CodeDeploy部署报错“PKCS7签名消息验证失败”求助
I’ve definitely encountered this odd issue before—your agent is on the latest stable version (1.0-1.1597) like you said, yet you’re getting an error that’s supposed to only affect pre-1.0.1.854 agents. Let’s go through some targeted fixes that have worked for me and others:
Check the CodeDeploy agent config file for forced SHA-1 usage
Sometimes even with a new agent, the config file might have been accidentally modified to restrict to SHA-1. On Linux, look at/etc/codedeploy-agent/conf/codedeployagent.yml; on Windows, checkC:\ProgramData\Amazon\CodeDeploy\conf\codedeployagent.yml. Look for a line likesha1_only: true—if it exists, change it tosha1_only: falseor delete it entirely, then restart the agent:# Linux sudo service codedeploy-agent restart# Windows Restart-Service codedeployagentVerify the instance's system certificate store
This error can also trigger if the instance can’t validate CodeDeploy’s signing certificates, even though it’s unrelated to agent version.- For Linux: Make sure the
ca-certificatespackage is up to date, then runsudo update-ca-certificatesto refresh the root certs. - For Windows: Check that your system’s root certificate store includes Amazon’s CA certificates, or run a system root cert update.
- For Linux: Make sure the
Test with a known-good deployment package
Even though your other project works, the current deployment package might have a signing anomaly. Try regenerating the package for the failing project, or use the package from your working project to test the failing pipeline. If this fixes it, the issue is likely in how your failing project’s package is being built—maybe a dependency tool auto-updated under the hood even if you didn’t make explicit changes.Dig into the agent’s detailed logs
The surface error doesn’t tell the whole story. Look for more context in the agent logs:- Linux:
/var/log/aws/codedeploy-agent/codedeploy-agent.log - Windows:
C:\ProgramData\Amazon\CodeDeploy\logs\codedeploy-agent.log
Search for "PKCS7" entries—they’ll often reveal the root cause, like a specific certificate that’s untrusted or a config misread.
- Linux:
Validate network connectivity to CodeDeploy services
If the instance can’t reach CodeDeploy’s signature validation endpoints, it might throw this error as a fallback. Test connectivity tocodedeploy.${your-region}.amazonaws.com(replace${your-region}with your actual AWS region):curl -I https://codedeploy.us-east-1.amazonaws.comIf this fails, check your security groups, NACLs, or any proxy settings to ensure the instance can communicate with CodeDeploy services.
内容的提问来源于stack exchange,提问作者yannis

