# New extension manager and issues with corporate certificates

**URL:** https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361
**Category:** Support
**Tags:** extensions-manager
**Created:** [August 25, 2021, 6:39pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361 "2021-08-25T18:39:59Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)
#### Post date: [August 25, 2021, 6:39pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/1 "2021-08-25T18:39:59Z")

</div>

Today I downloaded a new preview version, and tried to install MoniaLabel and SlicerMorph on my work computers, and encountered this error:

```auto

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.example.com/Slicer/Extensions/BreastImplantAnalyzer.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/b/b9/ChangeTracker_logo.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.example.com/Slicer/Extensions/CleverSeg.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/e/e1/CornerAnnotationIcon.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/b/b7/CurveMakerIcon.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://slicer.org/slicerWiki/images/9/92/DSC_logo_Resized.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/a/ac/ErodeDilateLabelIcon.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/1/16/FilmDosimetry_Logo_128x128.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/f/f1/GelDosimetry_Logo_128x128.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.example.com/Slicer/Extensions/GraphCutSegment.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/a/a7/GyroGuide.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/e/e5/QuickToolsLogo.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://wiki.slicer.org/slicerWiki/images/f/f6/IntensitySegmenterIcon.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/5/56/LAScarSegmenter.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/0/08/LongitudinalPETCTLogo.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/index.php/File:ModelClipIcon.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://slicer.org/slicerWiki/images/4/43/Slicer4ExtensionModelToModelDistance.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/2/2e/OpenCAD.PNG'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/a/ac/PAAlogo-small.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/2/21/PerkTutorLogo.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/b/b1/DPetBrainQuantification.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/a/a7/Portplacement_icon.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://wiki.slicer.org/slicerWiki/images/d/d6/ResectionPlannerLogo.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://viewvc.slicer.org/viewvc.cgi/Slicer4/trunk/Extensions/Testing/SNRMeasurement/SNRMeasurement.png?revision=21745&view=co'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.na-mic.org/Wiki/images/a/ad/Spharm-pdm-icon.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/b/ba/SegAidedRegSquareFocus128.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/5/5b/Slicer-Wasp.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://raw.githubusercontent.com/SlicerDMRI/slicerdmri.github.io/master/images/DMRI_3D_SLICER-icon.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://raw.githubusercontent.com/QIICR/SlicerDevelopmentToolbox/master/Resources/Icons/SlicerDevelopmentToolbox.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/f/ff/SlicerHeart_Logo_128x128.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/2/2b/SlicerIGTLogo.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.example.com/Slicer/Extensions/SlicerNetstim.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://wiki.slicer.org/slicerWiki/images/8/87/SlicerProstate_Logo_1.0_128x128.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/2/29/SlicerRT_Logo_3.0_128x128.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/w/images/6/6b/RadiomicsExtension.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/6/64/SlicerToKiwiExporterLogo.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.nitrc.org/project/screenshot.php?group_id=196&screenshot_id=269'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/c/cd/SwissSkullStripper.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://slicer.org/slicerWiki/images/3/32/T1_Mapping_Logo_Resized.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://wiki.slicer.org/slicerWiki/images/9/92/TCIABrowser_logo.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://www.slicer.org/slicerWiki/images/c/c2/VolumeClipLogo.png'. This content should also be served over HTTPS.

Mixed Content: The page at 'https://extensions.slicer.org/catalog/All/30133/win?q=' was loaded over HTTPS, but requested an insecure image 'http://wiki.slicer.org/slicerWiki/images/5/59/MpReviewLogo.png'. This content should also be served over HTTPS.

Retrieving extension metadata [extensionId: 61260e2b342a877cb3b8d73e]

Retrieving extension files [extensionId: 61260e2b342a877cb3b8d73e]

Downloading extension [item_id: 61260e2b342a877cb3b8d73e, file_id: 61260e2b342a877cb3b8d745]

Failed downloading: https://slicer-packages.kitware.com/api/v1/file/61260e2b342a877cb3b8d745/download

```

This happens both on Linux and WIndows. If I copy and paste the referenced URL to the web browser in the same computer, I can download the file 30133-win-amd64-SlicerMorph-gitf70c039-2021-08-20.zip without an issue.

I suspect this is because our institution uses self-signed certificates in their corporate network. While, the regular OS (browsers and other operations) work fine, somehow this is not getting propagated to the Slicer. Is there a solution for this? Our IT admins consider this as Slicer’s problem, since on the same computer I can get to the specified URL without the error.

@jcfr

---

<div class="post-metadata">

### Author: ![jcfr](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/jcfr/32/17825_2.png) [@jcfr](https://discourse.slicer.org/u/jcfr)
#### Post date: [September 2, 2021, 4:59pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/2 "2021-09-02T16:59:12Z")

</div>

> [@muratmaga](#):
>
> `Mixed Content`

This is because some of the extension icons are server over http.

This will be fixed in the next few weeks.

To help with this, we already developed a Jupyter notebook to identify and check which extensions have issues. The next step will be to harden the notebook and integrate the code into the [Slicer/ExtensionsIndex](https://github.com/Slicer/ExtensionsIndex/pull/1788) continuous integration.

For reference, see [https://github.com/jcfr/jupyter-notebooks/blob/master/45\_slicer\_extensions\_index\_check\_metadata\_urls.ipynb](https://github.com/jcfr/jupyter-notebooks/blob/master/45_slicer_extensions_index_check_metadata_urls.ipynb)

---

<div class="post-metadata">

### Author: ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)
#### Post date: [September 2, 2021, 6:00pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/3 "2021-09-02T18:00:48Z")

</div>

There is also an automatic URL check [implemented in the ExtensionsIndex repository](https://github.com/Slicer/ExtensionsIndex/pull/1788/files) - it just has not been merged yet (it can be used locally, though).

But these http/https warning are not related to the failed download, because I see these warnings on my computer, too, but the download does not fail.

---

<div class="post-metadata">

### Author: ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)
#### Post date: [September 3, 2021, 4:16pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/4 "2021-09-03T16:16:46Z")

</div>

@jcfr is there an update on this? Package download is still failing for me without any detailed error.

This is all there is in the log

```auto
Retrieving extension metadata [extensionId: 61260e2b342a877cb3b8d73e]

Retrieving extension files [extensionId: 61260e2b342a877cb3b8d73e]

Downloading extension [item_id: 61260e2b342a877cb3b8d73e, file_id: 61260e2b342a877cb3b8d745]

Failed downloading: https://slicer-packages.kitware.com/api/v1/file/61260e2b342a877cb3b8d745/download

```

Here is the screenshot that I shows I can get to the same package via wget on the same laptop.

 ![image](https://us1.discourse-cdn.com/flex002/uploads/slicer/original/3X/3/8/38d2bb14666e7f10710633d0eddca393e201b40f.png)

---

<div class="post-metadata">

### Author: ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)
#### Post date: [September 10, 2021, 5:56pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/5 "2021-09-10T17:56:33Z")

</div>

With todays preview, I tried again and still cannot download packages at office (fine at home).

```auto
Retrieving extension metadata [extensionId: 613b26b1342a877cb3bee817]

Retrieving extension files [extensionId: 613b26b1342a877cb3bee817]

Downloading extension [item_id: 613b26b1342a877cb3bee817, file_id: 613b26b1342a877cb3bee81e]

Failed downloading: https://slicer-packages.kitware.com/api/v1/file/613b26b1342a877cb3bee81e/download

```

---

<div class="post-metadata">

### Author: ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)
#### Post date: [September 10, 2021, 6:53pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/6 "2021-09-10T18:53:40Z")

</div>

Can you download the files using Python, in Slicer’s Python environment (using wget, curl, requests,…)?

---

<div class="post-metadata">

### Author: ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)
#### Post date: [September 10, 2021, 7:06pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/7 "2021-09-10T19:06:48Z")

</div>

This seems to work. At least it is finding the filename correct, I do not know how to write

```auto
>>> import wget
>>> url = "https://slicer-packages.kitware.com/api/v1/file/613b26b1342a877cb3bee81e/download"
>>> filename = wget.download(url)
>>> filename
'30168-win-amd64-SlicerMorph-gitf70c039-2021-08-20.zip'

```

---

<div class="post-metadata">

### Author: ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)
#### Post date: [September 10, 2021, 7:22pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/8 "2021-09-10T19:22:33Z")

</div>

OK, this is useful information (the file is saved in the current working directory).

Does the download work using Qt with the code snippet below?

```python
url = qt.QUrl("https://slicer-packages.kitware.com/api/v1/file/613b26b1342a877cb3bee81e/download")
request = qt.QNetworkRequest(url)
manager = qt.QNetworkAccessManager()
reply = manager.get(request)

while (not reply.isFinished()):
    slicer.app.processEvents()

localFile = qt.QFile("c:/tmp/downloaded2.zip")
localFile.open(qt.QIODevice.WriteOnly)
localFile.write(reply.readAll());
localFile.close()

print(f"HTTP response code: {reply.attribute(qt.QNetworkRequest.HttpStatusCodeAttribute)}")
print(f"Error code: {reply.error()}")

```

---

<div class="post-metadata">

### Author: ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)
#### Post date: [September 10, 2021, 7:29pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/9 "2021-09-10T19:29:16Z")

</div>

> [@lassoan](#):
>
> ```auto
> url = qt.QUrl("https://slicer-packages.kitware.com/api/v1/file/613b26b1342a877cb3bee81e/download")
> request = qt.QNetworkRequest(url)
> manager = qt.QNetworkAccessManager()
> reply = manager.get(request)
> 
> localFile = qt.QFile("c:/tmp/downloaded.zip")
> localFile.open(qt.QIODevice.WriteOnly)
> localFile.write(reply.readAll());
> localFile.close()
> 
> ```

There is now a downloaded.zip file in c:/tmp but it is 0 bytes.

```auto
>>> localFile = qt.QFile("c:/temp/downloaded.zip")
>>> localFile.open(qt.QIODevice.WriteOnly)
True
>>> localFile.write(reply.readAll());
0
>>> localFile.close()

```

---

<div class="post-metadata">

### Author: ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)
#### Post date: [September 10, 2021, 7:33pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/10 "2021-09-10T19:33:33Z")

</div>

Sorry, I forgot to say that you need to wait for the request to complete before you read out the result. I’ve updated the code above to wait so that you don’t need to wait manually. Try again with the updated code snippet.

---

<div class="post-metadata">

### Author: ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)
#### Post date: [September 10, 2021, 7:35pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/11 "2021-09-10T19:35:40Z")

</div>

> [@lassoan](#):
>
> ```auto
> url = qt.QUrl("https://slicer-packages.kitware.com/api/v1/file/613b26b1342a877cb3bee81e/download")
> request = qt.QNetworkRequest(url)
> manager = qt.QNetworkAccessManager()
> reply = manager.get(request)
> 
> while (not reply.isFinished()):
> slicer.app.processEvents()
> 
> localFile = qt.QFile("c:/tmp/downloaded2.zip")
> localFile.open(qt.QIODevice.WriteOnly)
> localFile.write(reply.readAll());
> localFile.close()
> 
> print(f"HTTP response code: {reply.attribute(qt.QNetworkRequest.HttpStatusCodeAttribute)}")
> print(f"Error code: {reply.error()}")
> 
> ```

Still 0.

```auto

>>> url = qt.QUrl("https://slicer-packages.kitware.com/api/v1/file/613b26b1342a877cb3bee81e/download")
>>> request = qt.QNetworkRequest(url)
>>> manager = qt.QNetworkAccessManager()
>>> reply = manager.get(request)
>>>
>>> while (not reply.isFinished()):
... slicer.app.processEvents()
...
>>> localFile = qt.QFile("c:/temp/downloaded2.zip")
>>> localFile.open(qt.QIODevice.WriteOnly)
True
>>> localFile.write(reply.readAll());
0
>>> localFile.close()
>>>
>>> print(f"HTTP response code: {reply.attribute(qt.QNetworkRequest.HttpStatusCodeAttribute)}")
HTTP response code: None
>>> print(f"Error code: {reply.error()}")
Error code: 6
>>>

```

---

<div class="post-metadata">

### Author: ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)
#### Post date: [September 10, 2021, 7:37pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/12 "2021-09-10T19:37:02Z")

</div>

Great, you’ve managed to reproduce the problem!

What is the output of `reply.errorString()`?

---

<div class="post-metadata">

### Author: ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)
#### Post date: [September 10, 2021, 7:37pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/13 "2021-09-10T19:37:55Z")

</div>

‘SSL handshake failed’

---

<div class="post-metadata">

### Author: ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)
#### Post date: [September 10, 2021, 7:44pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/14 "2021-09-10T19:44:11Z")

</div>

Perfect! Now you have everything to debug this problem and find how to fix the SSL configuration to make the handshake happen (by fixing the root cause of the error or making the error ignored). See all the configuration options in the [network access manager](https://doc.qt.io/qt-5/qnetworkaccessmanager.html) and the [network request](https://doc.qt.io/qt-5/qnetworkrequest.html).

---

<div class="post-metadata">

### Author: ![pieper](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/pieper/32/8_2.png) [@pieper](https://discourse.slicer.org/u/pieper)
#### Post date: [September 10, 2021, 9:13pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/15 "2021-09-10T21:13:01Z")

</div>

Can anyone else replicate this issue or suggest what might be the solution? It sounds like this is something to do with the institutional firewall and [SSL certificate management](https://doc.qt.io/qt-5/qsslconfiguration.html).

---

<div class="post-metadata">

### Author: ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)
#### Post date: [September 10, 2021, 9:31pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/16 "2021-09-10T21:31:53Z")

</div>

> [@lassoan](#):
>
> Perfect! Now you have everything to debug this problem and find how to fix the SSL configuration to make the handshake happen (by fixing the root cause of the error or making the error ignored). See all the configuration options in the [network access manager](https://doc.qt.io/qt-5/qnetworkaccessmanager.html) and the [network request](https://doc.qt.io/qt-5/qnetworkrequest.html).

I won’t know where to start with those.

However, as Steve pointed out I think this is most likely related to certificate. On the same computers, when I install the windows Git, if I do not choose to trust the windows certificate store, git would fail with the same error. A more detailed description of this is here (see the first answer): [How do I configure Git to trust certificates from the Windows Certificate Store? - Stack Overflow](https://stackoverflow.com/questions/16668508/how-do-i-configure-git-to-trust-certificates-from-the-windows-certificate-store)

Is there a way to test this option for Slicer as well?

---

<div class="post-metadata">

### Author: ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)
#### Post date: [September 10, 2021, 9:32pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/17 "2021-09-10T21:32:48Z")

</div>

> [@pieper](#):
>
> Can anyone else replicate this issue or suggest what might be the solution? It sounds like this is something to do with the institutional firewall and [SSL certificate management](https://doc.qt.io/qt-5/qsslconfiguration.html).

Yes, I really appreciate if any Slicer users behind corporate firewalls with self-signed certificates can try this and see if this happens to others as well.

---

<div class="post-metadata">

### Author: ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)
#### Post date: [September 10, 2021, 10:27pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/18 "2021-09-10T22:27:39Z")

</div>

> I won’t know where to start with those.

Just Google `qt linux "SSL handshake failed"` and try all the solutions that people recommend. It should be easy to disable verification, but it would be much nicer if you found out where Python gets the certificates from and make Qt find those, too. But maybe Python (wget) just does not verify the certificates by default.

You may be able to add your self-signed certificate to the certificate file in share\Slicer-4.13\Slicer.crt. See more information [here](https://github.com/Slicer/Slicer/tree/master/Base/QTCore/Resources/Certs).

---

<div class="post-metadata">

### Author: ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)
#### Post date: [September 10, 2021, 10:56pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/19 "2021-09-10T22:56:49Z")

</div>

OK. Will try those but looking at this example from your link, I am getting this error

```auto
 w = slicer.qSlicerWebWidget()
 w.show()
 v = w.webView()
 v.setUrl(qt.QUrl("https://www.eff.org/https-everywhere"))
Traceback (most recent call last):
  File "<console>", line 1, in <module>
AttributeError: QWebEngineView has no attribute named 'setUrl'

```

---

<div class="post-metadata">

### Author: ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)
#### Post date: [September 10, 2021, 11:42pm UTC](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361/20 "2021-09-10T23:42:46Z")

</div>

We have a very good, simple way to reproduce the error, just stick to that for now (the qSlicerWebWidget contains a full web browser, i.e., an entire operating system, so that could complicate things).

Just check what is needed to make the simple download code snippet work.

For example, check if [disabling verification](https://stackoverflow.com/a/26016487/12370111) fixes the issue. If it does, then that could be a simple, universal workaround that we could expose, if needed (and if we don’t find a safer solution).

Another idea to try: [select different protocol](https://www.qtcentre.org/threads/18762-QNetworkAccessManager-quot-SSL-handshake-failed-quot?p=92768#post92768).

[Next page](https://discourse.slicer.org/t/new-extension-manager-and-issues-with-corporate-certificates/19361.md?page=2)
