# Nexus Repo Mgr OSS version 2.14.9-01 doesn't work on VPN using proxy

**URL:** https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561
**Category:** Sonatype Nexus Repository
**Created:** [September 20, 2018, 6:28pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561 "2018-09-20T18:28:38Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![gary.l.mills](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gary.l.mills](https://community.sonatype.com/u/gary.l.mills)
#### Post date: [September 20, 2018, 6:28pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/1 "2018-09-20T18:28:39Z")

</div>

I have an issue where Nexus OSS cannot connect to repositories such as Maven Central and all others if I am over my Companies VPN. If I am not over VPN nexus can find and download artifacts. If over the VPN nexus cannot locate repositories. Any Ideas or suggestions, … thank you!

1. company uses a proxy script, I tried using the proxy script but I don’t think nexus supports this. it did not work.  
java.net.UnknownHostException: [myapps.setpac.ge.com/pac.pac](http://myapps.setpac.ge.com/pac.pac)  
org.sonatype.nexus.proxy.RemoteStorageException: Transport error while executing GET method [repositoryId=“central”, requestPath="/.index/nexus-maven-repository-index.properties", remoteUrl=“[https://repo1.maven.org/maven2/.index/nexus-maven-repository-index.properties](https://repo1.maven.org/maven2/.index/nexus-maven-repository-index.properties)”]

2. I remove the co. proxy script reference and go directly to the corp proxy server, but then I get a PKIX error.,  
javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target  
Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target  
Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

is there something I’m missing? what am I doing wrong? What did I miss?

thank you

---

<div class="post-metadata">

### Author: ![gary.l.mills](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gary.l.mills](https://community.sonatype.com/u/gary.l.mills)
#### Post date: [September 20, 2018, 7:12pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/2 "2018-09-20T19:12:37Z")

</div>

I notice that there are some plugins missing.

 ![image](https://canada1.discourse-cdn.com/flex047/uploads/communitysonatype/original/1X/0a12e44f77f2452835e9dc7e9053dbbb5667ebc0.png)

---

<div class="post-metadata">

### Author: ![rseddon](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/rseddon/32/341_2.png) [@rseddon](https://community.sonatype.com/u/rseddon)
#### Post date: [September 20, 2018, 7:20pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/3 "2018-09-20T19:20:21Z")

</div>

For problem #2 have you tried trusting the certificate of the remote in the repository configuration?

[https://help.sonatype.com/display/NXRM3/Configuring+SSL#ConfiguringSSL-OutboundSSL-TrustingSSLCertificatesofRemoteRepositories](https://help.sonatype.com/display/NXRM3/Configuring+SSL#ConfiguringSSL-OutboundSSL-TrustingSSLCertificatesofRemoteRepositories)

---

<div class="post-metadata">

### Author: ![gary.l.mills](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gary.l.mills](https://community.sonatype.com/u/gary.l.mills)
#### Post date: [September 20, 2018, 7:30pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/4 "2018-09-20T19:30:46Z")

</div>

thanks rseddon I’ll give this a try.

---

<div class="post-metadata">

### Author: ![rseddon](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/rseddon/32/341_2.png) [@rseddon](https://community.sonatype.com/u/rseddon)
#### Post date: [September 20, 2018, 7:34pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/5 "2018-09-20T19:34:21Z")

</div>

For the plugins showing as missing see here: [https://issues.sonatype.org/browse/NEXUS-10981](https://issues.sonatype.org/browse/NEXUS-10981)

---

<div class="post-metadata">

### Author: ![gary.l.mills](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gary.l.mills](https://community.sonatype.com/u/gary.l.mills)
#### Post date: [September 20, 2018, 7:44pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/6 "2018-09-20T19:44:33Z")

</div>

rseddon,

hey, I don’t have the administrative repository sub menu as described in the doc link. maybe this is my overall problem. Why wouldn’t I have this.  
" The administration user interface for repositories and repository groups is available via the _Repositories_ item in the _Repository_ sub menu of the _Administration_ menu."

 ![image](https://canada1.discourse-cdn.com/flex047/uploads/communitysonatype/original/1X/951d6382bd3bbf2cbafefc004209caa9f0bee0cb.png)

---

<div class="post-metadata">

### Author: ![rseddon](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/rseddon/32/341_2.png) [@rseddon](https://community.sonatype.com/u/rseddon)
#### Post date: [September 20, 2018, 8:07pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/7 "2018-09-20T20:07:22Z")

</div>

I missed the fact you were running Nexus Repo 2.x in my original reply. See here:

[https://support.sonatype.com/hc/en-us/articles/213465038-Fix-https-repository-blocking-by-PKIX-path-building-failed](https://support.sonatype.com/hc/en-us/articles/213465038-Fix-https-repository-blocking-by-PKIX-path-building-failed)

---

<div class="post-metadata">

### Author: ![gary.l.mills](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gary.l.mills](https://community.sonatype.com/u/gary.l.mills)
#### Post date: [September 20, 2018, 9:03pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/8 "2018-09-20T21:03:14Z")

</div>

Rseddon,  
thanks so much for helping me. Rseddon, It looks like there is something missing with my Nexus Repo OSS 2.x . the suggested instructions give a SSL tab on the repository. hmmmm, I don’t have such a tab. what did I do wrong? did I miss something during installation ??

 ![image](https://canada1.discourse-cdn.com/flex047/uploads/communitysonatype/original/1X/6e6f511645f4927df00a460194b34a5daff9c2bc.png)

---

<div class="post-metadata">

### Author: ![gary.l.mills](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gary.l.mills](https://community.sonatype.com/u/gary.l.mills)
#### Post date: [September 20, 2018, 9:24pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/9 "2018-09-20T21:24:20Z")

</div>

Rseddon,  
I just tried to create another proxy repo to see if the SSL or Truststore option is there and it is not an option when setting up a proxy repo?

---

<div class="post-metadata">

### Author: ![rseddon](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/rseddon/32/341_2.png) [@rseddon](https://community.sonatype.com/u/rseddon)
#### Post date: [September 20, 2018, 9:29pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/10 "2018-09-20T21:29:05Z")

</div>

The SSL tab only shows up if the URL of the proxy uses https. What is the URL set to in the central proxy?

---

<div class="post-metadata">

### Author: ![gary.l.mills](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gary.l.mills](https://community.sonatype.com/u/gary.l.mills)
#### Post date: [September 20, 2018, 11:27pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/11 "2018-09-20T23:27:17Z")

</div>

thanks Rseddon,

[https://repo1.maven.org/maven2/](https://repo1.maven.org/maven2/)

Maven Central - there is no SSL tab

---

<div class="post-metadata">

### Author: ![rseddon](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/rseddon/32/341_2.png) [@rseddon](https://community.sonatype.com/u/rseddon)
#### Post date: [September 21, 2018, 1:51pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/12 "2018-09-21T13:51:31Z")

</div>

Sorry, I’d forgotten that in Nexus 2.x the SSL UI is a pro only feature, and requires a license. In Nexus 3.x the SSL feature is in both OSS and pro.

You’ll need to use this technique to import the certificate into the truststore of the java running Nexus:

[https://support.sonatype.com/hc/en-us/articles/213465768-SSL-Certificate-Guide#java-client-trust-self-signed](https://support.sonatype.com/hc/en-us/articles/213465768-SSL-Certificate-Guide#java-client-trust-self-signed)

---

<div class="post-metadata">

### Author: ![gary.l.mills](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gary.l.mills](https://community.sonatype.com/u/gary.l.mills)
#### Post date: [September 21, 2018, 2:48pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/13 "2018-09-21T14:48:23Z")

</div>

Rseddon

it sounds like it is a licensed feature in 2.x but it comes out of box in 3.x - is this correct? if I upgraded to 3.x OSS would I need a license?

---

<div class="post-metadata">

### Author: ![rseddon](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/rseddon/32/341_2.png) [@rseddon](https://community.sonatype.com/u/rseddon)
#### Post date: [September 21, 2018, 3:06pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/14 "2018-09-21T15:06:31Z")

</div>

Yes, that’s right, if you upgrade to Nexus Repo 3 you don’t need a license for the SSL feature.

---

<div class="post-metadata">

### Author: ![gary.l.mills](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gary.l.mills](https://community.sonatype.com/u/gary.l.mills)
#### Post date: [September 21, 2018, 4:25pm UTC](https://community.sonatype.com/t/nexus-repo-mgr-oss-version-2-14-9-01-doesnt-work-on-vpn-using-proxy/561/15 "2018-09-21T16:25:33Z")

</div>

very Kewl. thanks so much Rseddon!!!

hey, just so you know. I performed the import of the proxy cert/ssl and it appears to work 🙂

this did the trick!!! thanks!

I will upgrade soon, but the proxy cert import worked.
