fetchedMavenDeps: honor NIX_SSL_CERT_FILE

Java doesn't honor NIX_SSL_CERT_FILE out of the box, but instead uses
its own concept of a key store.

If we see the environment variable being set, we can create a new key
store with all certs in that file and pass it to the JVM.

(cherry picked from commit cd931bff24)
This commit is contained in:
Florian Klink
2025-06-27 21:32:14 +03:00
parent 02fb4c295f
commit 36a6eeecf1

View File

@@ -57,6 +57,14 @@ let
${writeProxySettings} $mvnSettingsFile
MAVEN_EXTRA_ARGS="-s=$mvnSettingsFile"
fi
# handle cacert by populating a trust store on the fly
if [[ -n "''${NIX_SSL_CERT_FILE-}" ]] && [[ "''${NIX_SSL_CERT_FILE-}" != "/no-cert-file.crt" ]];then
keyStoreFile="$(mktemp -d)/keystore"
keyStorePwd="$(head -c10 /dev/random | base32)"
echo y | ${jdk}/bin/keytool -importcert -file "$NIX_SSL_CERT_FILE" -alias alias -keystore "$keyStoreFile" -storepass "$keyStorePwd"
MAVEN_EXTRA_ARGS="$MAVEN_EXTRA_ARGS -Djavax.net.ssl.trustStore=$keyStoreFile -Djavax.net.ssl.trustStorePassword=$keyStorePwd"
fi
''
+ lib.optionalString buildOffline ''
mvn $MAVEN_EXTRA_ARGS de.qaware.maven:go-offline-maven-plugin:1.2.8:resolve-dependencies -Dmaven.repo.local=$out/.m2 ${mvnDepsParameters}