Redhat registry error - Sonatype Nexus Repository - Sonatype Community
Redhat registry error
post by Andrew_Meyer1 on Aug 26, 2025
I’m trying to use podman to download containers and i’m getting the following errors:
auto
2025-08-26 09:40:55,552-0500 WARN [qtp1465691120-24] *UNKNOWN org.sonatype.nexus.repository.docker.internal.datastore.recipe.DockerProxyFacetImpl - Exception org.sonatype.nexus.repository.proxy.BypassHttpErrorException checking remote for update, proxy repo DockerHub failed to fetch v2/rancher/mirrored-pause/blobs/sha256:6270bb605e12e581514ada5fd5b3216f727db55dc87d5889c790e4c760683fee, content not in cache.
2025-08-26 09:41:34,376-0500 INFO [qtp1465691120-101] *UNKNOWN org.sonatype.nexus.repository.httpclient.internal.HttpClientFacetImpl - Repository status for registry_redhat_io changed from READY to AVAILABLE - reason n/a for n/a
2025-08-26 09:41:35,298-0500 INFO [qtp1465691120-101] *UNKNOWN org.sonatype.nexus.repository.httpclient.internal.HttpClientFacetImpl - Repository status for registry_redhat_io changed from AVAILABLE to UNAVAILABLE - reason javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target for https://registry.redhat.io
2025-08-26 09:41:35,299-0500 WARN [qtp1465691120-101] *UNKNOWN org.sonatype.nexus.repository.docker.internal.datastore.recipe.DockerProxyFacetImpl - Exception javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target checking remote for update, proxy repo registry_redhat_io failed to fetch v2/rhel9/nginx-120/blobs/sha256:81bbc99649880ff97cf59c50ec42d7e9ecd76a5042d4b03999f98745ddf272f0, content not in cache.
2025-08-26 09:44:01,685-0500 INFO [qtp1465691120-99] admin org.sonatype.nexus.rapture.internal.security.SessionServlet - Created session for user: admin
2025-08-26 09:44:42,575-0500 INFO [qtp1465691120-23] *UNKNOWN org.sonatype.nexus.repository.httpclient.internal.HttpClientFacetImpl - Repository status for registry_redhat_io changed from UNAVAILABLE to AVAILABLE - reason n/a for n/a
2025-08-26 09:44:42,782-0500 INFO [qtp1465691120-23] *UNKNOWN org.sonatype.nexus.repository.httpclient.internal.HttpClientFacetImpl - Repository status for registry_redhat_io changed from AVAILABLE to UNAVAILABLE - reason javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target for https://registry.redhat.io
2025-08-26 09:44:42,782-0500 WARN [qtp1465691120-23] *UNKNOWN org.sonatype.nexus.repository.docker.internal.datastore.recipe.DockerProxyFacetImpl - Exception javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target checking remote for update, proxy repo registry_redhat_io failed to fetch v2/rhel9/nginx-120/blobs/sha256:81bbc99649880ff97cf59c50ec42d7e9ecd76a5042d4b03999f98745ddf272f0, content not in cache.
post by mpiggott on Aug 26, 2025
This error indicates that there is a TLS certificate validation problem between Nexus and the remote registry. Try the Outbound SSL section of the help documentation - Configuring SSL
post by Andrew_Meyer1 on Aug 26, 2025
I have added the SSL certificate to the SSL truststore in the nexus web ui. So it is in there globally.
post by mpiggott on Aug 26, 2025
Does the RedHat registry expect client certificate authentication? That is only other thing I can think of if that outbound certificate isn’t sufficient.
post by Andrew_Meyer1 on Aug 26, 2025
It does not.
post by Andrew_Meyer1 on Aug 26, 2025
So in my homelab I gave all anonymous users admin privs. In my enterprise env I can’t do that even I probably could. But I’m creating a new user to be used as the anonymous user. I’m trying to give that user all the read and browse privileges. IS this all I need to do to allow for reading the SSL certs?
post by Andrew_Meyer1 on Aug 26, 2025
Something else to note, this works just fine for using pypi. I have no issues.