From 523e8c61b12686556f48f8808e51729c47a0ff2d Mon Sep 17 00:00:00 2001 From: Claude Date: Sat, 7 Mar 2026 11:11:14 +0000 Subject: [PATCH] Fix Gradle proxy: configure JVM trust store for TLS inspection The Anthropic proxy performs TLS inspection and presents certs signed by its own CA. The Ubuntu JDK (used by the Gradle wrapper) has this CA imported via /etc/ssl/certs/java/cacerts, but the JetBrains JDK that Gradle downloads for the daemon has its own isolated trust store that does not include the Anthropic CA. This caused the Gradle daemon to fail with SSL errors when trying to download plugins (e.g. foojay-resolver-convention) and dependencies through the proxy, even though the proxy credentials were correct. Fix by adding systemProp.javax.net.ssl.trustStore in the generated ~/.gradle/gradle.properties to point to Ubuntu's Java trust store (/etc/ssl/certs/java/cacerts), which already has the Anthropic CA imported. This makes the Gradle daemon use the system trust store regardless of which JDK it runs on. https://claude.ai/code/session_01761JmhtmzsagWwKw2DYyi3 --- .claude/hooks/session-start.sh | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.claude/hooks/session-start.sh b/.claude/hooks/session-start.sh index 03c5b3bb..4d3a806b 100755 --- a/.claude/hooks/session-start.sh +++ b/.claude/hooks/session-start.sh @@ -51,6 +51,12 @@ systemProp.http.proxyPassword=$pass # Override nonProxyHosts: route all external traffic (incl. *.google.com) through proxy systemProp.http.nonProxyHosts=localhost|127.0.0.1 systemProp.https.nonProxyHosts=localhost|127.0.0.1 +# Use Ubuntu's Java trust store (includes Anthropic TLS inspection CA) for all Gradle JVMs. +# This is needed because Gradle may download a custom JDK (e.g. JetBrains) whose bundled +# trust store doesn't include the Anthropic CA, causing TLS inspection failures. +systemProp.javax.net.ssl.trustStore=/etc/ssl/certs/java/cacerts +systemProp.javax.net.ssl.trustStoreType=JKS +systemProp.javax.net.ssl.trustStorePassword=changeit EOF echo "Configured Maven/Gradle proxy from HTTPS_PROXY" >&2