diff --git a/src/libstore/globals.cc b/src/libstore/globals.cc index 823b4af74..9b19e6611 100644 --- a/src/libstore/globals.cc +++ b/src/libstore/globals.cc @@ -47,6 +47,8 @@ Settings::Settings() auto sslOverride = getEnv("NIX_SSL_CERT_FILE").value_or(getEnv("SSL_CERT_FILE").value_or("")); if (sslOverride != "") caFile = sslOverride; + else if (caFile == "") + caFile = getDefaultSSLCertFile(); /* Backwards compatibility. */ auto s = getEnv("NIX_REMOTE_SYSTEMS"); diff --git a/src/libstore/globals.hh b/src/libstore/globals.hh index 63c7389da..20ed3f6b6 100644 --- a/src/libstore/globals.hh +++ b/src/libstore/globals.hh @@ -858,7 +858,7 @@ public: )"}; Setting caFile{ - this, getDefaultSSLCertFile(), "ssl-cert-file", + this, "", "ssl-cert-file", R"( The path of a file containing CA certificates used to authenticate `https://` downloads. Nix by default will use