【问题标题】:Cannot install anything with brew, Error: Failed to download resource "git--html"无法使用 brew 安装任何东西,错误:无法下载资源“git--html”
【发布时间】:2020-11-27 01:38:58
【问题描述】:

每当我尝试运行brew install <app>,例如brew install git,我都会收到以下错误:

$ brew install git
Updating Homebrew...
Warning: You are using macOS 10.10.
We (and Apple) do not provide support for this old version.
You will encounter build failures with some formulae.
Please create pull requests instead of asking for help on Homebrew's GitHub,
Discourse, Twitter or IRC. You are responsible for resolving any issues you
experience while you are running this old version.

==> Downloading https://ftp.gnu.org/gnu/gettext/gettext-0.21.tar.xz
Already downloaded: /Users/admin/Library/Caches/Homebrew/downloads/fbd8967fd8256b2e1856b74e8ff0f3d8371cb652c5768e47649613a69d4dc841--gettext-0.21.tar.xz
==> Downloading https://ftp.pcre.org/pub/pcre/pcre2-10.35.tar.bz2
Already downloaded: /Users/admin/Library/Caches/Homebrew/downloads/48997c77a7dae2fb85d52234e92e9032019609e091e23d72529d1e552978a260--pcre2-10.35.tar.bz2
==> Downloading https://mirrors.edge.kernel.org/pub/software/scm/git/git-htmldoc

curl: (60) SSL certificate problem: Invalid certificate chain
More details here: http://curl.haxx.se/docs/sslcerts.html

curl performs SSL certificate verification by default, using a "bundle"
 of Certificate Authority (CA) public keys (CA certs). If the default
 bundle file isn't adequate, you can specify an alternate file
 using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
 the bundle, the certificate verification probably failed due to a
 problem with the certificate (it might be expired, or the name might
 not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
 the -k (or --insecure) option.
Error: Failed to download resource "git--html"
Download failed: https://mirrors.edge.kernel.org/pub/software/scm/git/git-htmldocs-2.28.0.tar.xz
Warning: You are using macOS 10.10.
We (and Apple) do not provide support for this old version.
You will encounter build failures with some formulae.
Please create pull requests instead of asking for help on Homebrew's GitHub,
Discourse, Twitter or IRC. You are responsible for resolving any issues you
experience while you are running this old version.

==> Downloading https://ftp.gnu.org/gnu/gettext/gettext-0.21.tar.xz
Already downloaded: /Users/admin/Library/Caches/Homebrew/downloads/fbd8967fd8256b2e1856b74e8ff0f3d8371cb652c5768e47649613a69d4dc841--gettext-0.21.tar.xz
==> Downloading https://ftp.pcre.org/pub/pcre/pcre2-10.35.tar.bz2
Already downloaded: /Users/admin/Library/Caches/Homebrew/downloads/48997c77a7dae2fb85d52234e92e9032019609e091e23d72529d1e552978a260--pcre2-10.35.tar.bz2
==> Downloading https://mirrors.edge.kernel.org/pub/software/scm/git/git-htmldoc

curl: (60) SSL certificate problem: Invalid certificate chain
More details here: http://curl.haxx.se/docs/sslcerts.html

curl performs SSL certificate verification by default, using a "bundle"
 of Certificate Authority (CA) public keys (CA certs). If the default
 bundle file isn't adequate, you can specify an alternate file
 using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
 the bundle, the certificate verification probably failed due to a
 problem with the certificate (it might be expired, or the name might
 not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
 the -k (or --insecure) option.
Error: Failed to download resource "git--html"
Download failed: https://mirrors.edge.kernel.org/pub/software/scm/git/git-htmldocs-2.28.0.tar.xz

我已经尝试了this post 的答案,但没有运气。我也不喜欢使用 curl 的 -k 或 --insecure

我正在使用

  • OSX 优胜美地 10.10.5
  • 自制 2.4.9
  • rvm 1.29.10
  • 红宝石 2.0.0

更新:我尝试卸载并重新安装自制软件,并在重新安装时再次收到此消息:

curl: (60) SSL certificate problem: Invalid certificate chain
More details here: http://curl.haxx.se/docs/sslcerts.html

curl performs SSL certificate verification by default, using a "bundle"
 of Certificate Authority (CA) public keys (CA certs). If the default
 bundle file isn't adequate, you can specify an alternate file
 using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
 the bundle, the certificate verification probably failed due to a
 problem with the certificate (it might be expired, or the name might
 not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
 the -k (or --insecure) option.
Error: Failed to download resource "git--html"
Download failed: https://mirrors.edge.kernel.org/pub/software/scm/git/git-htmldocs-2.28.0.tar.xz

更新 2: 当我运行 brew doctor 时,我得到了一个不合理的冗长 list of unexpected header files。这些和我的问题有关吗?如果是这样,删除所有这些的最佳方法是什么?

更新 3: 我最终求助于使用 curl 的 -k。唯一的麻烦是,当我这样做时,终端给了我hundreds of lines 似乎是随机字符作为回报。有谁知道这是什么?不知道在这里做什么

更新 4: 不确定这是否相关,但当我尝试安装 ruby​​ 2.3 时,出现此错误:

Error running '__rvm_make -j4',
please read /Users/admin/.rvm/log/1596996566_ruby-2.3.8/make.log

This 是日志

【问题讨论】:

  • 我面临同样的错误
  • @developerme 当您运行“brew doctor”时,您是否还有很多未扩展的头文件?
  • 在通过 brew 安装 ffmpeg 时出现错误“无法下载资源“jemalloc_bottle_manifest”。有什么建议吗?非常感谢。

标签: curl openssl ssl-certificate homebrew osx-yosemite


【解决方案1】:

我在 git--html 下载时也遇到了一些问题 (10.11)。如果你打开 finder 并点击 command + shift + G 并输入 /usr/local/cellar 你会希望找到你的包的文件夹。之后找到 bin 文件夹并在 bin 文件夹中启动可执行文件(它将具有终端图标)。 What it should look like (bin folder inside 1.3.5 folder)

【讨论】:

  • 我的包文件夹是什么意思?
  • 包的文件夹是指 homebrew 放在您的光盘上的文件夹,其中包含您下载的所有内容。
【解决方案2】:

看起来下载器(在这种情况下是 curl 版本)不信任 https://mirrors.edge.kernel.org 域上的 CA 证书。您可以尝试导入此网络服务器提供的 CA(取决于您是否真的信任 CA)。

要导入证书,您可以下载证书,然后双击证书。 MacOS 默认会通过 Keychain 打开它并询问您是否要导入它。这个可以参考official docs

wget http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt

注意

如果您在任何其他域中遇到此问题,您如何知道从哪里下载证书。

您可以查看服务器颁发的证书以获取上述链接。例如:

$ echo | openssl s_client -connect mirrors.edge.kernel.org:443 2>/dev/null \
  | openssl x509 -noout -text | grep "CA Issuers"

 CA Issuers - URI:http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt

PS:我无法让我的 -ext 标志在 libressl 上工作,因此是 hacky grep

注意网址。这是您需要信任的证书的位置,以便信任 brew 安装。此 URL 很可能出现在证书的 Authority Information Access 部分中。

【讨论】:

  • 我做错了吗?未获得链接:Error: Failed to download resource "git--html" Download failed: https://mirrors.edge.kernel.org/pub/software/scm/git/git-htmldocs-2.28.0.tar.xz KariHeitadsiMac:~ admin$ echo | openssl s_client -connect https://mirrors.edge.kernel.org/pub/software/scm/git/git-htmldocs-2.28.0.tar.xz:443 2>/dev/null | openssl x509 -noout -text | grep "CA Issuers" unable to load certificate 25008:error:0906D06C:PEM routines:PEM_read_bio:no start line:/SourceCache/OpenSSL098/OpenSSL098-52.40.1/src/crypto/pem/pem_lib.c:648:Expecting: TRUSTED CERTIFICATE
  • 是的,你的 openssl 命令有完整的 URL。你只需要主机名。openssl s_client -connect mirrors.edge.kernel.org:443
  • 要添加到此评论中,在我下载证书后,使用“open certfile.ext”打开它并将其作为系统证书添加到密钥库(假设 mac 自制软件),我还必须打开信任存储中的证书并选择“始终信任”。这解决了它(对我来说是 El Capitan)。无需注销/登录。此外,请避免使用下面的 .curlrc 答案,尽管知道它的存在很酷,但它会跳过作为信任基础的 TLS 证书链验证。
【解决方案3】:

对于在此处尝试了这两个答案但无济于事的任何人(如我),我找到了解决烦人的curl (60) 问题的解决方法。运行以下命令:

  • MacBook:~ leetbacoon$ nano ~/.curlrc
  • 在单独的行中添加-k(我没有.curlrc 文件,所以整个文件只是-k 加上换行符,当然)
  • 运行您的 brew install/upgrade,它应该从 mirrors.edge.kernel.org 或任何其他存在 SSL 证书问题的站点下载

curl 默认从~/.curlrc 读取配置文件。 -k 指示 curl 忽略 SSL 证书问题,这是我们在这种情况下想要的。我建议之后从你的配置文件中删除-k

我的设置是使用 El Capitan 10.11.6 / Homebrew 2.5.2 / ruby​​ 2.0.0p648 但没有rvm。巧合的是,我也在尝试安装git,结果遇到了这个问题。

【讨论】:

    猜你喜欢
    • 2021-05-02
    • 1970-01-01
    • 2019-07-19
    • 2019-06-29
    • 2014-06-08
    • 1970-01-01
    • 1970-01-01
    • 2013-06-29
    • 1970-01-01
    相关资源
    最近更新 更多