# Issues with proxy using basic authentication

**URL:** https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652
**Category:** Bugs
**Created:** [January 12, 2016, 3:36pm UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652 "2016-01-12T15:36:57Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![msch](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@msch](https://discuss.gradle.org/u/msch)
#### Post date: [January 12, 2016, 3:36pm UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652/1 "2016-01-12T15:36:57Z")

</div>

I am trying to get gradle running behind a proxy server. However, the connection for resolving dependencies is unsuccessful, even after setting systemProp.http.proxyHost, proxyPort, proxyUser and proxyPassword (and the same for https) in ~/.gradle/gradle.properties.

The system is Ubuntu 14.04 and I tried both gradle 1.4 from the repository as well as gradle 2.10 downloaded from the website. The test case is a very simple test project using the plugin ‘checkstyle’. When running `gradle :check`, the download of checkstyle from the default maven repository fails.

From the [debug output](https://gist.github.com/anonymous/11b2ff7a3a9bf36f180b), it seems that the problem is very similar to [this old issue](https://discuss.gradle.org/t/cannot-access-repositories-via-basic-auth-proxy/7601/36). Gradle (or rather the org.apache.http library) tries three different authentication methods (NEGOTIATE, NTLM, BASIC). While it should use BASIC for this proxy server, it first tries NEGOTIATE (which fails) and NTLM. For NTLM, it gets a 500 error response but interprets that as successful authentication and proceeds. The download of the dependencies then fails with a 500 error too.

It seems like the issue could be fixed by [allowing to set the authentication scheme](https://issues.gradle.org/browse/GRADLE-2589) or by detecting the failure of the NTLM authentication.

If there is anything I can do to fix this issue or provide further information, please let me know.

---

<div class="post-metadata">

### Author: ![mark\_vieira](https://sea1.discourse-cdn.com/gradle/user_avatar/discuss.gradle.org/mark_vieira/32/5396_2.png) [@mark\_vieira](https://discuss.gradle.org/u/mark_vieira)
#### Post date: [January 13, 2016, 1:28am UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652/2 "2016-01-13T01:28:41Z")

</div>

Strange the proxy returns a 500, that seems incorrect. It _should_ return a 407. HttpClient simply isn’t configured to interpret a 500 response code as an authentication challenge (and I don’t believe it should). That said, you actually can [explicitly configuration authentication schemes](https://docs.gradle.org/current/userguide/dependency_management.html#sub:authentication_schemes).

```
repositories {
    maven {
        url 'https://repo.mycompany.com/maven2'
        credentials {
            username 'user'
            password 'password'
        }
        authentication {
            basic(BasicAuthentication)
        }
    }
}

```

I wasn’t aware that JIRA existed, I think we can mark it as fixed now 🙂

---

<div class="post-metadata">

### Author: ![mark\_vieira](https://sea1.discourse-cdn.com/gradle/user_avatar/discuss.gradle.org/mark_vieira/32/5396_2.png) [@mark\_vieira](https://discuss.gradle.org/u/mark_vieira)
#### Post date: [January 13, 2016, 1:33am UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652/3 "2016-01-13T01:33:02Z")

</div>

Actually I recant my previous response as that only applies to authenticating to repositories. That does not affect proxy authentication. There’s no workaround for this at the moment aside from possibly investigating why the proxy is incorrectly returning a 500.

---

<div class="post-metadata">

### Author: ![msch](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@msch](https://discuss.gradle.org/u/msch)
#### Post date: [February 4, 2016, 5:14pm UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652/4 "2016-02-04T17:14:49Z")

</div>

I have looked at the problem some more and something is really weird. I wrote a little test program that uses the Apache HTTP libraries from the gradle/lib folder to connect to an URL through the proxy and it works fine, even with NTLM and no matter what the domain and workstation strings are set to. I have then compared the HTTP headers of the request sent from my test program and from gradle.

Using the Proxy-Authorization header from gradle and the simple test program (with empty domain & workstation in both cases), I can replicate the problem on the command line with curl, as shown [in this gist](https://gist.github.com/anonymous/a6e21d674d45280ec9fb). I agree that the proxy should not return a 500, but could it be possible that gradle does something strange with the NTLM header?

This is the code of the test program:

```java
 public class ProxyTest {
    public static void main(String[] args) throws IOException {

        NTCredentials ntcredentials = new NTCredentials("%USER%","%PASSWORD%","","");

        CredentialsProvider credProvider = new BasicCredentialsProvider();
        credProvider.setCredentials(AuthScope.ANY, ntcredentials);
        HttpClient client = HttpClients.custom().setDefaultCredentialsProvider(credProvider).build();

        HttpHost proxy = new HttpHost("%PROXY%", 8080);
        RequestConfig config = RequestConfig.custom().setProxy(proxy).build();

        HttpGet get = new HttpGet("http://repo1.maven.org/maven2/com/puppycrawl/tools/checkstyle/5.6/checkstyle-5.6.pom");
        get.setConfig(config);
        HttpResponse response = client.execute(get);
        String headers = Arrays.toString(response.getAllHeaders());
        System.out.println(headers);
    }
}

```

---

<div class="post-metadata">

### Author: ![mark\_vieira](https://sea1.discourse-cdn.com/gradle/user_avatar/discuss.gradle.org/mark_vieira/32/5396_2.png) [@mark\_vieira](https://discuss.gradle.org/u/mark_vieira)
#### Post date: [February 5, 2016, 5:00am UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652/5 "2016-02-05T05:00:06Z")

</div>

It’s worth noting that Gradle uses the [JCIFS](https://jcifs.samba.org) library implementation for NTLM authentication rather then the one bundled with Apache HttpClient. There might be a subtle difference in default configurations. The relevant code can be found here:

> <https://github.com/gradle/gradle/blob/master/subprojects/resources-http/src/main/java/org/gradle/internal/resource/transport/http/ntlm/NTLMSchemeFactory.java>

---

<div class="post-metadata">

### Author: ![msch](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@msch](https://discuss.gradle.org/u/msch)
#### Post date: [February 5, 2016, 9:31am UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652/6 "2016-02-05T09:31:20Z")

</div>

Thanks for the pointer! With this, I have been able to narrow down the problem to the “Negotiate NTLM2 Key” flag: When it is set, the connection works, when it isn’t set, I get the 500 response.

working: TlRMTVNTUAABAAAAAQIIAA==  
failing: TlRMTVNTUAABAAAAAQIAAA==

I suppose there is no way of getting gradle to set this flag, other than changing the code?

---

<div class="post-metadata">

### Author: ![mark\_vieira](https://sea1.discourse-cdn.com/gradle/user_avatar/discuss.gradle.org/mark_vieira/32/5396_2.png) [@mark\_vieira](https://discuss.gradle.org/u/mark_vieira)
#### Post date: [February 5, 2016, 3:36pm UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652/7 "2016-02-05T15:36:16Z")

</div>

There’s no way for the user to configure this. Perhaps this is something that could be configured on the proxy side to support NTLM auth. It seems the proxy is requiring [session auth](http://davenport.sourceforge.net/ntlm.html#theNtlm2SessionResponse).

---

<div class="post-metadata">

### Author: ![lhotari](https://sea1.discourse-cdn.com/gradle/user_avatar/discuss.gradle.org/lhotari/32/5552_2.png) [@lhotari](https://discuss.gradle.org/u/lhotari)
#### Post date: [February 5, 2016, 7:43pm UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652/8 "2016-02-05T19:43:02Z")

</div>

Looks like there is a difference in the NTLM code in Gradle compared to where it was [originally copied from](http://hc.apache.org/httpcomponents-client-ga/ntlm.html). The original code does special handling for the flags. I wonder why this is missing from Gradle.

---

<div class="post-metadata">

### Author: ![mark\_vieira](https://sea1.discourse-cdn.com/gradle/user_avatar/discuss.gradle.org/mark_vieira/32/5396_2.png) [@mark\_vieira](https://discuss.gradle.org/u/mark_vieira)
#### Post date: [February 6, 2016, 12:19am UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652/9 "2016-02-06T00:19:20Z")

</div>

I’m not certain what the original intention was other than perhaps thinking going with the default flags was a good starting point. I’m also no sure what this would mean from a compatibility standpoint to change this. Making this configurable seems like it would be a good idea, perhaps by exposing some system properties.

---

<div class="post-metadata">

### Author: ![daz](https://sea1.discourse-cdn.com/gradle/user_avatar/discuss.gradle.org/daz/32/2475_2.png) [@daz](https://discuss.gradle.org/u/daz)
#### Post date: [February 10, 2016, 2:34am UTC](https://discuss.gradle.org/t/issues-with-proxy-using-basic-authentication/13652/10 "2016-02-10T02:34:03Z")

</div>

> [@lhotari](#):
>
> Looks like there is a difference in the NTLM code in Gradle compared to where it was originally copied from. The original code does special handling for the flags. I wonder why this is missing from Gradle.

I’m pretty sure the code in Gradle is a direct copy of [http://hc.apache.org/httpcomponents-client-ga/ntlm.html](http://hc.apache.org/httpcomponents-client-ga/ntlm.html) as it was published at the time (HTTP Client 4.1.2). There’s no reason that we shouldn’t update it to the current published version, except that we don’t have sufficient test coverage for NTML so we might break something.

> <https://github.com/gradle/gradle/commit/08fbe040d3587e9ddc815078462180531c94333a>
>
> \- Added JCIFS to NOTICE and LICENSE files
