清除Gradle缓存后导入依赖遇PKIX证书路径错误求助
Gradle依赖导入PKIX证书错误解决建议
问题背景
执行rm -rf $HOME/.gradle/caches/清除Gradle缓存后,项目导入Gradle依赖失败,安装新版本Gradle后问题仍存在。核心错误片段:
sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
完整错误日志
FAILURE: Build failed with an exception. * What went wrong: A problem occurred configuring root project 'acme-pay-core-service'. > Could not resolve all artifacts for configuration ':classpath'. > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE. Required by: project : > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE. > Could not get resource 'https://nexus-revamp.acmecompany.cloud/repository/acme-pay-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'. > Could not GET 'https://nexus-revamp.acmecompany.cloud/repository/acme-pay-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'. > sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE. > Could not get resource 'https://nexus-revamp.acmecompany.cloud/repository/acme-agent-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'. > Could not GET 'https://nexus-revamp.acmecompany.cloud/repository/acme-agent-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'. > sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE. > Could not get resource 'https://nexus-revamp.acmecompany.cloud/repository/acme-customer-releases/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'. > Could not GET 'https://nexus-revamp.acmecompany.cloud/repository/acme-customer-releases/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'. > sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE. > Could not get resource 'https://nexus-revamp.acmecompany.cloud/repository/acme-master-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'. > Could not GET 'https://nexus-revamp.acmecompany.cloud/repository/acme-master-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'. > sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target > Could not resolve org.springframework.boot:spring-boot-gradle-plugin:2.2.13.RELEASE. > Could not get resource 'https://nexus-revamp.acmecompany.cloud/repository/acmecompany-commons/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'. > Could not GET 'https://nexus-revamp.acmecompany.cloud/repository/acmecompany-commons/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom'. > sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
项目build.gradle文件
buildscript { repositories { maven { url readonlyRepoURL } maven { url readonlyAcmeSegmentRepoURL } maven { url readonlyAcmeSuiteRepoURL } mavenLocal() } dependencies { classpath("org.springframework.boot:spring-boot-gradle-plugin:${springBootVersion}") } } apply plugin: 'java' apply plugin: 'org.springframework.boot' apply plugin: 'io.spring.dependency-management' apply plugin: 'eclipse' apply plugin: 'idea' group = 'com.acme.acmepay.config' version = "${projectVersion}" sourceCompatibility = "${projectSourceCompatibility}" repositories { maven { url readonlyRepoURL } maven { url readonlyAcmeSegmentRepoURL } maven { url readonlyAcmeSuiteRepoURL } mavenLocal() } dependencyManagement { imports { mavenBom "org.springframework.cloud:spring-cloud-dependencies:Hoxton.RELEASE" } } dependencies { compile fileTree(dir: 'libs', include: '*.jar') compile ("com.acmecompany.segment:rule-service:${AcmeSegmentApiDefinitionVersion}") compile ("com.acmecompany.suite:user-service:${AcmeSuiteApiDefinitionVersion}") compile ("com.acmecompany.acme-pay:acme-pay-api-definition:${apiDefinitionVersion}") compile ("io.grpc:grpc-netty:${grpcVersion}") compile "org.modelmapper:modelmapper:${modelMapperVersion}" compile 'org.springframework.boot:spring-boot-devtools' compile "net.logstash.logback:logstash-logback-encoder:5.1" compile 'org.springframework.boot:spring-boot-starter-webflux' compile 'org.projectreactor:reactor-spring:1.0.1.RELEASE' compile group: 'com.oracle.oci.sdk', name: 'oci-java-sdk-objectstorage', version: '1.15.4' compile group: 'com.oracle.oci.sdk', name: 'oci-java-sdk-identity', version: '1.15.4' compile group: 'commons-lang', name: 'commons-lang', version: '2.6' compile group: 'com.google.code.gson', name: 'gson', version: '2.8.5' compile group: 'org.springframework.integration', name: 'spring-integration-core', version: '5.3.1.RELEASE' compile group: 'org.springframework.integration', name: 'spring-integration-file', version: '5.3.1.RELEASE' compile group: 'org.springframework.integration', name: 'spring-integration-sftp', version: '5.3.1.RELEASE' compile group: 'org.apache.httpcomponents', name: 'httpclient', version:'4.5.12' compile 'io.micrometer:micrometer-registry-prometheus' compile group: 'org.springframework.boot', name: 'spring-boot-starter-actuator' compile group: 'com.sun.xml.messaging.saaj', name: 'saaj-impl', version: '1.5.1' compile group: 'io.github.lognet', name: 'grpc-spring-boot-starter', version: '4.0.0' compile group: 'com.acmecompany.commons', name: 'header-interceptor', version: "0.0.34" compile 'com.amazonaws:aws-java-sdk-s3:1.11.163' compile ("org.springframework.retry:spring-retry:1.2.5.RELEASE") implementation group: 'org.aspectj', name: 'aspectjweaver', version: '1.9.6' implementation "io.grpc:grpc-netty-shaded:${grpcVersion}" implementation "io.grpc:grpc-protobuf:${grpcVersion}" implementation "io.grpc:grpc-stub:${grpcVersion}" implementation "io.grpc:grpc-services:${grpcVersion}" implementation "ch.qos.logback.contrib:logback-json-classic:${logbackJsonVersion}" implementation "ch.qos.logback.contrib:logback-jackson:${logbackJsonVersion}" implementation 'jakarta.xml.ws:jakarta.xml.ws-api' implementation 'org.jetbrains:annotations:15.0' implementation "org.springframework.boot:spring-boot-starter-data-couchbase" implementation 'org.apache.kafka:kafka-streams' implementation 'org.springframework.kafka:spring-kafka' implementation 'org.springframework.integration:spring-integration-core' implementation "io.github.lognet:grpc-spring-boot-starter" implementation "org.springframework.boot:spring-boot-starter-security" //sleuth implementation for tracing compile group: 'org.springframework.cloud', name: 'spring-cloud-starter-sleuth' compile group: 'io.zipkin.brave', name: 'brave-instrumentation-grpc', version: '5.9.0' compile group: 'io.zipkin.brave', name: 'brave-instrumentation-messaging', version: '5.9.0' compileOnly 'org.projectlombok:lombok:1.18.8' annotationProcessor 'org.projectlombok:lombok:1.18.8' testCompile group: 'org.mockito', name: 'mockito-core', version: '2.23.4' testCompile group: 'com.openpojo', name: 'openpojo', version: '0.8.10' testCompile group: 'org.hamcrest', name: 'hamcrest-all', version: '1.3' testImplementation 'org.mockito:mockito-core:2.22.0' testImplementation 'org.powermock:powermock-core:1.7.4' testImplementation 'org.powermock:powermock-module-testng:1.7.4' testImplementation 'org.powermock:powermock-api-mockito2:1.7.4' testImplementation 'org.springframework.kafka:spring-kafka-test' testImplementation 'org.springframework.boot:spring-boot-starter-test' testImplementation 'org.springframework.integration:spring-integration-test' } configurations { runtime.exclude group: "org.slf4j", module: "slf4j-log4j12" compile.exclude group: "org.slf4j", module: "slf4j-log4j12" }
项目gradle.properties文件
apiDefinitionVersion=0.0.324 projectVersion=latest projectSourceCompatibility=1.8 logbackJsonVersion=0.1.5 grpcVersion=1.17.0 springAopVersion=2.1.1.RELEASE springBootVersion=2.2.13.RELEASE modelMapperVersion=2.3.2 readonlyRepoURL=https://nexus-revamp.acmecompany.cloud/repository/acme-pay-group/ readonlyAcmeSegmentRepoURL=https://nexus-revamp.acmecompany.cloud/repository/acmecompany-release/ readonlyAcmeSuiteRepoURL=https://nexus-revamp.acmecompany.cloud/repository/acme-suite-releases/user-service/ acmeSegmentApiDefinitionVersion = 0.0.66 readonlyAroMasterDefinitionVersion = 0.0.13 acmeSuiteApiDefinitionVersion = 1.0.48
解决建议
1. 导入公司Nexus证书到JDK信任库
- 导出证书:浏览器打开
https://nexus-revamp.acmecompany.cloud,找到证书导出选项(不同浏览器操作略有差异),保存为DER或PEM格式文件。 - 执行导入命令:
默认信任库密码为keytool -import -alias nexus-acme -keystore $JAVA_HOME/jre/lib/security/cacerts -file /path/to/your/certificate.cerchangeit,如果使用IDE内置JDK,需找到对应JDK的cacerts文件路径后执行导入。
2. 配置Gradle信任证书
- 修改项目根目录的
gradle.properties,添加:systemProp.javax.net.ssl.trustStore=$JAVA_HOME/jre/lib/security/cacerts systemProp.javax.net.ssl.trustStorePassword=changeit - 或在
build.gradle的maven仓库配置中单独指定信任库:
所有用到的Nexus仓库都需要添加该ssl配置。maven { url readonlyRepoURL ssl { trustStore file("$JAVA_HOME/jre/lib/security/cacerts") trustStorePassword "changeit" } }
3. 检查代理配置
如果公司网络使用代理,确认Gradle代理配置是否正确,代理服务器的证书也需导入到信任库中,同时确保Nexus站点不在代理排除列表外。
4. 验证Nexus连接
用curl命令测试能否正常访问Nexus的POM地址:
curl -v https://nexus-revamp.acmecompany.cloud/repository/acme-pay-group/org/springframework/boot/spring-boot-gradle-plugin/2.2.13.RELEASE/spring-boot-gradle-plugin-2.2.13.RELEASE.pom
如果curl也返回证书错误,说明是系统层面的信任问题,优先解决证书导入。
内容的提问来源于stack exchange,提问作者Gehan
相关产品推荐
相关产品推荐

