Trying to configure remote repository that requires client side certificate.
I have pair of nexus nodes, first one has hosted repository and reverse proxy with SSL and CA.Second nexus is where the proxied repo is being configured, CA is added to trust store and remote repository is marked as Active.The question is where to provision the client side certificate required by remote side?
There is no such a functionality in the Web interface. Imported it into keystore.jks, java keystore, still ssl handshake error.Please advise for both version 2 and 3. Thanks a lot.
--
You received this message because you are subscribed to the Google Groups "Nexus Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to nexus-users+unsubscribe@glists.sonatype.com.
To post to this group, send email to nexus...@glists.sonatype.com.
To view this discussion on the web visit https://groups.google.com/a/glists.sonatype.com/d/msgid/nexus-users/7ff65ce8-5c49-4210-ac94-de9888205a74%40glists.sonatype.com.
For more options, visit https://groups.google.com/a/glists.sonatype.com/d/optout.
Peter, thank you for your response.Let me explain.First nexus that hosts repository has apache httpd with SSL on front of it.Second nexus proxies requests to this repo.In basic configuration, i manage to add CA into second nexus Java cacerts and it works correctly with remote repo.However, for various reasons, i need to implement two-way ssl between these nexus nodes.That actually implies 'SSLVerifyClient require' option at the front apache httpd."client" or 'second' nexus will validate 'server' or 'first' nexus certificate, then 'first' nexus (apache actually)will request valid certificate from the 'second' nexus.This is standard SSL/TLS feature.Not sure if relevant here, but i managed to set it up between Artifactory and Nexus: remote repository configuration in Artifactory allows to place specific certificate for given URL.Therefore, this option must be available in Spring or whatever framework is used by Nexus.My question is: since there's no Web gui function for this, is there any way to configure specific certificate for specific remote repository URL manually?
I've submitted a ticket quite long ago, it is still unassignedOn Fri, Mar 23, 2018 at 10:49 PM, R. Brian DiAngelo <r.brian....@gmail.com> wrote:All,
I'm having similar issue whereby nexus repository A is unable to proxy to a remote nexus repository B using 2-way SSL. It appears issue is that nexus repository A is not presenting client certificate to nexus B (in ssl debug seeing Warning: no suitable certificate found - continuing without client authentication).
I know keystore and truststore are loaded with correct certs. Also, was able to verify successful 2-way SSL connection between nexus repository A and B using openssl s_client with cert and key exported from keystore
I am running nexus-3.9.0-01.
Is there any progress resolving this issue. This is becoming a major showstopper.
Thanks,
Brian
To unsubscribe from this group and stop receiving emails from it, send an email to nexus-users...@glists.sonatype.com.
To post to this group, send email to nexus...@glists.sonatype.com.
To view this discussion on the web visit https://groups.google.com/a/glists.sonatype.com/d/msgid/nexus-users/7ff65ce8-5c49-4210-ac94-de9888205a74%40glists.sonatype.com.
For more options, visit https://groups.google.com/a/glists.sonatype.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Nexus Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to nexus-users+unsubscribe@glists.sonatype.com.
To post to this group, send email to nexus...@glists.sonatype.com.
To view this discussion on the web visit https://groups.google.com/a/glists.sonatype.com/d/msgid/nexus-users/b42e27a9-e7c5-4e5a-92c0-24ec5cebf622%40glists.sonatype.com.
All,
I'm having similar issue whereby nexus repository A is unable to proxy to a remote nexus repository B using 2-way SSL. It appears issue is that nexus repository A is not presenting client certificate to nexus B (in ssl debug seeing Warning: no suitable certificate found - continuing without client authentication).
I know keystore and truststore are loaded with correct certs. Also, was able to verify successful 2-way SSL connection between nexus repository A and B using openssl s_client with cert and key exported from keystore
I am running nexus-3.9.0-01.
Is there any progress resolving this issue. This is becoming a major showstopper.
Thanks,
Brian
On Wednesday, February 7, 2018 at 11:17:32 AM UTC-5, Serge Krawczenko wrote:
To unsubscribe from this group and stop receiving emails from it, send an email to nexus-users...@glists.sonatype.com.
To post to this group, send email to nexus...@glists.sonatype.com.
To view this discussion on the web visit https://groups.google.com/a/glists.sonatype.com/d/msgid/nexus-users/7ff65ce8-5c49-4210-ac94-de9888205a74%40glists.sonatype.com.
For more options, visit https://groups.google.com/a/glists.sonatype.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Nexus Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to nexus-users+unsubscribe@glists.sonatype.com.
To post to this group, send email to nexus...@glists.sonatype.com.
To view this discussion on the web visit https://groups.google.com/a/glists.sonatype.com/d/msgid/nexus-users/b42e27a9-e7c5-4e5a-92c0-24ec5cebf622%40glists.sonatype.com.

To view this discussion on the web visit https://groups.google.com/a/glists.sonatype.com/d/msgid/nexus-users/CAAfOBQ4HMXbbyjaWR52McU2OAQ1_U%2B2bKQ7xwUfH-B413m7irw%40mail.gmail.com.