<#22727 CA bundle is not respected when downloadin...
# github-notifications
q
#22727 CA bundle is not respected when downloading pants PEX files Issue created by michailw Describe the bug Hi, I'm trying to bypass the following error while my traffic is being inspected through a firewall.
Copy code
$ pants update
Failed to determine release URL for Pants: 2.28.0: pants.2.28.0-cp311-darwin_arm64.pex: URL check failed: <https://github.com/pantsbuild/pants/releases/download/release_2.28.0/pants.2.28.0-cp311-darwin_arm64.pex>: <urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)>

If this is unexpected (you are using a known good Pants version), try upgrading scie-pants first.
It may also be that the platform darwin_arm64 isn't supported for this version of Pants, or some other intermittent network/service issue.
To get help, please visit: <https://www.pantsbuild.org/community/getting-help>
I have tried both: • setting the SSL_CERT_FILE env var:
Copy code
export SSL_CERT_FILE=path_to_ca_bundle_file.pem
• setting the
ca_certs_path
in
pants.toml
file:
Copy code
[GLOBAL]  
 pants_version = "2.28.0"  
 ca_certs_path = "path_to_ca_bundle_file.pem"
Unfortunately, any of these solutions don't work on my Mac. Pants version 2.28, installed through Homebrew, just like Python. OS MacOS Additional info I could bypass this by running the same command in a Docker container. Setting the
SSL_CERT_FILE
inside the Docker was enough to resolve the issue. pantsbuild/pants