# Allow Autosigned https certificate on Maven plugin

**URL:** https://community.sonatype.com/t/allow-autosigned-https-certificate-on-maven-plugin/9183
**Category:** Sonatype Lifecycle & Firewall
**Tags:** maven
**Created:** [August 23, 2022, 7:53am UTC](https://community.sonatype.com/t/allow-autosigned-https-certificate-on-maven-plugin/9183 "2022-08-23T07:53:45Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![c.tixier](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@c.tixier](https://community.sonatype.com/u/c.tixier)
#### Post date: [August 23, 2022, 7:53am UTC](https://community.sonatype.com/t/allow-autosigned-https-certificate-on-maven-plugin/9183/1 "2022-08-23T07:53:46Z")

</div>

Hello,  
We have a test instance for lifecycle with an autosigned certificate.  
I try to launch maven plugin on a my projet and i can’t avoid the certificate check with -Dmaven.wagon.http.ssl.insecure=true option

> mvn clean install com.sonatype.clm:clm-maven-plugin:evaluate -Dclm.serverUrl=[https://myServer](https://myServer) -Dclm.applicationId=app\_id -Dmaven.wagon.http.ssl.insecure=false

give me this error

> [ERROR] Failed to execute goal com.sonatype.clm:clm-maven-plugin:2.31.1-01:evaluate (default-cli) on project myproject: Could not communicate with IQ Server: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target → [Help 1]

is there any option to set on command line to avoid certificate validation ?

---

<div class="post-metadata">

### Author: ![rseddon](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/rseddon/32/341_2.png) [@rseddon](https://community.sonatype.com/u/rseddon)
#### Post date: [August 23, 2022, 11:10am UTC](https://community.sonatype.com/t/allow-autosigned-https-certificate-on-maven-plugin/9183/2 "2022-08-23T11:10:44Z")

</div>

You need to set that in MAVEN\_OPTS environment variable, see here:

> **[Maven is unable to connect to Nexus Repository 2 after configuring to use SSL.](https://support.sonatype.com/hc/en-us/articles/213465088-Maven-is-unable-to-connect-to-Nexus-Repository-2-after-configuring-to-use-SSL)**
>
> Nexus Repository 2 officially sunsetted June 30, 2025. Visit my.sonatype.com for archived documentation. Migrate to Sonatype Nexus Repository 3 as soon as possible.
> Symptom: After configuring Nexus...

---

<div class="post-metadata">

### Author: ![c.tixier](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@c.tixier](https://community.sonatype.com/u/c.tixier)
#### Post date: [August 23, 2022, 2:59pm UTC](https://community.sonatype.com/t/allow-autosigned-https-certificate-on-maven-plugin/9183/3 "2022-08-23T14:59:37Z")

</div>

i try :

> export MAVEN\_OPTS=“-Dmaven.wagon.http.ssl.insecure=true -Dmaven.wagon.http.ssl.allowall=true -Dmaven.wagon.http.ssl.ignore.validity.dates=true”

this is recorded

> env | grep MAVEN\_OPTS  
> MAVEN\_OPTS=-Dmaven.wagon.http.ssl.insecure=true -Dmaven.wagon.http.ssl.allowall=true -Dmaven.wagon.http.ssl.ignore.validity.dates=true

still have the same error. i also see it inside the log

> [DEBUG] properties used … env.MAVEN\_OPTS= -Dmaven.wagon.http.ssl.insecure=true -Dmaven.wagon.http.ssl.allowall=true -Dmaven.wagon.http.ssl.ignore.validity.dates=true … maven.wagon.http.ssl.insecure=true …

I also try to put into the plugin configuration without success :

> ```
> <groupId>com.sonatype.clm</groupId>
> <artifactId>clm-maven-plugin</artifactId>
> <version>2.31.1-01</version>
> <configuration>
> <maven.wagon.http.ssl.insecure>true</maven.wagon.http.ssl.insecure>
> <maven.wagon.http.ssl.allowall>true</maven.wagon.http.ssl.allowall>
> <maven.wagon.http.ssl.ignore.validity.dates>true</maven.wagon.http.ssl.ignore.validity.dates>
> </configuration>
> 
> ```
