Invalid SSL certificate when pushing to Git server

爷,独闯天下 提交于 2019-12-17 05:50:31

问题


I am running Gitblit on a Windows Server and am trying to push data to a repository from another machine on the network. I have used a SSL certificate (not self signed, but I think signed by my company? Not really sure how that works but Chrome, IE, etc. see it is identity verified).

The server that runs Gitblit is named itscm and on the developer's desktop I am using this URL to push data via TortoiseGit:

git.exe push --progress  "https://itscm:8234/git/TestRepo.git" master

However, I get this error:

fatal: unable to access 'https://itscm:8234/git/TestRepo.git/': SSL certificate problem: self signed certificate in certificate chain

When I go to that address in chrome, I get a 404 on the page, BUT I can see that the padlock in the URL bar is green. When I click the padlock I see that the identity is verified. I don't understand how my browser sees this certificate as valid but when I try to push data to it via Git, it fails.


回答1:


Git for Windows has its own trust store of trusted certificates which is normally located in the file

  • Git for Windows <=1.9: [Git installdir]\bin\curl-ca-bundle.crt (e.g., C:\Program Files (x86)\Git\bin\curl-ca-bundle.crt; configured by the key http.sslCAinfo in [Git installdir]\etc\gitconfig).
  • Git for Windows >= 2.0: [Git installdir]\mingwXX\ssl\certs\ca-bundle.crt where XX stands for 32 or 64 (e.g., C:\Program Files\Git\mingw64\ssl\certs\ca-bundle.crt; configured by the key http.sslCAinfo in C:\ProgramData\Git\config).

Disabling checking of certificates (e.g., by setting git config http.sslVerify false) is not a good idea and might be extremely dangerous (as all security checks are disabled and MitM attacks are easily possible - depending where this is set it applies for all new https connections).

In order to add a certificate (may it be a self-signed one or another root certificate) to this trust store in order to automatically trust it, you have to perform the following steps:

  1. Open the URL of the site in Internet Explorer
  2. Click on the lock symbol in the local bar and choose "Show certificates" (or choose Properties of the site and click on "Certificates")
  3. (Optional) Select the certificate you want to trust on the certificate chain (third tab) and open it
  4. Go to the second tab "Details"
  5. Click on "Save to file", choose "Base64-encoded X.509 (.CER)" and save it with a unique name (remember that name; a name w/o spaces is recommended).
  6. Now you have several options

    1. Use a separate certificate trust store which only contains your just downloaded cert, by executing git config --global http.sslCAinfo "[yourfilename]" in a cli shell in order to only use this certificate as the trust store.
    2. Use a separate certificate trust store which contains your just downloaded cert and all certificates from the git trust store, by appending all content from the system trust store file (path see above) and then execute git config --global http.sslCAinfo "[yourfilename]" in a cli shell in order to use this new trust store.
    3. Update the system certificate file, by appending the content of your just saved file to [path-to-git-trust-store-crt-file] (e.g. by type [yourfilename] >> [path-to-git-trust-store-crt-file] in a cli shell running with administrative rights) OR using notepad (make a copy of the ca-bundle.crt file on desktop, append the content of the downlaoded .crt file and then copy it back). Disadvantage: changes might get overwritten on git update

Done. Now, this certificate is in the trust store of Git for Windows.




回答2:


TortoiseGit is probably not using the same truststore Chrome. I think Chrome uses the system store, Firefox uses it's own. I have no idea what TortoiseGit uses.

On the client, if you set git config http.sslVerify false you may have more luck. You can also set this globally.




回答3:


Here is what worked for me. Create a folder C:\GitCerts. Then download the Base64 .cer file (follow the answer provided by MrTux) to this C:\GitCerts folder.

  • From command line run the following command: git config --global http.sslCAinfo "C:\GitCerts\MyCert.cer"
  • Open the MyCert.cer file in Notepad and leave it open
  • Open the Git ca-bundle.crt file in another Notepad. Mine was in the location C:\Program Files\Git\mingw64\ssl\certs\ca-bundle.crt.
  • Verify the cert text in the MyCert.cer file is in the ca-bundle.crt file (it should be), if not just copy and paste all the text from MyCert.cer and append it at the bottom of the ca-bundle.crt file (make sure you leave all the other cert information in there).

-----BEGIN CERTIFICATE-----

your cert info here

-----END CERTIFICATE-----

  • If you had to modify the ca-bundle.crt file then save it (you may have to save it to your Desktop and then copy and paste it back in to overwrite the ca-bundle.crt file)
  • Finally, based on the path of your ca-bundle.crt file run the following command: git config --global http.sslcainfo "C:\Program Files\Git\mingw64\ssl\certs\ca-bundle.crt"



回答4:


For those in a corporates, who get the self signed certificate error - below is an alternative.

In corporates, the same git server, that is accessible over https protocol, usually will also be accessible over ssh protocol. So choose the ssh option of server url and clone the repository as

git clone user@server/project.git

Of course, the public key( id_rsa.pub ) from your ~\.ssh folder will have to added to server. This way you don't have add the https server certificate to your windows certificate store or mac keychain ( example ).




回答5:


I experienced this error using GitHub and it seemingly came out of nowhere. I had done plenty of work on GitHub before.

Kaspersky anti-virus was the culprit!!

When I turned off my anti-virus protection (and waited a couple of minutes) I was able to push / pull from my github repo.

My final solution was to locate a certificate from Kaspersky then add it to the Git for Windows trust store. The latter step is already detailed in the accepted answer, but for anyone else in a similar position I was able to locate the Kaspersky certificate by going to:

Settings > Additional > Network > Encrypted connections scanning - Advanced Settings > Install Certificate > Show Certificate > Details > Copy to File > Base-64 encoded X.509 (.cer)




回答6:


I found one more answer for this issue :

$ git config http.sslVerify false


来源:https://stackoverflow.com/questions/19413537/invalid-ssl-certificate-when-pushing-to-git-server

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!