You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决Jenkins Artifactory插件的Conan SSL用户认证错误?

解决Jenkins流水线中Conan访问HTTPS Artifactory的SSL认证问题

针对你遇到的SSL证书验证失败问题,我会分别给出两种方案的实现方式,优先覆盖你需要的短期解决方案:

方案1:在流水线中禁用SSL验证(短期解决)

你可以通过两种方式在Jenkins Artifactory Conan客户端中禁用SSL验证:

方式1:使用client.remote.add的verifySsl参数

你的Jenkins Artifactory插件版本(v2.16.1)已经支持在添加远程仓库时指定verifySsl参数,直接修改流水线代码即可:

stage('Package and Publish') { 
    def artifactory_name = "MyCompanyArtifactory" 
    def artifactory_repo = "conan-local" 
    def server = Artifactory.server artifactory_name 
    def client = Artifactory.newConanClient() 
    // 添加remote时禁用SSL验证
    def serverName = client.remote.add server: server, repo: artifactory_repo, verifySsl: false 
    client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Debug") 
    client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Release") 
    String myCmd = "upload MyLib/* --all -r ${serverName} --confirm" 
    def bInfo = client.run(command: myCmd) 
    //server.publishBuildInfo bInfo 
}

方式2:直接执行conan remote add命令(兼容旧版本插件)

如果上述参数在你的环境中不生效,也可以绕过插件的remote.add方法,直接用client.run执行原生Conan命令来添加远程仓库并禁用SSL:

stage('Package and Publish') { 
    def artifactory_name = "MyCompanyArtifactory" 
    def artifactory_repo = "conan-local" 
    def server = Artifactory.server artifactory_name 
    def client = Artifactory.newConanClient() 
    // 自定义远程仓库名称
    def serverName = "MyConanRemote"
    // 手动执行conan remote add命令,末尾加False禁用SSL验证
    client.run(command: "remote add ${serverName} ${server.getUrl()}/api/conan/${artifactory_repo} False")
    // 添加用户(如果需要)
    client.run(command: "user ci-user -r ${serverName} -p <your-password>")
    client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Debug") 
    client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Release") 
    String myCmd = "upload MyLib/* --all -r ${serverName} --confirm" 
    def bInfo = client.run(command: myCmd) 
    //server.publishBuildInfo bInfo 
}

方案2:配置服务器证书到Conan工作区(长期解决方案)

这种方式更安全,需要将Artifactory的CA证书添加到Conan工作区的cacert.pem文件中,步骤如下:

1. 上传证书到Jenkins凭据

  • 导出Artifactory服务器的CA证书(.crt格式)
  • 登录Jenkins,进入凭据 > 系统 > 全局凭据,点击添加凭据
  • 选择Secret file类型,上传你的证书文件,设置一个凭据ID(比如artifactory-ca-cert)

2. 修改流水线代码添加证书

在流水线中引入凭据,并将证书内容追加到Conan的CA证书文件中:

stage('Package and Publish') { 
    def artifactory_name = "MyCompanyArtifactory" 
    def artifactory_repo = "conan-local" 
    def server = Artifactory.server artifactory_name 
    def client = Artifactory.newConanClient() 

    // 引入Jenkins中存储的证书文件
    withCredentials([file(credentialsId: 'artifactory-ca-cert', variable: 'ARTIFACTORY_CERT')]) {
        // 将证书追加到Conan的cacert.pem中
        sh "cat ${ARTIFACTORY_CERT} >> \$(conan config get cacert)"
    }

    def serverName = client.remote.add server: server, repo: artifactory_repo 
    client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Debug") 
    client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Release") 
    String myCmd = "upload MyLib/* --all -r ${serverName} --confirm" 
    def bInfo = client.run(command: myCmd) 
    //server.publishBuildInfo bInfo 
}

这样每次流水线运行时,都会自动将证书添加到当前工作区专属的Conan环境中,解决SSL验证问题。

内容的提问来源于stack exchange,提问作者Chris S.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:44:56