I think you may need a successful switch to actually apply the addition of the proxy CA to your root CA store before attempting any other changes that could require reaching out across the network. At least that was the order of operations I had to follow to remove an offline remote cache before attempting any package updates.
this post was submitted on 04 Nov 2025
3 points (100.0% liked)
Nix / NixOS
2668 readers
1 users here now
Main links
Videos
founded 2 years ago
MODERATORS
The problem is that I cannot successfully rebuild because of the SSL certificate errors. Is there any way to bypass the SSL verification?
You should be able to rebuild offline if the minimal change set is self contained enough, as in purely local. Did you update any other inputs? I guess you could be missing some kind of extra TLS or CA store dependency for adding custom CAs, but that doesn't seem likely for regular NixOS install. I use flakes instead of channels, so I wouldn't know what else may be blocked you. A stdout log may showcase your error more clearly.