Git for Windows has its own trust store of trusted certificates which is normally located in the file
- Git for Windows <=1.9:
[Git installdir]incurl-ca-bundle.crt
(e.g., C:Program Files (x86)Gitincurl-ca-bundle.crt
; configured by the key http.sslCAinfo
in [Git installdir]etcgitconfig
).
- Git for Windows >= 2.0:
[Git installdir]mingwXXsslcertsca-bundle.crt
where XX
stands for 32
or 64
(e.g., C:Program FilesGitmingw64sslcertsca-bundle.crt
; configured by the key http.sslCAinfo
in git config, e.g. C:Program FilesGitetc
or your global/local config).
Disabling checking of certificates (e.g., by setting git config http.sslVerify false
) is not a good idea and might be extremely dangerous (as all security checks are disabled and MitM attacks are easily possible - depending where this is set it applies for all new https connections).
In order to add a certificate (may it be a self-signed one or another root certificate) to this trust store in order to automatically trust it, you have to perform the following steps (the first five steps are just to gather the certificate, this can also be done with your favorite browser, but might require different tasks):
Open the URL of the site in Microsoft Edge
Click on the lock symbol in the local bar and choose "Connection is safe" and then click on the certificate symbol.
(Optional) Select the certificate you want to trust on the certificate chain (third tab) and open it
Go to the second tab "Details"
Click on "Save to file", choose "Base64-encoded X.509 (.CER)" and save it with a unique name (remember that name; a name w/o spaces is recommended).
Now you have several options
- Use a separate certificate trust store which only contains your just downloaded cert, by executing
git config --global http.sslCAinfo "[yourfilename]"
in a cli shell in order to only use this certificate as the trust store.
- Use a separate certificate trust store which contains your just downloaded cert and all certificates from the git trust store, by appending all content from the system trust store file (path see above) and then execute
git config --global http.sslCAinfo "[yourfilename]"
in a cli shell in order to use this new trust store.
- Update the system certificate file, by appending the content of your just saved file to
[path-to-git-trust-store-crt-file]
(e.g. by type [yourfilename] >> [path-to-git-trust-store-crt-file]
in a cli shell running with administrative rights) OR using notepad (make a copy of the ca-bundle.crt file on desktop, append the content of the downlaoded .crt file and then copy it back). Disadvantage: changes might get overwritten on git update
Done. Now, this certificate is in the trust store of Git for Windows.
Recent versions of Git for Windows can use also Windows certificate store which might be more convenient in a corporate environment. This can be configured on installation.
与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…