PuppyIP Resource Center
AI Coding Tools 10 min Published 2026-08-17

GitHub Copilot Enterprise Proxy Configuration: Variable Priority, Kerberos and CA Troubleshooting

For developers and administrators whose Copilot works on a home network but fails to sign in, reports certificate errors or stays offline on enterprise or campus networks.

GitHub Copilot Enterprise proxies Kerberos Custom CA NODE_EXTRA_CA_CERTS

Service eligibility and regional restrictions

PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.

Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.

Key Takeaways

  • Copilot supports basic HTTP proxies and Kerberos. Official guidance currently does not support proxy URLs starting with https://.
  • Proxy variables are selected in this order: HTTPS_PROXY, https_proxy, HTTP_PROXY, http_proxy. The highest-priority value is used for both HTTP and HTTPS requests.
  • In Kerberos environments, check the ticket, proxy hostname and SPN together. Use AGENT_KERBEROS_SERVICE_PRINCIPAL for an explicit override when necessary.
  • For certificate errors caused by enterprise TLS inspection, supply a trusted CA through the system trust store or NODE_EXTRA_CA_CERTS. Do not disable certificate verification.
  • Use editor logs to distinguish proxy connections, 407, TLS and account permissions before blindly changing environment variables across clients.

Confirm that this is the applicable scenario

If Copilot works on a normal network but fails behind an enterprise proxy, prioritize proxy authentication, variable selection and the enterprise CA. If every network reports missing permissions, subscriptions or organization policy, address the account and administrator authorization first. This article is not for bypassing organization policies, device management or regional restrictions.

Save the editor version, Copilot extension version, error time and redacted logs. Distinguish 407, connection timeouts, certificate-chain errors and server-side 401/403 first, then use the proxy connection troubleshooting checklist for the corresponding layer.

Proxy URLs: Why https:// is not supported here

GitHub's official guidance states that Copilot supports basic HTTP proxies, including HTTPS destination traffic carried through them, but currently does not support proxy URLs that themselves start with https://. Here, http:// describes how the client connects to the proxy; it does not mean TLS is disabled when accessing Copilot services.

Confirm the host, port and authentication method supplied by the proxy administrator. Do not apply the destination website's usual https:// scheme to the proxy URL. Do not put credentials directly into shareable editor settings, screenshots or repositories. Enterprises should prefer managed configuration and integrated authentication.

Which of the four environment variables is selected?

Copilot selects proxies in the order HTTPS_PROXY, https_proxy, HTTP_PROXY, http_proxy, and uses the highest-priority value found for both HTTP and HTTPS requests. When multiple variables point to different proxies, terminal tests may succeed while the editor still uses another address.

During investigation, read only variable names, their sources and redacted hosts and ports. Clear conflicting values, restart the relevant editor process, then confirm the actual proxy in the logs. Do not assume system settings, terminals and editors launched from desktop icons inherit identical environments.

Checking Kerberos and SPNs

For an enterprise single-sign-on proxy, first confirm that the device has joined the appropriate domain, the current user has a valid Kerberos ticket, and the proxy hostname matches DNS. If the proxy expects a service principal name different from the automatically derived value, set AGENT_KERBEROS_SERVICE_PRINCIPAL to the exact value supplied by the administrator.

Do not guess an SPN or repeatedly try personal account passwords. If 407 persists, ask the network administrator to check supported proxy-authentication schemes, time synchronization, tickets and server logs. Switching networks can help locate the issue, but does not authorize bypassing enterprise controls.

Enterprise CAs and NODE_EXTRA_CA_CERTS

TLS-inspection devices reissue connection certificates using an enterprise CA. Copilot can use the operating-system trust store, or receive an additional CA file through NODE_EXTRA_CA_CERTS. Importing a certificate only in the browser may not cover the Node runtime inside the editor.

Obtain the CA file from the enterprise security team and verify its fingerprint, validity period and file permissions. Do not configure TLS-verification bypasses or download unknown certificates from forums. After configuration, fully exit and restart the editor, then check whether the failure has progressed from the certificate-chain stage to a normal service response.

Minimal diagnostic order

Check in order: first, account and organization authorization; second, destination-domain resolution; third, connectivity to the proxy port; fourth, the proxy ultimately selected by the variables; fifth, whether the issue is 407/Kerberos; sixth, whether the enterprise CA correctly validates the certificate chain; and seventh, the request ID and server status in the editor's Copilot logs. Change only one condition at each step.

If your team needs stable access to overseas code hosting, AI coding services and official documentation, visit the PuppyIP website to learn about fixed network egress. Network egress cannot replace a Copilot subscription, organization authorization, Kerberos identity or enterprise CA management.

Sources

Frequently Asked Questions

Can a Copilot proxy address start with https://?

GitHub's current official guidance does not support proxy URLs starting with https://. Use the supported HTTP proxy configuration supplied by your administrator.

Which is used when both HTTP_PROXY and HTTPS_PROXY are set?

Copilot selects the highest-priority value in the order HTTPS_PROXY, https_proxy, HTTP_PROXY, http_proxy, and uses it for both request types.

Does Copilot support Kerberos proxies?

Yes. Confirm the ticket and proxy hostname first. In special environments, an administrator can guide configuration of AGENT_KERBEROS_SERVICE_PRINCIPAL.

Why does Copilot still report an error when the browser trusts the enterprise certificate?

The editor's runtime may use the system trust store or an additional CA file. Check NODE_EXTRA_CA_CERTS according to official guidance.

Can I disable TLS verification to fix certificate errors?

You should not. Obtain and verify the correct CA from the enterprise security team and repair the trust chain.

Can changing proxies fix a missing Copilot subscription or an organization disabling it?

No. Networking only affects the connection path. GitHub or the organization administrator must handle subscriptions, organization policies and account permissions.