Azure DevOps代理执行git update-git-for-windows报curl 60证书错误
Git for Windows升级报SSL证书自签名错误解决方案
问题场景
在Azure DevOps代理的Windows服务器上执行git update-git-for-windows命令升级Git版本时,返回如下报错:
PS C:\Program Files\Git> git update-git-for-windows curl: (60) SSL certificate problem: self signed certificate in certificate chain curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. PS C:\Program Files\Git> git update-git-for-windows curl: (60) SSL certificate problem: self signed certificate in certificate chain curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it.
已执行配置
已提前在Git配置文件中添加自定义根证书路径,配置如下:
[user] name = tfsbuild email = tfsbuild@XXX [http] sslCAInfo = C:/Users/tfsbuild/RootCA.crt
问题根因
git update-git-for-windows命令的升级逻辑底层直接调用独立curl程序发起网络请求,不会读取Git配置文件中的http.sslCAInfo参数,因此单独配置Git的证书路径无法解决该场景下的SSL校验报错。
解决方案
按以下步骤操作即可解决:
- 打开Windows用户环境变量配置界面
- 新增名为
CURL_CA_BUNDLE的用户环境变量,变量值填写根证书的完整路径,本例为C:/Users/tfsbuild/RootCA.crt - 重启当前使用的PowerShell/命令行终端,重新执行
git update-git-for-windows命令即可正常完成升级
内容的提问来源于stack exchange,提问作者Shoshana Tzi
相关产品推荐
相关产品推荐

