# How to specify TLS Client Certificate for ExternalProject/FetchContent

**URL:** https://discourse.cmake.org/t/how-to-specify-tls-client-certificate-for-externalproject-fetchcontent/15000
**Category:** Usage
**Created:** [August 14, 2025, 8:16am UTC](https://discourse.cmake.org/t/how-to-specify-tls-client-certificate-for-externalproject-fetchcontent/15000 "2025-08-14T08:16:42Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![kawk](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/k/d26b3c/32.png) [@kawk](https://discourse.cmake.org/u/kawk)
#### Post date: [August 14, 2025, 8:16am UTC](https://discourse.cmake.org/t/how-to-specify-tls-client-certificate-for-externalproject-fetchcontent/15000/1 "2025-08-14T08:16:42Z")

</div>

Hi,

Is it possible to specify a client certificate for use with GIT or SVN in ExternalProject or FetchContent (or do I have to formulate a custom DOWNLOAD\_COMMAND)?

I have to fetch content from a GIT server that requires clients to present a certificate.

Kolja

---

<div class="post-metadata">

### Author: ![kawk](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/k/d26b3c/32.png) [@kawk](https://discourse.cmake.org/u/kawk)
#### Post date: [August 14, 2025, 8:26am UTC](https://discourse.cmake.org/t/how-to-specify-tls-client-certificate-for-externalproject-fetchcontent/15000/2 "2025-08-14T08:26:50Z")

</div>

Ah, it’s possible using “GIT\_CONFIG http.sslCert=…” etc.

---

<div class="post-metadata">

### Author: ![kawk](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/k/d26b3c/32.png) [@kawk](https://discourse.cmake.org/u/kawk)
#### Post date: [August 14, 2025, 6:04pm UTC](https://discourse.cmake.org/t/how-to-specify-tls-client-certificate-for-externalproject-fetchcontent/15000/3 "2025-08-14T18:04:19Z")

</div>

But that doesn’t apply to submodules when cloning --recursive ☹ - the config is not used when fetching them. Also, I had no luck yet with setting global config beforehand (and I’d like to avoid that anyway)
