homebrew换源后“证书过期”错误实为git ssl校验误判let's encrypt证书链,主因是macos自带旧版git及openssl支持不全;正确解法是安装homebrew版git、确保其优先调用,并更新ca-certificates。
homebrew 换源后提示“证书过期”,常见于执行 brew update 或安装命令时出现类似错误:
curl: (60) SSL certificate problem: certificate has expired
或fatal: unable to access 'https://mirrors.tuna.tsinghua.edu.cn/git/homebrew/brew.git/': server certificate verification failed
这不是你本地系统时间错了,也不是清华镜像站真的停运了——而是 Homebrew 内部使用的 Git 证书验证机制,误判了镜像站所用的 Let's Encrypt 证书链(尤其在 macOS 系统自带 Git 版本较旧、或 OpenSSL 未及时更新时)。
检查是否真为证书问题
先快速确认是不是证书导致的:运行
git -C "$(brew --repo)" ls-remote origin >/dev/null
如果报错含 SSL certificate problem 或 certificate has expired,基本就是证书校验失败。若提示 Could not resolve host,则是 DNS 或网络问题,和证书无关。
临时绕过证书验证(仅限排查)
不推荐长期使用,但可快速验证是否为证书阻断:
- 执行:
git config --global http.sslVerify false - 再试
brew update - 若成功,说明确实是 SSL 校验环节卡住
✅ 验证后请立即恢复:git config --global http.sslVerify true
正确修复方式:更新 Git 并刷新证书信任链
macOS 自带 Git(通常位于 /usr/bin/git)依赖系统 OpenSSL,而旧版 OpenSSL 对新 Let's Encrypt 中间证书支持不全。解决路径是:
- 用 Homebrew 安装新版 Git:
brew install git(若尚未安装) - 确保终端默认调用的是 Homebrew 版 Git:
which git应返回/opt/homebrew/bin/git(Apple Silicon)或/usr/local/bin/git(Intel) - 如未生效,把 Homebrew 的 bin 目录加到
PATH前置位(检查echo $PATH,确认/opt/homebrew/bin在/usr/bin之前) - 更新证书包:
brew install ca-certificates && brew link --force ca-certificates
清华源配置本身也要核对
证书错误有时会掩盖真正的配置错误。请确认你已完整设置以下两个仓库地址:
- 主仓库(brew):
git -C "$(brew --repo)" remote set-url origin https://mirrors.tuna.tsinghua.edu.cn/git/homebrew/brew.git - 核心公式库(core):
git -C "$(brew --repo homebrew/core)" remote set-url origin https://mirrors.tuna.tsinghua.edu.cn/git/homebrew/homebrew-core.git
注意:URL 必须是 https 开头,且域名是 mirrors.tuna.tsinghua.edu.cn,不是 github.com 或其他变体。
做完上述操作后,执行 brew update。多数情况下,证书报错会消失。如果仍有问题,大概率是系统级代理或环境变量干扰(比如设置了 HTTP_PROXY 却无法访问镜像站),可临时清空代理测试:unset HTTP_PROXY HTTPS_PROXY。











