Clone/pull/push with ssh problem in gitlab (Error creating http client: cannot find cafile '': cafile not found)

Viewed 108

I've experiencing a new problem using the Gitlab. When I try to pull, push clone a gitlab repository or even directly test ssh connection (ssh mygitlabserver) I'm receiving the error message:

remote: Error creating http client: cannot find cafile '': cafile not found

I do not really understand what might going on in the background. No other user has the same problem and I'm experiencing it globally meaning no matter what machine I try.

Also the http clone, push is working fine. I've also tried git config --global http.sslverify false followed by 'export GIT_SSL_NO_VERIFY=true, but it had no effect. I was also did some experimenting with CI/CD integration.

Can someone knows how to debug or understand what might the problem be?

2 Answers

That is most likely a server-side error caused by a missing certificate file. Tracing back the error showed that the SSH connection is built up correctly using the SSH key set in Gitlab for this user. The output you see is generated by the forced command (that belongs to the key) which tries to open a gitlab-shell for this authenticated user:

/opt/gitlab/embedded/service/gitlab-shell/bin/gitlab-shell key-XXX

This process fails since it cannot create the HTTP client because of the missing certificate file.

In my case the solution to this error was to add the path of the certificate file directly to the gitlab.rb config file:

gitlab_shell['http_settings'] = { ca_file: '/path/to/cert.pem' }

Don't forget to run gitlab-ctl reconfigure to apply the changes.

For anyone not knowing which cert to use Gitlab comes with an embedded cacert file at /opt/gitlab/embedded/ssl/certs/cacert.pem:

gitlab_shell['http_settings'] = { ca_path: '/opt/gitlab/embedded/ssl/certs', ca_file: '/opt/gitlab/embedded/ssl/certs/cacert.pem' }

(using the embedded Gitlab cacert file).

After running gitlab-ctl reconfigure everything's fine again.

Related