Gradle 6.9+Zulu11构建失败:TLS协议及PKIX证书路径问题求助
问题:Gradle 6.9 + Zulu 11构建失败,出现PKIX证书路径错误
错误信息
A problem occurred configuring root project 'Auth-mapper'. > Could not resolve all artifacts for configuration ':classpath'. > Could not download commons-codec-1.11.jar (commons-codec:commons-codec:1.11) > Could not get resource 'https://repo.maven.apache.org/maven2/commons-codec/commons-codec/1.11/commons-codec-1.11.jar'. > Could not HEAD 'https://repo.maven.apache.org/maven2/commons-codec/commons-codec/1.11/commons-codec-1.11.jar'. > The server may not support the client's requested TLS protocol versions: (TLSv1.2, TLSv1.3). You may need to configure the client to allow other protocols to be used. See: https://docs.gradle.org/6.9/userguide/build_environment.html#gradle_system_properties > PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
已尝试操作
- 将
https://repo.maven.apache.org/maven2的证书导入Zulu 11目录下的cacerts信任库 - 在项目根目录的
gradle.properties中配置:systemProp.javax.net.ssl.trustStore=cacerts systemProp.javax.net.ssl.trustStorePassword=changeit - 把
cacerts复制到项目根目录
解决方案
1. 验证证书导入有效性
使用keytool命令确认证书已正确导入Zulu 11的信任库:
keytool -list -keystore <你的Zulu11安装目录>/lib/security/cacerts -alias <你导入时设置的别名> -storepass changeit
如果命令返回证书信息,说明导入成功;若提示"alias not found",需重新导入证书,且确保导入的是完整证书链(而非单一证书)。
2. 修正gradle.properties中的信任库路径
避免使用相对路径,改用Zulu 11信任库的绝对路径,修改gradle.properties:
systemProp.javax.net.ssl.trustStore=/完整路径/zulu11/lib/security/cacerts systemProp.javax.net.ssl.trustStorePassword=changeit
无需将cacerts复制到项目根目录,直接使用JDK自带的信任库更稳定。
3. 配置TLS协议版本
针对错误提示的TLS协议问题,在gradle.properties中添加以下属性:
systemProp.jdk.tls.client.protocols=TLSv1.2,TLSv1.3 systemProp.javax.net.ssl.enabledProtocols=TLSv1.2,TLSv1.3
4. 清理Gradle缓存并重新构建
执行命令强制刷新依赖、清理缓存后重新构建:
./gradlew clean build --refresh-dependencies
内容的提问来源于stack exchange,提问作者Pracheer Pancholi
相关产品推荐
相关产品推荐

