Files
nixpkgs/pkgs/by-name/ca/cacert/setup-hook.sh
Dark Steveneq 646b892680
Some checks failed
Periodic Merges (6h) / master → staging-nixos (push) Failing after 12m50s
Periodic Merges (6h) / master → staging-next (push) Failing after 12m54s
Periodic Merges (24h) / merge-base(master,staging) → haskell-updates (push) Failing after 11m54s
Periodic Merges (6h) / staging-next → staging (push) Failing after 12m13s
Periodic Merges (24h) / staging-next-25.05 → staging-25.05 (push) Failing after 13m24s
Periodic Merges (24h) / release-25.05 → staging-next-25.05 (push) Failing after 14m28s
push sheeet
2025-10-09 14:15:47 +02:00

14 lines
556 B
Bash

export NIX_SSL_CERT_FILE="${NIX_SSL_CERT_FILE:-@out@/etc/ssl/certs/ca-bundle.crt}"
if test ! -r "$NIX_SSL_CERT_FILE"; then
# If we inherited an unreadable cert file path, just use the bundled one
# TODO: This is just a workaround, the proper solution should be made on the Nix side
# Issue: https://github.com/NixOS/nix/issues/12698
export NIX_SSL_CERT_FILE="@out@/etc/ssl/certs/ca-bundle.crt"
fi
# compatibility
# - openssl
export SSL_CERT_FILE=$NIX_SSL_CERT_FILE
# - Haskell x509-system
export SYSTEM_CERTIFICATE_PATH=$NIX_SSL_CERT_FILE