snapcraft cannot connect through a transparent SSL proxy
Metadata
Current evaluation
snapcraft fails with SSL CERTIFICATE_VERIFY_FAILED behind a transparent MITM proxy because it does not use the system CA store; workaround is REQUESTS_CA_BUNDLE. Reported on 8.3.1/7.5.5; maintainer asked a clarifying question, no labels or fix yet.
Suggested action: needs triage
Reason: No labels, no assignee, and only a single clarifying question from @lengau (2024-07-24) with no further maintainer action; the reporter's answer (2024-07-26) was never followed up. A related commit 6a4aa6ff0 'use system certificates by default for https requests (#3252)' exists but its scope relative to this transparent-proxy case is unconfirmed, so the issue still needs triage to determine whether it is already addressed.
Issue body
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.8-27b |
Impact:
55
Quick Win:
30.25
Staleness:
75
Complexity:
45
Confidence:
55
Support Request:
10
|
needs triage | snapcraft fails with SSL CERTIFICATE_VERIFY_FAILED behind a transparent MITM proxy because it does not use the system CA store; workaround is REQUESTS_CA_BUNDLE. Reported on 8.3.1/7.5.5; maintainer asked a clarifying question, no labels or fix yet. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
90
Complexity:
45
Confidence:
85
Support Request:
20
|
needs triage | Feature request for native system CA bundle support to work through transparent SSL proxies. Currently fails certificate verification. Unlabeled, no assignee, and stuck over a year after a maintainer follow-up question. | |
| qwen3.6-35b-a3b-mtp-q6 |
Staleness:
85
Complexity:
55
Confidence:
75
Support Request:
25
|
needs triage | Feature request to add built-in system CA bundle support for transparent SSL proxies. Open for over two years with no labels, assignee, or maintainer triage. | |
| qwen3.6-35b-a3b-mtp-q6 |
Staleness:
75
Complexity:
40
Confidence:
65
Support Request:
10
|
needs triage | Snapcraft fails to connect through transparent SSL proxies due to missing system CA support. Needs a dedicated flag to use the system CA bundle without affecting other apps. Open and awaiting maintainer feedback. |
Update history
No update history recorded yet.
Related work
-
Likely Fixed By:
snapcraft#3252
(confidence 40%)
Commit 6a4aa6ff0 'snapcraft: use system certificates by default for https requests' may address the system-CA-store request, but it is unverified whether it covers the transparent MITM proxy / whoami path described here.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #2073910 snapcraft cannot connect through a transparent SSL proxy | snapcraft (launchpad) | open | snapcraft fails with SSL CERTIFICATE_VERIFY_FAILED behind transparent MITM proxies; no system CA store option exists. Open 772 days, 0 comments, no labels, no maintainer engagement. |