# Nexus 3 - Validate retrieved content with md5 checksum?

**URL:** <https://community.sonatype.com/t/nexus-3-validate-retrieved-content-with-md5-checksum/5527>\
**Category:** Sonatype Nexus Repository\
**Tags:** help\
**Created:** [December 7, 2020, 2:06pm UTC](https://community.sonatype.com/t/nexus-3-validate-retrieved-content-with-md5-checksum/5527 "2020-12-07T14:06:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![phil](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/phil/32/1571_2.png) [@phil](https://community.sonatype.com/u/phil)\
**Post date:** [December 7, 2020, 2:06pm UTC](https://community.sonatype.com/t/nexus-3-validate-retrieved-content-with-md5-checksum/5527/1 "2020-12-07T14:06:01Z")

</div>

I’m looking into the adoption of Nexus 3 repository manager. Our security manager has asked what security mechanisms are in place when retrieving content from Maven Central e.g. in addition to the connection being SSL/TLS adoes the Nexus RM compare the md5 checksums?

many thanks

---

<div class="post-metadata">

**Author:** ![rseddon](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/rseddon/32/341_2.png) [@rseddon](https://community.sonatype.com/u/rseddon)\
**Post date:** [December 7, 2020, 2:52pm UTC](https://community.sonatype.com/t/nexus-3-validate-retrieved-content-with-md5-checksum/5527/2 "2020-12-07T14:52:38Z")

</div>

Checksum validation is done by the client. In the case of central, clients such as Maven optionally will validate the checksum against the original published checksum. You can do that by setting checksumPolicy to either “warn” or “fail”:

> **[Settings Reference – Maven](https://maven.apache.org/settings.html#Repositories)**
>
> Repositories are remote collections of projects from which Maven uses to populate the local repository of the build system. It is from this local repository that Maven calls it plugins and dependencies. Different remote repositories may contain...

If you’d like additional checks to be done you might be interested in our Nexus Firewall product:

> **[Sonatype Repository Firewall for Malicious Code Protection | Sonatype](https://www.sonatype.com/products/sonatype-repository-firewall)**
>
> Sonatype Repository Firewall blocks malicious code and packages before they enter your software supply chain. Protect your repositories and builds.

That product allows you to define policies against the component’s licenses and known security vulnerabilities, and block components that violate those policies.

Rich

---

<div class="post-metadata">

**Author:** ![msymons](https://avatars.discourse-cdn.com/v4/letter/m/a6a055/32.png) [@msymons](https://community.sonatype.com/u/msymons)\
**Post date:** [December 8, 2020, 3:07pm UTC](https://community.sonatype.com/t/nexus-3-validate-retrieved-content-with-md5-checksum/5527/3 "2020-12-08T15:07:44Z")

</div>

The upcoming Maven 4.0.0 release will switch the default checksum policy from “warn” to “fail”. See [MNG-5728](https://issues.apache.org/jira/browse/MNG-5728).

It will also upgrade Maven Resolver to 1.6.1. See [MNG-6996](https://issues.apache.org/jira/browse/MNG-6996), which lists all the new functionality, such as adding support for SHA-256 and SHA-512 as checksums.

I am not sure when v4.0.0 is due for release but I’m hoping it’s soon.
