# Downloading from github behind a firewall - Peer’s Certificate issuer is not recognized

**URL:** <https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003>\
**Category:** Internals & Design\
**Created:** [July 13, 2020, 7:51pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003 "2020-07-13T19:51:23Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![feacluster](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/feacluster/32/16361_2.png) [@feacluster](https://discourse.julialang.org/u/feacluster)\
**Post date:** [July 13, 2020, 7:51pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/1 "2020-07-13T19:51:23Z")

</div>

I am behind a corporate firewall but am authenticated to access the internet. I can access any site using curl . But I keep running into this error in Julia when installing packages:

│ [18:12:51] curl: (60) Peer’s Certificate issuer is not recognized.

The problem seems to be downloading from github. Does Julia ship with its own git and SSL certificates for it? I am using v1 .2.

Thanks!

---

<div class="post-metadata">

**Author:** ![anon92994695](https://avatars.discourse-cdn.com/v4/letter/a/ce7236/32.png) [@anon92994695](https://discourse.julialang.org/u/anon92994695)\
**Post date:** [July 13, 2020, 8:40pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/2 "2020-07-13T20:40:02Z")

</div>

Yea this is a common problem.

One option is to change your environ variables:

```julia
ENV["HTTP_PROXY"] = ...
ENV["HTTPS_PROXY"] = ...

```

Sometimes that helps.

Another is to change where the pkg manager points. JuliaLang hosts an alternate location I forget the URL now but if that doesn’t work let us know and I’ll try to dig it up.

---

<div class="post-metadata">

**Author:** ![jling](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jling/32/212909_2.png) [@jling](https://discourse.julialang.org/u/jling)\
**Post date:** [July 13, 2020, 9:04pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/3 "2020-07-13T21:04:15Z")

</div>

what I don’t understand is why your cooperation would firewall github; can you access [https://github.com](https://github.com) in browser?

---

<div class="post-metadata">

**Author:** ![feacluster](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/feacluster/32/16361_2.png) [@feacluster](https://discourse.julialang.org/u/feacluster)\
**Post date:** [July 13, 2020, 9:06pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/4 "2020-07-13T21:06:30Z")

</div>

Thanks. Yes I do have the proxy set as follows:

export https\_proxy=[http://myproxy](http://myproxy)…  
export http\_proxy=$https\_proxy

I can curl or wget any site. The issue seems Julia calls git which does not seem to see these proxy variables or something. Or it is not seeing or using the correct SSL certificates . We have the corporate SSL certificates installed in:

/etc/pki/ca-trust/source/anchors

Not sure how to debug if it is proxy issue or SSL certificate issue?

---

<div class="post-metadata">

**Author:** ![anon92994695](https://avatars.discourse-cdn.com/v4/letter/a/ce7236/32.png) [@anon92994695](https://discourse.julialang.org/u/anon92994695)\
**Post date:** [July 13, 2020, 9:46pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/5 "2020-07-13T21:46:42Z")

</div>

So when I was debugging this I found Julia calls LibGit2 via LibGit.jl(I think) and not Git directly. This complicates things a little more. Also, can I ask which OS you are using? Curl can also have unexpected behaviour behind corporate … situaitons.

you could try setting the proxy in libgit: [LibGit2 · The Julia Language](https://docs.julialang.org/en/v1/stdlib/LibGit2/#LibGit2.ProxyOptions)

You should be able to change where Julia get’s it’s packages too: ie they have different pkg servers here’s one which directs to your nearest available server: [https://pkg.julialang.org/](https://pkg.julialang.org/). trying to dig up the command to set so Pkg.jl uses it.

In the absolute worst case you can set up a pkg server locally with something like: [GitHub - JuliaPackaging/PkgServer.jl](https://github.com/JuliaPackaging/PkgServer.jl)  
or using JuliaTeams! The JuliaTeams team is really nice and helpful.

Or the end of the road. Offer many great gifts to your sysadmin and promise them Julia is not malicious.

---

<div class="post-metadata">

**Author:** ![Fliks](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fliks/32/2494_2.png) [@Fliks](https://discourse.julialang.org/u/Fliks)\
**Post date:** [July 13, 2020, 10:01pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/6 "2020-07-13T22:01:49Z")

</div>

There is some issue in certain libgit2 versions with trailing slashes in the proxy variables.  
Maybe this can help you.  
[https://github.com/JuliaLang/julia/issues/33111#issuecomment-541224149](https://github.com/JuliaLang/julia/issues/33111#issuecomment-541224149)

---

<div class="post-metadata">

**Author:** ![feacluster](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/feacluster/32/16361_2.png) [@feacluster](https://discourse.julialang.org/u/feacluster)\
**Post date:** [July 14, 2020, 4:17pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/7 "2020-07-14T16:17:54Z")

</div>

Just an update I got it working. Apparently I had to add this environment variable:

export SSL\_CERT\_FILE=~myusername/.ssh/corporate.pem

I am not sure why Julia can not see the same certificate I already placed in:

/etc/pki/ca-trust/source/anchors

Curl is able to access all websites without me having to export this SSL\_CERT\_FILE variable.

---

<div class="post-metadata">

**Author:** ![feacluster](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/feacluster/32/16361_2.png) [@feacluster](https://discourse.julialang.org/u/feacluster)\
**Post date:** [July 14, 2020, 4:18pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/8 "2020-07-14T16:18:41Z")

</div>

Haha, I am actually the sysadmin! Trying to help a user with Julia…

---

<div class="post-metadata">

**Author:** ![anon92994695](https://avatars.discourse-cdn.com/v4/letter/a/ce7236/32.png) [@anon92994695](https://discourse.julialang.org/u/anon92994695)\
**Post date:** [July 14, 2020, 6:10pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/9 "2020-07-14T18:10:32Z")

</div>

oh well your corporate environment is way more sane then my own! We have a predominately windows stack, very complicated network, and that complicates cert’s to a huge extent.

Glad you got it working!

---

<div class="post-metadata">

**Author:** ![feacluster](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/feacluster/32/16361_2.png) [@feacluster](https://discourse.julialang.org/u/feacluster)\
**Post date:** [July 15, 2020, 3:46pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/10 "2020-07-15T15:46:52Z")

</div>

So I spoke too soon and the “certificate error” has resurfaced again. I can install packages like CSV without any issue. But if I try to install Plots, I run into this:

│ ERROR: LoadError: LoadError: Could not download [https://github.com/JuliaBinaryWrappers/Bzip2\_jll.jl/releases/download/Bzip2-v1.0.6+1/Bzip2.v1/Bzip2.v1.0.6.x86\_64-linux-gnu.tar.gz](https://github.com/JuliaBinaryWrappers/Bzip2_jll.jl/releases/download/Bzip2-v1.0.6+1/Bzip2.v1/Bzip2.v1.0.6.x86_64-linux-gnu.tar.gz)

│ [11:41:39] curl: (60) Peer’s Certificate issuer is not recognized.

From the command line I have no issue wget’ing the tar ball in question.

I wonder if Julia is launching some new shell that does not see all my proxy related environment variables?

---

<div class="post-metadata">

**Author:** ![feacluster](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/feacluster/32/16361_2.png) [@feacluster](https://discourse.julialang.org/u/feacluster)\
**Post date:** [July 15, 2020, 4:00pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/11 "2020-07-15T16:00:48Z")

</div>

I upgraded to v1.4.2 . Still get same error but a little different:

julia\> Pkg.add(“Plots”)  
Updating registry at `~/.julia/registries/General`  
Updating git-repo `https://github.com/JuliaRegistries/General.git`  
┌ Warning: Some registries failed to update:  
│ — /Apps/users/hussaif1/.julia/registries/General — failed to fetch from repo  
└ @ Pkg.Types /buildworker/worker/package\_linux64/build/usr/share/julia/stdlib/v1.4/Pkg/src/Types.jl:1131  
Resolving package versions…  
Installed LibVPX\_jll ───── v1.8.1+1  
Installed FFMPEG\_jll ───── v4.1.0+3  
Installed FreeType2\_jll ── v2.10.1+2  
Installed Adapt ────────── v2.0.2  
Installed StructArrays ─── v0.4.4  
Installed FFMPEG ───────── v0.3.0  
Installed IterTools ────── v1.3.0  
Installed Plots ────────── v1.5.4  
Installed OpenSSL\_jll ──── v1.1.1+4  
Installed Bzip2\_jll ────── v1.0.6+2  
Installed x264\_jll ─────── v2019.5.25+2  
Installed FriBidi\_jll ──── v1.0.5+3  
Installed x265\_jll ─────── v3.0.0+1  
Installed Opus\_jll ─────── v1.3.1+1  
Installed MbedTLS ──────── v1.0.2  
Installed GeometryBasics ─ v0.2.15  
Installed MbedTLS\_jll ──── v2.16.6+1  
Installed LAME\_jll ─────── v3.100.0+1  
Installed libfdk\_aac\_jll ─ v0.1.6+2  
Installed libvorbis\_jll ── v1.3.6+4  
Installed libass\_jll ───── v0.14.0+2  
Installed Zlib\_jll ─────── v1.2.11+14  
Installed Ogg\_jll ──────── v1.3.4+0  
Downloading artifact: LibVPX  
######################################################################## 100.0%  
curl: (60) Peer’s Certificate issuer is not recognized.  
More details here: [curl - SSL CA Certificates](http://curl.haxx.se/docs/sslcerts.html)

curl performs SSL certificate verification by default, using a “bundle”  
of Certificate Authority (CA) public keys (CA certs). If the default  
bundle file isn’t adequate, you can specify an alternate file  
using the --cacert option.  
If this HTTPS server uses a certificate signed by a CA represented in  
the bundle, the certificate verification probably failed due to a  
problem with the certificate (it might be expired, or the name might  
not match the domain name in the URL).  
If you’d like to turn off curl’s verification of the certificate, use  
ERROR: Unable to automatically install ‘LibVPX’ from ‘/Apps/users/hussaif1/.julia/packages/LibVPX\_jll/os8kH/Artifacts.toml’

---

<div class="post-metadata">

**Author:** ![feacluster](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/feacluster/32/16361_2.png) [@feacluster](https://discourse.julialang.org/u/feacluster)\
**Post date:** [July 15, 2020, 4:34pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/12 "2020-07-15T16:34:54Z")

</div>

Seems I have resolved it by simply exporting this environment variable:

export JULIA\_PKG\_SERVER=[pkg.julialang.org](http://pkg.julialang.org)

---

<div class="post-metadata">

**Author:** ![tyleransom](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tyleransom/32/530_2.png) [@tyleransom](https://discourse.julialang.org/u/tyleransom)\
**Post date:** [February 17, 2021, 9:27pm UTC](https://discourse.julialang.org/t/downloading-from-github-behind-a-firewall-peer-s-certificate-issuer-is-not-recognized/43003/13 "2021-02-17T21:27:25Z")

</div>

To anyone else who might be encountering this problem, it was solved for me by typing

```julia
export BINARYPROVIDER_DOWNLOAD_ENGINE="wget"

```

at the (bash) shell, then opening Julia and installing packages as I normally would. My understanding is that this changes the package download command from `curl` to `wget` and bypasses the issues documented above.
