You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jenkins构建克隆Git仓库失败:SSL握手错误需客户端证书

解决方案

问题根源在于目标Git服务器要求客户端SSL证书认证,你之前的配置要么是关闭验证(无法满足服务器的客户端证书要求),要么是配置了错误的域名(code.example.com而非你的仓库域名organization.host.com),导致配置未生效。

以下是具体解决步骤:

  1. 准备客户端证书文件
    如果你的客户端证书是.p12格式,先转换成.crt和.key文件:

    # 提取证书
    openssl pkcs12 -in client-cert.p12 -clcerts -nokeys -out client.crt
    # 提取私钥(若证书有保护密码,输入对应密码)
    openssl pkcs12 -in client-cert.p12 -nocerts -out client.key
    

    确保你持有服务器信任的客户端证书及对应私钥文件。

  2. 针对目标仓库域名配置Git客户端证书
    修改Git配置(必须匹配你的仓库域名organization.host.com):

    [http "https://organization.host.com/"]
        sslCert = /path/to/client.crt
        sslKey = /path/to/client.key
        # 若服务器CA证书未被系统信任,添加此项
        sslCAinfo = /path/to/server-ca.crt
    

    不要使用--global参数,因为Jenkins运行的jenkins用户可能和你执行命令的用户不同,建议直接在Jenkins项目工作目录下执行:

    git config http.https://organization.host.com/.sslCert /path/to/client.crt
    git config http.https://organization.host.com/.sslKey /path/to/client.key
    
  3. 确保Jenkins用户有权限访问证书文件
    修改证书文件权限,让Jenkins用户能读取:

    chmod 644 /path/to/client.crt /path/to/client.key
    
  4. 验证配置有效性
    在Jenkins服务器上切换到jenkins用户,执行克隆命令测试:

    git clone https://organization.host.com/example-repo.git
    

    若克隆成功,再重新运行Jenkins构建任务。


内容的提问来源于stack exchange,提问作者Mathi Rajan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 22:52:48