Jenkins中Maven从Nexus拉取依赖时遇SSL peer shut down incorrectly错误
Yep, I’ve run into this exact kind of SSL head-scratcher before—super frustrating when the cert checks out but the connection still dies mid-handshake. Let’s walk through the most likely fixes based on what I’ve debugged in similar scenarios:
1. Fix TLS Version Mismatch
More often than not, this boils down to a TLS version mismatch between your Jenkins JVM and the Nexus server. Older JDKs (pre-8u161) might default to disabled TLS 1.2/1.3, while modern Nexus instances usually block older, insecure TLS versions.
Quick fix: Add TLS protocol flags to your Maven execution. You can set this in Jenkins’ global MAVEN_OPTS or directly in your build step:
export MAVEN_OPTS="-Dhttps.protocols=TLSv1.2,TLSv1.3"
Or update your Jenkins JVM arguments (in Jenkins > Manage Jenkins > Configure System) to enforce these TLS versions globally.
2. Rule Out Network/Proxy Interruptions
Even if your local OpenSSL test works, Jenkins might be routing through a different proxy or hitting a firewall that’s messing with the SSL handshake (deep packet inspection tools often cause this).
Checks to run:
- SSH into your Jenkins server and run a direct download test with
curlorwgetto confirm connectivity:curl -O https://nexus.tech/nexus/content/repositories/thirdparty/com/sap/hybris/hybris-commerce-suite/6.6.0.1/hybris-commerce-suite-6.6.0.1.zip - Verify your Maven
settings.xml(either global in Jenkins or project-specific) has the correct proxy configuration—including any required authentication for HTTPS connections.
3. Clean Maven Cache & Fix Repository Config
Corrupted local cache or misconfigured repository settings can cause the BasicRepositoryConnector to fail unexpectedly.
Steps:
- Delete the cached dependency directory from your Maven local repo:
rm -rf ~/.m2/repository/com/sap/hybris/hybris-commerce-suite/6.6.0.1 - Double-check your Nexus server credentials in
settings.xml(if your repo requires auth):
Ensure the<servers> <server> <id>thirdparty</id> <username>your-nexus-username</username> <password>your-nexus-password</password> </server> </servers><id>matches the repository ID in yourpom.xml.
4. Verify JDK Certificate Store
OpenSSL uses your system’s certificate store, but Java uses its own cacerts file—even valid Amazon certs might be missing from Jenkins’ JDK truststore.
Fix:
- Export Nexus’ full certificate chain using OpenSSL:
openssl s_client -connect nexus.tech:443 -showcerts > nexus-cert-chain.crt - Import the chain into your Jenkins JVM’s
cacerts(default password ischangeit):keytool -importcert -file nexus-cert-chain.crt -keystore $JAVA_HOME/jre/lib/security/cacerts -alias nexus-repo - Restart Jenkins to apply the new certificate.
Start with the TLS version and curl test—those are usually the quickest wins. If none of these work, check Nexus logs for any handshake errors on the server side too.
内容的提问来源于stack exchange,提问作者David

