错误:

- name: Upload to Nexus
  uses: sonatype-nexus-community/nexus-repo-github-action@master
  env:
    javax.net.ssl.trustStore: /dev/null
    javax.net.ssl.trustStorePassword: changeit
    org.apache.http.ssl.insecure: true
    org.apache.http.ssl.allowall: true
  with:
    serverUrl: https://test.xyz/repository/maven-testreleases/
    username: test
    password: ${{ secrets.pwd }}
    format: maven3
    repository: maven-test-releases
    coordinates: groupId=com.example artifactId=app version=1.0.0
    assets: extension=jar
    filename: target/*.jar

注意:原coordinates参数中groupId=com.exampleartifactId=app缺少空格,会导致坐标解析失败,需修正为groupId=com.example artifactId=app。

方案3:使用HTTP协议(仅测试环境)

若为测试环境且允许,可将serverUrl从HTTPS改为HTTP,直接绕过SSL验证:

serverUrl: http://test.xyz/repository/maven-testreleases/

内容的提问来源于stack exchange,提问作者Sudhir Goswami

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 08:55:54