# SSL Conflict Issue on Jenkins for Gitlab Repo

**URL:** <https://community.jenkins.io/t/ssl-conflict-issue-on-jenkins-for-gitlab-repo/26668>\
**Category:** Community\
**Tags:** pipeline\
**Created:** [February 6, 2025, 6:02pm UTC](https://community.jenkins.io/t/ssl-conflict-issue-on-jenkins-for-gitlab-repo/26668 "2025-02-06T18:02:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahuldhande](https://avatars.discourse-cdn.com/v4/letter/r/e47c2d/32.png) [@rahuldhande](https://community.jenkins.io/u/rahuldhande)\
**Post date:** [February 6, 2025, 6:02pm UTC](https://community.jenkins.io/t/ssl-conflict-issue-on-jenkins-for-gitlab-repo/26668/1 "2025-02-06T18:02:45Z")

</div>

Hello Team,

I’m facing the SSL Conflict Issue on Jenkins Pipeline Job while adding the Gitlab Repo. PFA attached the screenshot.

I’m able to use git commands lke git clone on Jenkins Server from console, but through pipline job it’s shows me SSL Error.

Jenkins is already configured to trust the self signed certificate i.e. The Gitlab Cert is already imported into both trustred toot directory and Java Keystore directory of Jenkins Server

/etc/pki/ca-trust/source/anchors/

sudo keytool -importcert -trustcacerts -keystore /usr/lib/jvm/java-11-openjdk/lib/security/cacerts -storepass changeit -noprompt -alias gitlab-cert -file /etc/pki/ca-trust/source/anchors/\<cert.pem\>

Add on, If I fire echo | openssl s\_client -connect [gitlab.yourdomain.com:443](http://gitlab.yourdomain.com:443) -showcerts on jenkins server console it shows me correct the gitlab cert But issue is still remain.

Looking forwared for your repsonce

Thanks

Rahul

 ![WhatsApp Image 2025-02-06 at 18.00.29_0bfaf078](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/0/04c64566d1a043dbdac638f7996b9b53b977290c.jpeg)

---

<div class="post-metadata">

**Author:** ![rahuldhande](https://avatars.discourse-cdn.com/v4/letter/r/e47c2d/32.png) [@rahuldhande](https://community.jenkins.io/u/rahuldhande)\
**Post date:** [February 7, 2025, 11:56am UTC](https://community.jenkins.io/t/ssl-conflict-issue-on-jenkins-for-gitlab-repo/26668/2 "2025-02-07T11:56:12Z")

</div>

@poddingue Any Thoughts? Thanks.

---

<div class="post-metadata">

**Author:** ![poddingue](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/poddingue/32/985_2.png) [@poddingue](https://community.jenkins.io/u/poddingue)\
**Post date:** [July 9, 2025, 9:04am UTC](https://community.jenkins.io/t/ssl-conflict-issue-on-jenkins-for-gitlab-repo/26668/3 "2025-07-09T09:04:36Z")

</div>

You’re encountering a common Jenkins issue when SSL certificates aren’t trusted inside the Jenkins runtime, even though they work fine in your shell. Here’s a focused step-by-step approach to fix it:

* * *

### ✅ **1. Identify the Java runtime used by Jenkins**

Jenkins runs under its own Java installation, which might differ from your local one.

- Navigate to:  
**`Manage Jenkins → System Information`**
- Look for the value of `java.home`
- Example: `/usr/lib/jvm/java-17-openjdk`

You must import the SSL certificate into **this** Java runtime’s trust store.

* * *

### ✅ **2. Import your certificate into the correct Java keystore**

Suppose your certificate file is `gitlab.yourdomain.com.crt`. Run:

```bash
sudo keytool -importcert -trustcacerts -alias gitlab-cert \
  -file gitlab.yourdomain.com.crt \
  -keystore /usr/lib/jvm/java-17-openjdk/lib/security/cacerts \
  -storepass changeit

```

> Replace the `-keystore` path with the actual `java.home` path from Jenkins, plus `/lib/security/cacerts`.

* * *

### ✅ **3. Restart Jenkins**

After importing the cert, restart Jenkins to pick up the updated trust store:

```bash
sudo systemctl restart jenkins

```

* * *

### ✅ **4. If your pipeline runs on agents (that’s the way to go) or Docker containers**

You must repeat step 2 on **every agent** that runs jobs:

- For physical/VM agents: check their Java install and keystore
- For Docker agents: bake the cert into the Docker image or mount it at runtime and import it during startup

> Tip: In Docker-based builds, you can add trusted certs under `/usr/local/share/ca-certificates/` and run `update-ca-certificates`.

* * *

### 🔄 **5. For debugging only: temporarily disable SSL verification**

You can bypass SSL verification using:

```groovy
environment {
  GIT_SSL_NO_VERIFY = 'true'
}

```

Or:

```groovy
withEnv(["GIT_SSL_NO_VERIFY=true"]) {
  git url: 'https://your-git-server', credentialsId: 'creds-id'
}

```

⚠ **This is not secure** , and should only be used for diagnosis, not in production.

* * *

### ✅ **6. Validate in Jenkins logs**

If the error persists, check:

- Jenkins logs: `Manage Jenkins → System Log`
- Console output of the failed build
- Agent logs (if applicable)

* * *

### ✅ Summary

| Step | Action |
| --- | --- |
| 🔍 1 | Identify `java.home` from Jenkins system info |
| 🔐 2 | Import cert into that Java keystore (`cacerts`) |
| 🔁 3 | Restart Jenkins |
| 🧑‍🤝‍🧑 4 | Repeat on agents or update Docker image |
| ⚠ 5 | Use `GIT_SSL_NO_VERIFY=true` only for testing |
