You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地Azure DevOps(TFS)构建代理下载.NET Core SDK遇证书链错误

解决Azure DevOps本地代理下载.NET Core SDK时的自签名证书错误

问题描述

本地部署的Azure DevOps构建代理在下载.NET Core SDK(如6.0.401版本)时失败,报错self signed certificate in certificate chain,完整错误日志如下:

Starting: Use version 6.0.x of nuget
==============================================================================
Task         : Use .NET Core
Description  : Acquires a specific version of the .NET Core SDK from the internet or the local cache and adds it to the PATH. Use this task to change the version of .NET Core used in subsequent tasks. Additionally provides proxy support.
Version      : 2.184.0
Author       : Microsoft Corporation
Help         : https://aka.ms/AA4xgy0
==============================================================================
Tool to install: .NET Core sdk version 6.0.x.
Found version 6.0.401 in channel 6.0 for user specified version spec: 6.0.x
Version 6.0.401 was not found in cache.
Getting URL to download .NET Core sdk version: 6.0.401.
Detecting OS platform to find correct download package for the OS.
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoLogo -Sta -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -Command "& 'C:\AzureDevops\agent\_work\_tasks\UseDotNet_b0ce7256-7898-45d3-9cb5-176b752bfea6\2.184.0\externals\get-os-platform.ps1'"
Primary:win-x64
Detected platform (Primary): win-x64
Downloading: https://download.visualstudio.microsoft.com/download/pr/aa0b6cf3-c5dc-40ff-8b2f-f2970ca7b9e3/5b4a9999ea41ca5897e01a3e0e1accad/dotnet-sdk-6.0.401-win-x64.zip
##[error]Failed while installing version: 6.0.401 at path: C:\AzureDevops\agent\_work\_tool/dotnet with error: Could not download installation package from this URL: https://download.visualstudio.microsoft.com/download/pr/aa0b6cf3-c5dc-40ff-8b2f-f2970ca7b9e3/5b4a9999ea41ca5897e01a3e0e1accad/dotnet-sdk-6.0.401-win-x64.zip Error: Error: self signed certificate in certificate chain
Finishing: Use version 6.0.x of nuget

当前临时方案为手动下载SDK到代理缓存目录,但每次版本更新都需重复操作,以下是可行的长期解决配置:

解决方法

1. 导入企业自签名根证书到代理机器

这是最安全的方案,核心是让代理机器信任企业内网的自签名证书:

  • 打开mmc控制台,添加「证书」管理单元,选择「本地计算机」
  • 展开「受信任的根证书颁发机构」→「证书」,右键选择「所有任务」→「导入」
  • 导入企业内网的自签名根证书文件,完成后重启Azure DevOps代理服务

2. 配置Node.js环境变量跳过证书验证(应急方案)

由于Use .NET Core任务基于Node.js运行,可通过环境变量临时跳过证书验证:

  • 打开代理机器的「系统属性」→「环境变量」,添加系统环境变量:
    • 变量名:NODE_TLS_REJECT_UNAUTHORIZED
    • 变量值:0
  • 重启Azure DevOps代理服务
  • 注意:此方法会降低安全性,仅建议在测试环境使用

3. 配置代理使用企业证书及代理参数

如果代理通过企业HTTP代理访问外网,需完成以下配置:

  • 添加系统环境变量DOTNET_SYSTEM_NET_HTTP_USESOCKETSHTTPHANDLER=0,确保.NET使用传统HTTP处理器,从而读取系统证书存储
  • 重新配置Azure DevOps代理,添加代理参数:
    .\config.cmd --proxyurl http://your-enterprise-proxy:port --proxyusername proxy-user --proxypassword proxy-pass
    
  • 或者直接修改代理目录下的.agent配置文件,更新proxyurl、proxyusername、proxypassword字段,然后重启代理

4. 自动化预缓存SDK版本(优化手动方案)

若无法修改证书或代理配置,可通过脚本自动化缓存更新:

  • 编写PowerShell脚本,定期拉取微软.NET SDK版本列表,自动下载对应版本的SDK压缩包
  • 将下载的SDK解压到代理缓存目录C:\AzureDevops\agent\_work\_tool\dotnet\sdk\{版本号}下
  • 设置Windows任务计划,定期执行该脚本,实现自动更新缓存

内容的提问来源于stack exchange,提问作者xszaboj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 11:55:23