JSnider152709 (Community Member) asked a question.

Resolving communication issues with SCA Agent Based scanner while on VPN

Has anyone had any issues with attempting to run the SCA Agent based scan while on a corporate VPN? I'm pretty sure it is a certificate issues with my company's corporate proxy and that I need to add the appropriate certificates for the srcclr cli agent to trust those certificates, but am unable to get any verbose output from the tool to see what the exact certificate issues is. I could take it off VPN to scan, however I'm resolving dependencies using an On-Prem Artifactory server that is only accessible via the VPN. Any guidance or assistance would be much appreciated.


  • JSnider152709 (Community Member)

    One more thing I forgot to mention. This error is occurring when the SCA Agent is attempting to validate the license with the Veracode server.

  • JSnider152709 (Community Member)

    NVM. It was buried in the documentation. I didn't realize there was an environment variable that had to be leveraged to point to the CA bundle for our proxy. In case anyone else comes across this issue, just set the environment variable SRCCLR_SSL_CERT_FILE to point to the CA for your corporate proxy and it should work. Found it under the Enable Veracode Agent-Based Scan Behind a Proxy section of the SCA Configuration section https://help.veracode.com/r/t_sc_agent_proxy

    Expand Post

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.