使用HTTP SonarQube服务器时如何禁用sonar-cxx插件的SSL?
问题
我分别在Docker容器中运行SonarScanner CLI和SonarQube,环境信息如下:
- SonarQube:免费版,Docker镜像版本26.3.0.120487,部署在HTTP(非HTTPS)地址
- sonar-cxx插件:v2.2.2
- SonarScanner:v12.1
启动代码分析时,社区C++插件(sonar-cxx)导致扫描器崩溃。插件尝试初始化SSL上下文以从服务器下载规则,但提示找不到扫描器容器中的密钥库路径,尽管该路径实际存在。错误日志如下:
09:00:49.879 INFO trust store based on javax.net.ssl not loadable: The value for the system property [javax.net.ssl.keyStore] is absent 09:00:49.892 ERROR Error during SonarScanner Engine execution nl.altindag.ssl.exception.GenericKeyStoreException: java.lang.IllegalArgumentException: Failed to load the keystore from the classpath for the given path: [/usr/lib/jvm/java-21-amazon-corretto.x86_64/lib/security/cacerts] at nl.altindag.ssl.util.KeyStoreUtils.loadKeyStore(KeyStoreUtils.java:91) at nl.altindag.ssl.SSLFactory$Builder.withTrustMaterial(SSLFactory.java:308) at org.sonar.cxx.sensors.utils.SSLContextBuilder.createSSLContext(SSLContextBuilder.java:107) at org.sonar.cxx.sensors.utils.SonarServerWebApi.setServerConfig(SonarServerWebApi.java:174) at org.sonar.cxx.sensors.utils.CxxIssuesReportSensor.downloadRulesFromServer(CxxIssuesReportSensor.java:95) at org.sonar.cxx.sensors.utils.CxxIssuesReportSensor.executeImpl(CxxIssuesReportSensor.java:84) at org.sonar.cxx.sensors.utils.CxxReportSensor.execute(CxxReportSensor.java:101) ... Caused by: java.lang.IllegalArgumentException: Failed to load the keystore from the classpath for the given path: [/usr/lib/jvm/java-21-amazon-corretto.x86_64/lib/security/cacerts] at nl.altindag.ssl.util.internal.ValidationUtils.requireNotNull(ValidationUtils.java:41) at nl.altindag.ssl.util.KeyStoreUtils.loadKeyStore(KeyStoreUtils.java:88) ... 26 common frames omitted
我的sonar.host.url设置为http://<hostname>:9000,不需要SSL验证。尝试过在Dockerfile中更换Java版本、修改SONAR_SCANNER_OPTS指定密钥库路径,但都没解决问题。想知道:
- 是否可以通过
sonar-project.properties或SONAR_SCANNER_OPTS添加特定属性,完全禁用sonar-cxx插件的SSL上下文初始化? - 是否必须将SonarQube服务器转为HTTPS?
解决方案
1. 禁用sonar-cxx插件的SSL验证(推荐)
sonar-cxx插件提供了专门的配置项来跳过SSL验证,即使服务器用HTTP也能避免插件强制初始化SSL上下文:
- 在
sonar-project.properties中添加:sonar.cxx.ssl.skipVerification=true - 或者通过
SONAR_SCANNER_OPTS传递系统属性:SONAR_SCANNER_OPTS="-Dsonar.cxx.ssl.skipVerification=true" sonar-scanner
这个配置会让插件跳过所有SSL相关的验证逻辑,包括密钥库加载,完美适配HTTP服务器场景。
2. 检查密钥库权限与路径
如果不想禁用SSL验证,可确认扫描器容器中目标密钥库的权限:
- 确保SonarScanner运行用户有该文件的读取权限,可在Dockerfile中添加:
RUN chmod 644 /usr/lib/jvm/java-21-amazon-corretto.x86_64/lib/security/cacerts - 也可以通过
SONAR_SCANNER_OPTS显式指定密钥库路径和默认密码(changeit):SONAR_SCANNER_OPTS="-Djavax.net.ssl.trustStore=/usr/lib/jvm/java-21-amazon-corretto.x86_64/lib/security/cacerts -Djavax.net.ssl.trustStorePassword=changeit" sonar-scanner
3. 无需强制转为HTTPS
你的场景下服务器用HTTP完全可行,不需要为了适配插件特意切换到HTTPS,优先尝试上面两种方法即可。
内容的提问来源于stack exchange,提问作者Etienne
相关产品推荐
相关产品推荐

