<#23391 Coursier TLS errors with corp proxy for Re...
# github-notifications
q
#23391 Coursier TLS errors with corp proxy for Restricted Internet access Issue created by chris-smith-zocdoc Is your feature request related to a problem? Please describe. Coursier ships as a GraalVM native image that bundles its own trust store from build time. It does honor -J-Djavax.net.ssl.trustStore=... CLI flags (its Scala main() parses -J-D prefixed args and calls System.setProperty()) but currently Pants doesn't expose a way to set these extra CLI flags to coursier. https://get-coursier.io/docs/other-proxy Pants has
[jvm].global_options
but that only flows to java invocations, not to coursier. This means any environment with a custom proxy or CA (corporate TLS inspection proxies, mitmproxy, etc.) cannot use pants' JVM tooling — coursier fails with SSLHandshakeException: PKIX path building failed when fetching nailgun-server, JDKs, or any Maven artifact. Small reproduction here https://github.com/chris-smith-zocdoc/pants-mitm-issue/tree/cs_kotlin_issue Describe the solution you'd like Add a [coursier].jvm_options option (list of strings) that gets injected as CLI flags into: 1. COURSIER_FETCH_WRAPPER_SCRIPT — between "$coursier_exe" and fetch 2. Coursier.args() — between the exe path and subcommand args (for java-home calls) Values should be auto-prefixed with -J if not already present. Example config: [coursier] jvm_options = [ "-Djavax.net.ssl.trustStore=/etc/pki/ca-trust/extracted/java/cacerts", "-Djavax.net.ssl.trustStorePassword=changeit", ] Describe alternatives you've considered Pants has some other settings for the http proxy are are related and we might be able to autoconfigure something here, but I these settings are different enough I think its best to just expose them directly. https://www.pantsbuild.org/stable/docs/using-pants/restricted-internet-access#setting-http_proxy-and-https_proxy Additional context
Copy code
Resolution error: Error downloading com.google.guava:guava:33.4.0-jre
  download error: Caught javax.net.ssl.SSLHandshakeException (PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target) while downloading <https://maven-central.storage-download.googleapis.com/maven2/com/google/guava/guava/33.4.0-jre/guava-33.4.0-jre.pom>
  download error: Caught javax.net.ssl.SSLHandshakeException (PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target) while downloading <https://repo1.maven.org/maven2/com/google/guava/guava/33.4.0-jre/guava-33.4.0-jre.pom>
pantsbuild/pants