You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地GitLab服务器Git LFS自签名证书配置故障求助

问题背景

在Windows 10主机的VirtualBox虚拟机中,基于Debian系统搭建本地GitLab服务器,卡在Git LFS与自签名证书兼容的配置环节,要求不关闭Git SSL验证,最终服务器可在局域网使用。

已执行操作及遇到的错误

1. 初始自签名证书生成与GitLab配置

生成证书命令:

# 创建证书目录
mkdir /etc/gitlab/ssl
# 设置目录权限
chmod 755 /etc/gitlab/ssl/
# 进入目录生成证书
cd /etc/gitlab/ssl
openssl req -x509 -newkey rsa:4096 -keyout Gitlab_Prototyp.key -out Gitlab_Prototyp.crt -days 10000 -sha256 -nodes

证书填写信息:

  • 国家(Country Name):DE
  • 地区(Locality Name):SomeCity
  • 组织(Organization Name):SomeCompany
  • 通用名(Common Name):192.168.56.1

修改gitlab.rb配置文件:

external_url 'https://192.168.56.1'

nginx['enable'] = true
nginx['redirect_http_to_https'] = true                       
nginx['redirect_http_to_https_port'] = 80

nginx['ssl_certificate'] = "/etc/gitlab/ssl/Gitlab_Prototyp.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/Gitlab_Prototyp.key"

nginx['ssl_ciphers'] = "ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256"
nginx['ssl_prefer_server_ciphers'] = "on" 
nginx['ssl_protocols'] = "TLSv1.2 TLSv1.3"
nginx['ssl_session_cache'] = "shared:SSL:10m"
nginx['ssl_session_timeout'] = "5m"
nginx['hsts_max_age'] = 31536000
nginx['hsts_include_subdomains'] = true

执行配置生效命令:

gitlab-ctl reconfigure
gitlab-ctl restart

2. 主机Git配置与初始推送

浏览器下载PEM证书保存至C:\Program Files\Git\mingw64\ssl\192-168-56-1.pem,配置Git:

git config --global http."https://192.168.56.1/".sslCAInfo "C:\Program Files\Git\mingw64\ssl\192-168-56-1.pem"

初始推送成功:

git push -uf --all origin

3. Git LFS相关错误

添加文件到Git LFS后推送,出现第一个错误:

Remote "origin" does not support the Git LFS locking API. Consider disabling it with:
$ git config lfs.https://192.168.56.1/gitlab-instance-0fc1769d/testgitproject.git/info/lfs.locksverify false

执行命令关闭锁验证:

git config lfs.https://192.168.56.1/gitlab-instance-0fc1769d/testgitproject.git/info/lfs.locksverify false

再次推送出现证书SAN错误:

batch response: Post "https://192.168.56.1/gitlab-instance-0fc1769d/testgitproject.git/info/lfs/objects/batch": x509: certificate relies on legacy Common Name field, use SANs instead

4. 生成带SAN证书后的错误

生成带SAN的证书:

cd /etc/gitlab/ssl
openssl req -x509 -newkey rsa:4096 -keyout NSI_Gitlab_Prototyp.key -out NSI_Gitlab_Prototyp.crt -days 10000 -sha256 -nodes -addext "subjectAltName = DNS:192.168.56.1"

重新配置GitLab并重启后,推送出现错误:

fatal: unable to access 'https://192.168.56.1/gitlab-instance-0fc1769d/testgitproject.git/': SSL: no alternative certificate subject name matches target host name '192.168.56.1'

解决方案

1. 正确生成带IP SAN的自签名证书

因为使用IP地址而非域名,SAN需指定IP类型而非DNS类型,执行以下命令生成证书:

cd /etc/gitlab/ssl
# 删除旧证书(可选,避免混淆)
rm Gitlab_Prototyp.* NSI_Gitlab_Prototyp.*
# 生成带IP SAN的证书
openssl req -x509 -newkey rsa:4096 -keyout Gitlab_Prototyp.key -out Gitlab_Prototyp.crt -days 10000 -sha256 -nodes \
-addext "subjectAltName = IP:192.168.56.1" \
-subj "/C=DE/L=SomeCity/O=SomeCompany/CN=192.168.56.1"

说明:subjectAltName = IP:192.168.56.1明确指定IP作为SAN字段,同时保持CN为该IP,兼容新旧验证逻辑。

2. 更新GitLab配置并生效

修改gitlab.rb确保证书路径正确(若更换证书文件名,需对应更新):

nginx['ssl_certificate'] = "/etc/gitlab/ssl/Gitlab_Prototyp.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/Gitlab_Prototyp.key"

执行生效命令:

gitlab-ctl reconfigure
gitlab-ctl restart

3. 更新主机Git及Git LFS的证书配置

  1. 从浏览器重新下载GitLab的PEM证书,覆盖之前的C:\Program Files\Git\mingw64\ssl\192-168-56-1.pem
  2. 单独配置Git LFS的SSL证书(Git LFS可能独立读取证书):
git config --global lfs.https://192.168.56.1/.sslCAInfo "C:\Program Files\Git\mingw64\ssl\192-168-56-1.pem"

说明:Git LFS的配置项是lfs.<url>.sslCAInfo,需与Git的配置保持一致。

4. 局域网其他机器配置

对于局域网内的其他Windows机器,重复以下步骤:

  1. 访问https://192.168.56.1,下载PEM证书保存到本地路径(如C:\GitCert\192-168-56-1.pem)
  2. 配置Git和Git LFS:
git config --global http."https://192.168.56.1/".sslCAInfo "C:\GitCert\192-168-56-1.pem"
git config --global lfs.https://192.168.56.1/.sslCAInfo "C:\GitCert\192-168-56-1.pem"

验证推送

重新执行Git LFS推送:

git lfs push origin main
# 或整体推送
git push

内容的提问来源于stack exchange,提问作者tomko

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 23:25:20