Tutorial

How to Set Up a Proxy on openSUSE

Set a proxy on openSUSE Tumbleweed and Leap 15 or 16: /etc/sysconfig/proxy, PROXY_ENABLED, zypper, services, passwords, exceptions, and turning it off.

HProxy Team··Updated October 4, 2026·7 min read
HProxy.Tutorial

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.44/GB, pay as you go.

See plans & pricing→

openSUSE keeps its whole proxy setup in one file, /etc/sysconfig/proxy. Logins, systemd services and zypper all read it, each in its own way, and two details of how they read it decide whether it works: the order of the lines, and which characters survive in a password. This page covers Tumbleweed, Leap 15 and Leap 16, which has no YaST.

We did not install openSUSE for this page. Every statement comes from the code that reads the file, on 4 October 2026: openSUSE's aaa_base package (the file's template, the login script and the systemd helper) and libzypp, the library behind zypper, plus the Leap 16.0 release notes.

What reads /etc/sysconfig/proxyHowWhen it changes
zypperlibzypp opens the file itselfAt once, with or without sudo
Terminals and SSH loginsprofile.sh exports the variablesAt the next login
systemd servicesA path unit copies them into systemdAt once; restart a running service
Browsers in GNOME or KDENot this file: their own desktop settingSee the Linux guide
Who reads /etc/sysconfig/proxy on openSUSE

Read it

  • zypper

    libzypp reads the file, PROXY_ENABLED first

  • Logins

    profile.sh exports http_proxy and the rest

  • systemd services

    a path unit writes DefaultEnvironment

Do not

  • Terminals already open

    until you log in again

  • Browsers in GNOME or KDE

    the desktop's own proxy setting

Source: openSUSE aaa_base (sysconfig.proxy, profile.sh, setup-systemd-proxy-env) and libzypp (proxyinfo), master branches

What you need before you start

One proxy line, four parts

198.51.100.7Host:8080Port:hp_ir4k2Username:9fa2c1Password
  • 198.51.100.7:8080:hp_ir4k2:9fa2c1host:port:user:passMost proxy tools and checkers
  • hp_ir4k2:9fa2c1@198.51.100.7:8080user:pass@host:portcurl, requests, most HTTP clients
  • http://hp_ir4k2:9fa2c1@198.51.100.7:8080http://user:pass@host:portAnything taking a full proxy URL

The file takes all four in one address: http://user:pass@host:port. Values shown are examples.

  • A proxy address as host:port, plus a user name and password if the proxy needs a login. If your provider sent the parts in another order, the proxy format guide sorts them out.
  • Root rights through sudo.
  • For a first test, any HTTP entry from our free proxy list will do. Free entries come and go, so test one first; the check further down shows how.
  • Our free proxy setup generator writes the address with the password encoded where it has to be.
Our free proxy list filtered to HTTP on 2 October 2026: 8,276 entries, each row with its address and port, country, anonymity, uptime, speed and a Copy button.
Captured on 2 October 2026 at hproxy.com/free-proxy-list/http. The address and port of a row are the host:port the steps below ask for.

Step 1: fill in /etc/sysconfig/proxy

Open the file as root, for example with sudo nano /etc/sysconfig/proxy. It ships with every value empty and the proxy switched off (1). Change these lines and leave the comments as they are:

PROXY_ENABLED="yes"
HTTP_PROXY="http://198.51.100.7:8080"
HTTPS_PROXY="http://198.51.100.7:8080"
NO_PROXY="localhost,127.0.0.1,.example.com"

With a login, put it into both addresses: http://hp_ir4k2:9fa2c1@198.51.100.7:8080. Use http:// for HTTPS_PROXY too: it names the kind of proxy, not the sites you visit.

Keep PROXY_ENABLED above the address lines, where the file has it. The login script reads the file from the top and skips every proxy line it meets before PROXY_ENABLED="yes" (3), so a file reordered by hand can look right and still give your terminals nothing.

Terminal on our workstation, 4 October 2026: openSUSE's own source shows the proxy file's defaults (PROXY_ENABLED no), the login script's eval and its PROXY_ENABLED test, the systemd path unit watching /etc/sysconfig/proxy, and libzypp's exception matching and proxy-user line.
(1) The file ships switched off. (2) Logins read every value through eval. (3) A proxy line counts only after PROXY_ENABLED is yes. (4) systemd watches the file. (5) zypper ignores a leading dot in exceptions. (6) The one thing zypper takes from ~/.curlrc.

Step 2: what happens when you save

  • zypper uses the proxy at once. libzypp opens /etc/sysconfig/proxy itself, so sudo zypper refresh needs no variables in your environment.
  • systemd services get it within moments: a path unit watches the file (4) and writes the variables into /etc/systemd/system.conf.d/proxy.conf as DefaultEnvironment, then reloads systemd. A service that is already running keeps its old environment until you restart it.
  • Terminals get http_proxy, https_proxy and no_proxy at the next login, from /etc/profile.d/profile.sh. Log out and back in, or open a new SSH session.

Leap 15, Leap 16 and YaST

On Leap 15 and where YaST is installed, YaST, Network Services, Proxy fills in the same file. Older YaST versions also wrote the login into /root/.curlrc, as a reply on the openSUSE Forums found in 2013; zypper reads a proxy-user line from that file and nothing else from it.

openSUSE Leap 16.0 removed YaST and points to Cockpit instead, and the release notes say nothing about a proxy screen. On Leap 16, edit the file as in Step 1: the code that reads it is the same.

A password with special characters

The login script runs every value of the file through eval (2), so the shell gets a say before the variable is set:

In the passwordWhat goes wrongWrite it as
$The shell reads the rest as a variable name%24
a backquoteThe shell runs what follows as a command%60
\The shell can take it as an escape and drop it%5C
@curl stops with Unsupported proxy syntax: the @ before the host has to be the only one%40

zypper percent-decodes the user name and password before it hands them to curl, and curl, wget and git decode them from the variables too, so the proxy receives the password you were given. The proxy format guide has the full list.

Exceptions that zypper understands

zypper reads NO_PROXY from the same file and compares host names only: an entry matches the same host, or any host that ends in a dot followed by the entry. A leading dot is ignored (5), so .example.com and example.com both cover mirror.example.com, and a single * turns the proxy off for everything.

Address ranges do not work there. 10.0.0.0/8 or 192.168.0.0/16, which several guides put into NO_PROXY, match no host at all in zypper. Write the names or the individual addresses of local mirrors instead.

sudo and other commands

zypper does not care about sudo, because it reads the file. Other programs started with sudo depend on what sudo passes on. Check it directly after your next login:

sudo env | grep -i _proxy

If nothing appears, run the command with sudo -E, which keeps your variables for that one command.

Check that it worked

env | grep -i _proxy
cat /etc/systemd/system.conf.d/proxy.conf
sudo zypper refresh
curl -s https://www.cloudflare.com/cdn-cgi/trace | grep ^ip=

The first shows the login's variables, the second the copy for services, the third proves zypper reaches its repositories, and the last shows the address the internet sees, which should be the proxy's. Our IP lookup tells you who owns it.

These come up in the pages and answers that rank for openSUSE and zypper proxy searches:

  • Address ranges in NO_PROXY. zypper matches names, so 10.0.0.0/8 excludes nothing.
  • Forgetting PROXY_ENABLED="yes". The file ships with "no", and then neither zypper nor logins use the addresses below it.
  • A proxy line in /root/.curlrc for zypper. zypper takes only proxy-user from that file; the address has to be in /etc/sysconfig/proxy.
  • "Use YaST" on Leap 16. YaST is gone there; the file is the way.
  • The file's contents as screenshots only. Copying from a picture invites typos in exactly the lines that matter.

Turning it off again

  • Set PROXY_ENABLED="no" in /etc/sysconfig/proxy. Your addresses stay in the file for later.
  • zypper stops using the proxy at once, openSUSE removes /etc/systemd/system.conf.d/proxy.conf and reloads systemd, and the next login has no proxy variables.
  • Restart services that were running, and log in again in open terminals.
  • Remove a proxy-user line from /root/.curlrc if YaST or you put one there.

How we wrote this

We did not install openSUSE for this page. We read the code that handles the proxy on 4 October 2026: from openSUSE's aaa_base, the template of /etc/sysconfig/proxy, the login script profile.sh, and setup-systemd-proxy-env with its path unit; from libzypp, the proxy reader (proxyinfo, including its exception matching) and the code that passes the login to curl. We also read the openSUSE Leap 16.0 release notes. The picture above is our own terminal reading of those sources.

Real problems come from Unix & Linux (a question with 10,203 views), the openSUSE Forums (threads from 2013, 2024 and March 2026) and openSUSE's bug tracker.

Limits: no command on this page ran on openSUSE. The sources are the current development branches, which Tumbleweed follows; Leap ships older builds of the same files. Whether libproxy is installed, which libzypp prefers when it is, was not checked; both paths honour this file. Myrlyn and Cockpit were not read.

Sources

All read on 4 October 2026.

  • openSUSE aaa_base: files/usr/share/fillup-templates/sysconfig.proxy, files/usr/etc/profile.d/profile.sh, files/usr/bin/setup-systemd-proxy-env, setup-systemd-proxy-env.path (github.com/openSUSE/aaa_base).
  • openSUSE libzypp: zypp-curl/proxyinfo (proxyinfo.cc, proxyinfosysconfig.cc, proxyinfoimpl.h), curlconfig.cc, curlhelper.cc, MediaCurl.cc (github.com/openSUSE/libzypp).
  • openSUSE Leap 16.0 release notes (doc.opensuse.org).
  • Unix & Linux question 474152; openSUSE Forums threads 86298, 176324 and 192426; openSUSE bug 731606.
  • Our terminal reading of aaa_base and libzypp, 4 October 2026.

Frequently asked questions

How do I set a proxy on openSUSE?
Edit /etc/sysconfig/proxy as root: set PROXY_ENABLED="yes", HTTP_PROXY and HTTPS_PROXY to http://host:port (or http://user:pass@host:port), and NO_PROXY to the hosts that should skip it. zypper uses it at once, services get it automatically, and terminals after the next login.
How do I set a proxy on openSUSE Leap 16 without YaST?
Leap 16.0 removed YaST, so edit /etc/sysconfig/proxy directly. It is the same file YaST's proxy screen wrote on Leap 15, and zypper, logins and services still read it.
Why does zypper ignore my proxy?
Usually because PROXY_ENABLED is still "no", the file's default. zypper reads /etc/sysconfig/proxy itself and uses the proxy only when PROXY_ENABLED is "yes"; exported variables in your own terminal do not matter to it.
Where does zypper take the proxy username and password from?
From the proxy address in /etc/sysconfig/proxy, written as http://user:pass@host:port. zypper percent-decodes them before handing them to curl, so encode special characters there. A proxy-user line in root's ~/.curlrc also works; a proxy line in ~/.curlrc is not read.
Does the order of the lines in /etc/sysconfig/proxy matter?
Yes, for logins. openSUSE's profile.sh reads the file from the top and skips every proxy line that comes before PROXY_ENABLED="yes". Keep PROXY_ENABLED at the top, where the shipped file has it.
Why does NO_PROXY with 10.0.0.0/8 not work in zypper?
zypper compares host names: an entry matches the same host or any host ending in a dot plus the entry. It does not understand address ranges, so 10.0.0.0/8 matches nothing. List the names or addresses, or *.example.com as .example.com.
Do systemd services use the proxy on openSUSE?
Yes. openSUSE watches /etc/sysconfig/proxy with a path unit; on every change it writes the variables into /etc/systemd/system.conf.d/proxy.conf as DefaultEnvironment and reloads systemd. Restart a running service to give it the new value.
Why does my proxy password break on openSUSE?
Logins read each value of /etc/sysconfig/proxy through eval, so a $, a backquote or a backslash in the password is changed. Percent-encode them: $ as %24, a backquote as %60, a backslash as %5C, @ as %40.
How do I turn the proxy off on openSUSE?
Set PROXY_ENABLED="no" in /etc/sysconfig/proxy. The addresses stay in the file for later; zypper stops using them, openSUSE removes the systemd proxy file, and the next login has no proxy variables.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires. $0.44/GB is the 2,000 GB+ rate; a single gigabyte is $0.50/GB, with no minimum order.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed