# Bad cert when accessing the General registry

**URL:** <https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738>\
**Category:** Package Management\
**Created:** [April 9, 2024, 3:51pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738 "2024-04-09T15:51:53Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![danielmatz](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/danielmatz/32/2285_2.png) [@danielmatz](https://discourse.julialang.org/u/danielmatz)\
**Post date:** [April 9, 2024, 3:51pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/1 "2024-04-09T15:51:54Z")

</div>

I just started getting errors about untrusted SSL cert when accessing the General registry.

If I try to update General:

```julia
(@v1.10) pkg> registry update General
    Updating registry at `~/.julia/registries/General.toml`
┌ Error: Some registries failed to update:
│ — /Users/dmatz/.julia/registries/General.toml — failed to download from https://pkg.julialang.org/registry/23338594-aafe-5451-b93e-139f81909106/89c6967ae14017d23abb5eda0c65a7c263ca9aac. Exception: RequestError: HTTP/2 301 (SSL certificate problem: Invalid certificate chain) while requesting https://pkg.julialang.org/registry/23338594-aafe-5451-b93e-139f81909106/89c6967ae14017d23abb5eda0c65a7c263ca9aac
└ @ Pkg.Registry ~/.julia/juliaup/julia-1.10.2+0.aarch64.apple.darwin14/share/julia/stdlib/v1.10/Pkg/src/Registry/Registry.jl:510

```

Another type of error when my CI system tries to get General in a fresh depot:

```bash
$ julia -e 'using Pkg; Pkg.Registry.add("General")'
ERROR: could not download https://pkg.julialang.org/registry/23338594-aafe-5451-b93e-139f81909106/89c6967ae14017d23abb5eda0c65a7c263ca9aac
Stacktrace:
  [1] pkgerror(msg::String)
    @ Pkg.Types /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Types.jl:55
  [2] (::Pkg.Types.var"#82#85"{Pkg.Types.Context, String, Pkg.Types.RegistrySpec})(tmp::String)
    @ Pkg.Types /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Types.jl:1035
  [3] mktempdir(fn::Pkg.Types.var"#82#85"{Pkg.Types.Context, String, Pkg.Types.RegistrySpec}, parent::String; prefix::String)
    @ Base.Filesystem ./file.jl:729
  [4] mktempdir (repeats 2 times)
    @ ./file.jl:727 [inlined]
  [5] clone_or_cp_registries(ctx::Pkg.Types.Context, regs::Vector{Pkg.Types.RegistrySpec}, depot::String)
    @ Pkg.Types /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Types.jl:1027
  [6] clone_or_cp_registries
    @ /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Types.jl:1020 [inlined]
  [7] #add#7
    @ /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Registry.jl:33 [inlined]
  [8] add
    @ /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Registry.jl:29 [inlined]
  [9] #add#5
    @ /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Registry.jl:26 [inlined]
 [10] add
    @ /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Registry.jl:26 [inlined]
 [11] add(regs::Vector{String}; kwargs::Base.Iterators.Pairs{Union{}, Union{}, Tuple{}, NamedTuple{(), Tuple{}}})
    @ Pkg.Registry /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Registry.jl:25
 [12] add
    @ /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Registry.jl:25 [inlined]
 [13] #add#1
    @ /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Registry.jl:24 [inlined]
 [14] add(reg::String)
    @ Pkg.Registry /buildworker/worker/package_linux64/build/usr/share/julia/stdlib/v1.6/Pkg/src/Registry.jl:24
 [15] top-level scope
    @ none:1
caused by: HTTP/2 301 (Cert verify failed: BADCERT_NOT_TRUSTED) while requesting https://pkg.julialang.org/registry/23338594-aafe-5451-b93e-139f81909106/89c6967ae14017d23abb5eda0c65a7c263ca9aac

```

Is anyone else seeing this?

---

<div class="post-metadata">

**Author:** ![jling](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jling/32/212909_2.png) [@jling](https://discourse.julialang.org/u/jling)\
**Post date:** [April 9, 2024, 3:54pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/2 "2024-04-09T15:54:26Z")

</div>

what Linux distribution (and version) are you on?

---

<div class="post-metadata">

**Author:** ![danielmatz](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/danielmatz/32/2285_2.png) [@danielmatz](https://discourse.julialang.org/u/danielmatz)\
**Post date:** [April 9, 2024, 3:55pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/3 "2024-04-09T15:55:11Z")

</div>

The top example is on my Mac, and the bottom example is a CI job running on our Linux system, which is CentOS 7.

---

<div class="post-metadata">

**Author:** ![jling](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jling/32/212909_2.png) [@jling](https://discourse.julialang.org/u/jling)\
**Post date:** [April 9, 2024, 3:59pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/4 "2024-04-09T15:59:01Z")

</div>

> [@danielmatz](#):
>
> CentOS 7.

Ha. At CERN we have this problem as well, where the stock COS7 with Julia (which is official binary but the our software environment would overload a bunch of things) would give you cert error, but only if you’re not using the official binary from `juliaup`.

As for your local macOS laptop, I’m not sure, I just tried it now and it works fine.

---

<div class="post-metadata">

**Author:** ![danielmatz](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/danielmatz/32/2285_2.png) [@danielmatz](https://discourse.julialang.org/u/danielmatz)\
**Post date:** [April 9, 2024, 5:02pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/5 "2024-04-09T17:02:07Z")

</div>

Some co-workers are also seeing the issue, but only when on our company network. Must be an issue on our side.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [April 9, 2024, 6:23pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/6 "2024-04-09T18:23:10Z")

</div>

Is there a proxy/firewall? Those will sometimes MITM your connections. In such cases there’s usually some company-specific certificate authority cert that needs to be added to allow the transparent proxy to perform this MITM. It will read all your traffic in such a case, even over HTTPS connections.

---

<div class="post-metadata">

**Author:** ![mbauman](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/mbauman/32/31082_2.png) [@mbauman](https://discourse.julialang.org/u/mbauman)\
**Post date:** [April 10, 2024, 2:54pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/7 "2024-04-10T14:54:38Z")

</div>

5 posts were split to a new topic: [Unexpected end of data when updating registries with LocalPackageServer](https://discourse.julialang.org/t/unexpected-end-of-data-when-updating-registries-with-localpackageserver/112782)

---

<div class="post-metadata">

**Author:** ![danielmatz](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/danielmatz/32/2285_2.png) [@danielmatz](https://discourse.julialang.org/u/danielmatz)\
**Post date:** [April 10, 2024, 2:50pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/12 "2024-04-10T14:50:44Z")

</div>

If I use my browser to navigate to your us-west URL, it tries to download the registry. If I navigate to us-east, it seems to forward to “[storage.julialang.net](http://storage.julialang.net)”, and my browser complains about an invalid certificate.

If I force Julia to use the us-west server, things are working great:

```julia
$ JULIA_PKG_SERVER=https://us-west.pkg.julialang.org julia

```

(To be clear, my original issue was unrelated to HTTP.jl.)

---

<div class="post-metadata">

**Author:** ![fredrikekre](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fredrikekre/32/1688_2.png) [@fredrikekre](https://discourse.julialang.org/u/fredrikekre)\
**Post date:** [April 10, 2024, 8:53pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/13 "2024-04-10T20:53:52Z")

</div>

The root certificate for [https://storage.julialang.net](https://storage.julialang.net) (which [https://us-east.pkg.julialang.org](https://us-east.pkg.julialang.org) redirects to) is _ISRG Root X2_ and the root certificate for [https://us-west.pkg.julialang.org](https://us-west.pkg.julialang.org) (and [https://us-east.pkg.julialang.org](https://us-east.pkg.julialang.org) too) is _ISRG Root X1_. Is it possible that the former isn’t trusted (yet) by your system?

See [https://letsencrypt.org/certificates/](https://letsencrypt.org/certificates/) for some more details. In particular they list a couple of test pages where you can verify the theory above. For example, [https://valid-isrgrootx1.letsencrypt.org/](https://valid-isrgrootx1.letsencrypt.org/) present a valid certificate signed by ISRG Root X1 and [https://valid-isrgrootx2.letsencrypt.org/](https://valid-isrgrootx2.letsencrypt.org/) a valid cert signed by ISRG Root X2.

---

<div class="post-metadata">

**Author:** ![danielmatz](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/danielmatz/32/2285_2.png) [@danielmatz](https://discourse.julialang.org/u/danielmatz)\
**Post date:** [April 10, 2024, 9:17pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/14 "2024-04-10T21:17:05Z")

</div>

Thanks for that detail, I’ll pass that along. I’ve opened a ticket with my company’s IT department. They must have changed something this week!

---

<div class="post-metadata">

**Author:** ![fredrikekre](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fredrikekre/32/1688_2.png) [@fredrikekre](https://discourse.julialang.org/u/fredrikekre)\
**Post date:** [April 10, 2024, 9:22pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/15 "2024-04-10T21:22:53Z")

</div>

Not necessarily a change on your end since the redirection to [https://storage.julialang.net](https://storage.julialang.net) was deployed yesterday. Regardless, all certs are valid as far as I can tell.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [April 14, 2024, 8:58pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/16 "2024-04-14T20:58:58Z")

</div>

You can locally try to curl the two letsencrypt URLs that Fredrik posted and check if the [https://valid-isrgrootx2.letsencrypt.org/](https://valid-isrgrootx2.letsencrypt.org/) one doesn’t work. In that case that would confirm the issue.

---

<div class="post-metadata">

**Author:** ![danielmatz](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/danielmatz/32/2285_2.png) [@danielmatz](https://discourse.julialang.org/u/danielmatz)\
**Post date:** [April 15, 2024, 2:22pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/17 "2024-04-15T14:22:42Z")

</div>

I tried both [https://valid-isrgrootx1.letsencrypt.org/](https://valid-isrgrootx1.letsencrypt.org/) and [https://valid-isrgrootx2.letsencrypt.org/](https://valid-isrgrootx2.letsencrypt.org/) in both my browser and with curl, and everything worked fine. But [https://us-east.pkg.julialang.org/registry/23338594-aafe-5451-b93e-139f81909106/6e59100195a18329cf56e7a7b76c065fa25d3a5c](https://us-east.pkg.julialang.org/registry/23338594-aafe-5451-b93e-139f81909106/6e59100195a18329cf56e7a7b76c065fa25d3a5c) continues to give me issues.

---

<div class="post-metadata">

**Author:** ![danielmatz](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/danielmatz/32/2285_2.png) [@danielmatz](https://discourse.julialang.org/u/danielmatz)\
**Post date:** [April 15, 2024, 2:24pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/18 "2024-04-15T14:24:09Z")

</div>

> [@fredrikekre](#):
>
> The root certificate for [https://storage.julialang.org](https://storage.julialang.org)

Did you mean `.org`? Because I get redirected to [https://storage.julialang.net](https://storage.julialang.net).

---

<div class="post-metadata">

**Author:** ![fredrikekre](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fredrikekre/32/1688_2.png) [@fredrikekre](https://discourse.julialang.org/u/fredrikekre)\
**Post date:** [April 15, 2024, 2:56pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/19 "2024-04-15T14:56:45Z")

</div>

I meant `.net`, sorry. Updated.

---

<div class="post-metadata">

**Author:** ![danielmatz](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/danielmatz/32/2285_2.png) [@danielmatz](https://discourse.julialang.org/u/danielmatz)\
**Post date:** [April 18, 2024, 6:26pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/20 "2024-04-18T18:26:00Z")

</div>

My issue bounced through the bureaucracy for a week or so, but it finally made it to the network team. The issue appears to be resolved. Unfortunately, they didn’t leave any notes about what they did, so I’m not sure if it was the root cert or something else.

Thank you all again for help on this!

---

<div class="post-metadata">

**Author:** ![croberts](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/croberts/32/9465_2.png) [@croberts](https://discourse.julialang.org/u/croberts)\
**Post date:** [May 14, 2026, 8:36pm UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/21 "2026-05-14T20:36:40Z")

</div>

> [@fredrikekre](#):
>
> Not necessarily a change on your end since the redirection to [https://storage.julialang.net](https://storage.julialang.net) was deployed yesterday. Regardless, all certs are valid as far as I can tell.

You indicate that on April 9th the redirection was _to_ [https://storage.julialang.net](https://storage.julialang.net) . What was the redirect _from_? That information might help me to pinpoint the source of my CERT\_TRUST\_IS\_UNTRUSTED\_ROOT error, which has prevented me from downloading packages / updating packages / updating registry for the last 6 weeks and is probably related.

---

<div class="post-metadata">

**Author:** ![fredrikekre](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fredrikekre/32/1688_2.png) [@fredrikekre](https://discourse.julialang.org/u/fredrikekre)\
**Post date:** [May 15, 2026, 11:25am UTC](https://discourse.julialang.org/t/bad-cert-when-accessing-the-general-registry/112738/22 "2026-05-15T11:25:00Z")

</div>

By default Pkg connects to `https://pkg.julialang.org` which redirects you to a regional server (e.g. `https://eu-central.pkg.julialang.org` if you are in Europe). The regional endpoint serves some data itself (no redirect) and redirects some requests to `https://storage.julialang.org`. This hasn’t really changed since my post though, and that was two years ago at this point.
