You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jenkins运行Bitbucket仓库Pipeline出现issuer certificate错误如何解决

报错根因

"fatal: unable to access 'https://my.repos.example:***.git/': SSL certificate problem: unable to get local issuer certificate"
该错误是Jenkins节点上的git客户端拉取Bitbucket仓库代码时,无法验证Bitbucket服务端SSL证书的信任链,本地没有存储该证书对应的根颁发机构证书导致的。

修复方案

按安全性优先级排列如下:

方案1:导入Bitbucket证书到本地git信任库(生产环境推荐)

  • 第一步导出Bitbucket站点的完整证书链:
    openssl s_client -showcerts -connect my.repos.example:443 < /dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > bitbucket.crt
  • 第二步查看git系统级证书存储路径:
    git config --system http.sslCAInfo
  • 第三步将导出的bitbucket.crt内容追加到上一步返回的证书文件末尾即可全局生效
  • 若仅需要对当前Jenkins运行用户生效,可单独配置对应域名的信任证书:
    git config --global http."https://my.repos.example/".sslCAInfo /path/to/bitbucket.crt

方案2:指定Pipeline拉取代码时携带证书参数

如果使用Jenkins官方Git插件拉取代码,可以在checkout步骤的CloneOption中传入证书配置:

checkout([
  $class: 'GitSCM',
  branches: [[name: '你需要拉取的分支名']],
  userRemoteConfigs: [[
    url: '你的Bitbucket仓库地址',
    credentialsId: 'Jenkins中存储的Bitbucket访问凭证ID',
    extensions: [[
      $class: 'CloneOption',
      extraArgs: '--config http.sslCAInfo=/path/on/jenkins/node/to/bitbucket.crt'
    ]]
  ]]
])

方案3:关闭对应域名的SSL校验(仅临时测试使用,不建议生产环境配置)

如果只是临时测试验证问题,可以单独关闭该Bitbucket域名的SSL证书校验:
git config --global http."https://my.repos.example/".sslVerify false
测试完成后建议立刻改回true,避免产生安全漏洞。

内容的提问来源于stack exchange,提问作者Vitaliy Kuzmenko

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.30 19:48:00