You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

局域网Ubuntu服务器部署GitLab HTTPS访问失败及证书问题求助

解决局域网GitLab HTTPS访问及Let's Encrypt验证失败问题

问题核心原因

Let's Encrypt的ACME验证服务器是公网服务,无法访问你局域网内的gitlab.mydomain.com域名,导致HTTP-01验证流程直接失败,这是你执行gitlab-ctl reconfigure报错的根本原因——公网验证服务器无法穿透到你的内网环境完成验证。

具体解决步骤

1. 禁用GitLab自带的Let's Encrypt自动配置

编辑GitLab主配置文件/etc/gitlab/gitlab.rb,找到并修改以下配置项:

# 禁用Let's Encrypt自动证书申请
letsencrypt['enable'] = false
# 注释或删除所有与Let's Encrypt相关的其他配置(如contact_emails、auto_renew等)

2. 生成自签名证书(适用于局域网场景)

如果没有内网CA,直接生成自签名证书即可满足内网HTTPS需求:

# 生成私钥
openssl genrsa -out /etc/gitlab/ssl/gitlab.mydomain.com.key 2048
# 生成自签名证书,有效期365天,CN需与你的内网域名一致
openssl req -new -x509 -key /etc/gitlab/ssl/gitlab.mydomain.com.key -out /etc/gitlab/ssl/gitlab.mydomain.com.crt -days 365 -subj "/CN=gitlab.mydomain.com"

设置证书文件权限(GitLab需要正确的权限才能读取):

chmod 600 /etc/gitlab/ssl/gitlab.mydomain.com.key
chmod 644 /etc/gitlab/ssl/gitlab.mydomain.com.crt
chown root:root /etc/gitlab/ssl/gitlab.mydomain.com.*

3. 配置GitLab使用自定义证书

回到/etc/gitlab/gitlab.rb,设置HTTPS相关配置:

external_url 'https://gitlab.mydomain.com'
# 开启HTTP转HTTPS
nginx['redirect_http_to_https'] = true
# 指定自定义证书路径
nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab.mydomain.com.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab.mydomain.com.key"

4. 应用配置并重启服务

执行命令让GitLab加载新配置:

gitlab-ctl reconfigure
gitlab-ctl restart

5. 客户端信任自签名证书(可选)

将/etc/gitlab/ssl/gitlab.mydomain.com.crt复制到局域网内的客户端机器,添加到系统或浏览器的信任根证书列表中,即可消除访问时的安全提示。

内容的提问来源于stack exchange,提问作者Z.J

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 01:16:08