# Redhat registry error

## post by Andrew_Meyer1 on Aug 26, 2025

I’m trying to use podman to download containers and i’m getting the following errors:

```auto
2025-08-26 09:40:55,552-0500 WARN  [qtp1465691120-24]  *UNKNOWN org.sonatype.nexus.repository.docker.internal.datastore.recipe.DockerProxyFacetImpl - Exception org.sonatype.nexus.repository.proxy.BypassHttpErrorException checking remote for update, proxy repo DockerHub failed to fetch v2/rancher/mirrored-pause/blobs/sha256:6270bb605e12e581514ada5fd5b3216f727db55dc87d5889c790e4c760683fee, content not in cache.
2025-08-26 09:41:34,376-0500 INFO  [qtp1465691120-101]  *UNKNOWN org.sonatype.nexus.repository.httpclient.internal.HttpClientFacetImpl - Repository status for registry_redhat_io changed from READY to AVAILABLE - reason n/a for n/a
2025-08-26 09:41:35,298-0500 INFO  [qtp1465691120-101]  *UNKNOWN org.sonatype.nexus.repository.httpclient.internal.HttpClientFacetImpl - Repository status for registry_redhat_io changed from AVAILABLE to UNAVAILABLE - reason javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target for https://registry.redhat.io
2025-08-26 09:41:35,299-0500 WARN  [qtp1465691120-101]  *UNKNOWN org.sonatype.nexus.repository.docker.internal.datastore.recipe.DockerProxyFacetImpl - Exception javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target checking remote for update, proxy repo registry_redhat_io failed to fetch v2/rhel9/nginx-120/blobs/sha256:81bbc99649880ff97cf59c50ec42d7e9ecd76a5042d4b03999f98745ddf272f0, content not in cache.
2025-08-26 09:44:01,685-0500 INFO  [qtp1465691120-99]  admin org.sonatype.nexus.rapture.internal.security.SessionServlet - Created session for user: admin
2025-08-26 09:44:42,575-0500 INFO  [qtp1465691120-23]  *UNKNOWN org.sonatype.nexus.repository.httpclient.internal.HttpClientFacetImpl - Repository status for registry_redhat_io changed from UNAVAILABLE to AVAILABLE - reason n/a for n/a
2025-08-26 09:44:42,782-0500 INFO  [qtp1465691120-23]  *UNKNOWN org.sonatype.nexus.repository.httpclient.internal.HttpClientFacetImpl - Repository status for registry_redhat_io changed from AVAILABLE to UNAVAILABLE - reason javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target for https://registry.redhat.io
2025-08-26 09:44:42,782-0500 WARN  [qtp1465691120-23]  *UNKNOWN org.sonatype.nexus.repository.docker.internal.datastore.recipe.DockerProxyFacetImpl - Exception javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target checking remote for update, proxy repo registry_redhat_io failed to fetch v2/rhel9/nginx-120/blobs/sha256:81bbc99649880ff97cf59c50ec42d7e9ecd76a5042d4b03999f98745ddf272f0, content not in cache.
```

## post by mpiggott on Aug 26, 2025

This error indicates that there is a TLS certificate validation problem between Nexus and the remote registry. Try the Outbound SSL section of the help documentation - [Configuring SSL](https://help.sonatype.com/en/configuring-ssl.html#outbound-ssl---trusting-ssl-certificates-globally)

## post by Andrew_Meyer1 on Aug 26, 2025

I have added the SSL certificate to the SSL truststore in the nexus web ui. So it is in there globally.

## post by mpiggott on Aug 26, 2025

Does the RedHat registry expect client certificate authentication? That is only other thing I can think of if that outbound certificate isn’t sufficient.

## post by Andrew_Meyer1 on Aug 26, 2025

It does not.

## post by Andrew_Meyer1 on Aug 26, 2025

So in my homelab I gave all anonymous users admin privs. In my enterprise env I can’t do that even I probably could. But I’m creating a new user to be used as the anonymous user. I’m trying to give that user all the read and browse privileges. IS this all I need to do to allow for reading the SSL certs?

## post by Andrew_Meyer1 on Aug 26, 2025

Something else to note, this works just fine for using pypi. I have no issues.
