You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

清除Gradle缓存后导入依赖遇PKIX证书路径错误求助

Gradle依赖导入PKIX证书错误解决建议

问题背景

执行rm -rf $HOME/.gradle/caches/清除Gradle缓存后,项目导入Gradle依赖失败,安装新版本Gradle后问题仍存在。核心错误片段:

sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

完整错误日志

FAILURE: Build failed with an exception.

* What went wrong:
A problem occurred configuring root project 'acme-pay-core-service'.
> Could not resolve all artifacts for configuration ':classpath'.
   > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE.
     Required by:
         project :
      > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE.
         > Could not get resource 'https://nexus-revamp.acmecompany.cloud/repository/acme-pay-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'.
            > Could not GET 'https://nexus-revamp.acmecompany.cloud/repository/acme-pay-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'.
               > sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
      > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE.
         > Could not get resource 'https://nexus-revamp.acmecompany.cloud/repository/acme-agent-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'.
            > Could not GET 'https://nexus-revamp.acmecompany.cloud/repository/acme-agent-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'.
               > sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
      > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE.
         > Could not get resource 'https://nexus-revamp.acmecompany.cloud/repository/acme-customer-releases/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'.
            > Could not GET 'https://nexus-revamp.acmecompany.cloud/repository/acme-customer-releases/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'.
               > sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
      > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE.
         > Could not get resource 'https://nexus-revamp.acmecompany.cloud/repository/acme-master-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'.
            > Could not GET 'https://nexus-revamp.acmecompany.cloud/repository/acme-master-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'.
               > sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
      > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE.
         > Could not get resource 'https://nexus-revamp.acmecompany.cloud/repository/acmecompany-commons/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'.
            > Could not GET 'https://nexus-revamp.acmecompany.cloud/repository/acmecompany-commons/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'.
               > sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

项目build.gradle文件

buildscript {
    repositories {
        maven {
            url readonlyRepoURL
        }

        maven {
            url readonlyAcmeSegmentRepoURL
        }

        maven {
            url readonlyAcmeSuiteRepoURL
        }

        mavenLocal()
    }
    dependencies {
        classpath("org.springframework.boot:spring-boot-gradle-plugin:${springBootVersion}")
    }
}

apply plugin: 'java'
apply plugin: 'org.springframework.boot'
apply plugin: 'io.spring.dependency-management'
apply plugin: 'eclipse'
apply plugin: 'idea'
 
group = 'com.acme.acmepay.config'
version = "${projectVersion}"
sourceCompatibility = "${projectSourceCompatibility}"

repositories {
    maven {
        url readonlyRepoURL
    }

    maven {
        url readonlyAcmeSegmentRepoURL
    }

    maven {
        url readonlyAcmeSuiteRepoURL
    }
    
    mavenLocal()
}

dependencyManagement {
    imports {
        mavenBom "org.springframework.cloud:spring-cloud-dependencies:Hoxton.RELEASE"
    }
}

dependencies {

    
    compile fileTree(dir: 'libs', include: '*.jar')
    compile ("com.acmecompany.segment:rule-service:${AcmeSegmentApiDefinitionVersion}")
    compile ("com.acmecompany.suite:user-service:${AcmeSuiteApiDefinitionVersion}")
    compile ("com.acmecompany.acme-pay:acme-pay-api-definition:${apiDefinitionVersion}")

    compile ("io.grpc:grpc-netty:${grpcVersion}")
    compile "org.modelmapper:modelmapper:${modelMapperVersion}"

    compile 'org.springframework.boot:spring-boot-devtools'
    compile "net.logstash.logback:logstash-logback-encoder:5.1"
    compile 'org.springframework.boot:spring-boot-starter-webflux'
    compile 'org.projectreactor:reactor-spring:1.0.1.RELEASE'
    compile group: 'com.oracle.oci.sdk', name: 'oci-java-sdk-objectstorage', version: '1.15.4'
    compile group: 'com.oracle.oci.sdk', name: 'oci-java-sdk-identity', version: '1.15.4'
    compile group: 'commons-lang', name: 'commons-lang', version: '2.6'
    compile group: 'com.google.code.gson', name: 'gson', version: '2.8.5'
    compile group: 'org.springframework.integration', name: 'spring-integration-core', version: '5.3.1.RELEASE'
    compile group: 'org.springframework.integration', name: 'spring-integration-file', version: '5.3.1.RELEASE'
    compile group: 'org.springframework.integration', name: 'spring-integration-sftp', version: '5.3.1.RELEASE'
    compile group: 'org.apache.httpcomponents', name: 'httpclient', version:'4.5.12'
    compile 'io.micrometer:micrometer-registry-prometheus'
    compile group: 'org.springframework.boot', name: 'spring-boot-starter-actuator'
    compile group: 'com.sun.xml.messaging.saaj', name: 'saaj-impl', version: '1.5.1'
    compile group: 'io.github.lognet', name: 'grpc-spring-boot-starter', version: '4.0.0'
    compile group: 'com.acmecompany.commons', name: 'header-interceptor', version: "0.0.34"

    compile 'com.amazonaws:aws-java-sdk-s3:1.11.163'
    compile ("org.springframework.retry:spring-retry:1.2.5.RELEASE")
    implementation group: 'org.aspectj', name: 'aspectjweaver', version: '1.9.6'

    implementation "io.grpc:grpc-netty-shaded:${grpcVersion}"
    implementation "io.grpc:grpc-protobuf:${grpcVersion}"
    implementation "io.grpc:grpc-stub:${grpcVersion}"
    implementation "io.grpc:grpc-services:${grpcVersion}"
    implementation "ch.qos.logback.contrib:logback-json-classic:${logbackJsonVersion}"
    implementation "ch.qos.logback.contrib:logback-jackson:${logbackJsonVersion}"
    implementation 'jakarta.xml.ws:jakarta.xml.ws-api'

    implementation 'org.jetbrains:annotations:15.0'
    implementation "org.springframework.boot:spring-boot-starter-data-couchbase"
    implementation 'org.apache.kafka:kafka-streams'
    implementation 'org.springframework.kafka:spring-kafka'
    implementation 'org.springframework.integration:spring-integration-core'
    implementation "io.github.lognet:grpc-spring-boot-starter"
    implementation "org.springframework.boot:spring-boot-starter-security"
    
    //sleuth implementation for tracing
    
    compile group: 'org.springframework.cloud', name: 'spring-cloud-starter-sleuth'
    compile group: 'io.zipkin.brave', name: 'brave-instrumentation-grpc', version: '5.9.0'
    compile group: 'io.zipkin.brave', name: 'brave-instrumentation-messaging', version: '5.9.0'
    

    compileOnly 'org.projectlombok:lombok:1.18.8'
    annotationProcessor 'org.projectlombok:lombok:1.18.8'

    testCompile group: 'org.mockito', name: 'mockito-core', version: '2.23.4'
    testCompile group: 'com.openpojo', name: 'openpojo', version: '0.8.10'
    testCompile group: 'org.hamcrest', name: 'hamcrest-all', version: '1.3'

    testImplementation 'org.mockito:mockito-core:2.22.0'
    testImplementation 'org.powermock:powermock-core:1.7.4'
    testImplementation 'org.powermock:powermock-module-testng:1.7.4'
    testImplementation 'org.powermock:powermock-api-mockito2:1.7.4'
    testImplementation 'org.springframework.kafka:spring-kafka-test'
    testImplementation 'org.springframework.boot:spring-boot-starter-test'
    testImplementation 'org.springframework.integration:spring-integration-test'
}

configurations {
    runtime.exclude group: "org.slf4j", module: "slf4j-log4j12"
    compile.exclude group: "org.slf4j", module: "slf4j-log4j12"
}

项目gradle.properties文件

apiDefinitionVersion=0.0.324

projectVersion=latest
projectSourceCompatibility=1.8
logbackJsonVersion=0.1.5
grpcVersion=1.17.0
springAopVersion=2.1.1.RELEASE
springBootVersion=2.2.13.RELEASE
modelMapperVersion=2.3.2

readonlyRepoURL=https://nexus-revamp.acmecompany.cloud/repository/acme-pay-group/
readonlyAcmeSegmentRepoURL=https://nexus-revamp.acmecompany.cloud/repository/acmecompany-release/
readonlyAcmeSuiteRepoURL=https://nexus-revamp.acmecompany.cloud/repository/acme-suite-releases/user-service/

acmeSegmentApiDefinitionVersion = 0.0.66
readonlyAroMasterDefinitionVersion = 0.0.13
acmeSuiteApiDefinitionVersion = 1.0.48

解决建议

1. 导入公司Nexus证书到JDK信任库

  • 导出证书:浏览器打开https://nexus-revamp.acmecompany.cloud,找到证书导出选项(不同浏览器操作略有差异),保存为DER或PEM格式文件。
  • 执行导入命令:
    keytool -import -alias nexus-acme -keystore $JAVA_HOME/jre/lib/security/cacerts -file /path/to/your/certificate.cer
    
    默认信任库密码为changeit,如果使用IDE内置JDK,需找到对应JDK的cacerts文件路径后执行导入。

2. 配置Gradle信任证书

  • 修改项目根目录的gradle.properties,添加:
    systemProp.javax.net.ssl.trustStore=$JAVA_HOME/jre/lib/security/cacerts
    systemProp.javax.net.ssl.trustStorePassword=changeit
    
  • 或在build.gradle的maven仓库配置中单独指定信任库:
    maven {
        url readonlyRepoURL
        ssl {
            trustStore file("$JAVA_HOME/jre/lib/security/cacerts")
            trustStorePassword "changeit"
        }
    }
    
    所有用到的Nexus仓库都需要添加该ssl配置。

3. 检查代理配置

如果公司网络使用代理,确认Gradle代理配置是否正确,代理服务器的证书也需导入到信任库中,同时确保Nexus站点不在代理排除列表外。

4. 验证Nexus连接

用curl命令测试能否正常访问Nexus的POM地址:

curl -v https://nexus-revamp.acmecompany.cloud/repository/acme-pay-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom

如果curl也返回证书错误,说明是系统层面的信任问题,优先解决证书导入。

内容的提问来源于stack exchange,提问作者Gehan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 18:31:16