If you're still maintaining a server or VPS running CentOS 5 and hit this error when running yum update:
http://mirrorlist.centos.org/?release=5&arch=x86_64&repo=os Error: Cannot find a valid baseurl for repo: base
Don't panic — the packages are still there. You just need to point your repo config to the correct vault mirror. This guide covers all working mirrors in 2026 and the complete fix.
Quick summary: Use http://archive.kernel.org/centos-vault/5.11/ as the baseurl instead of the old mirrorlist. vault.centos.org enforces HTTPS which CentOS 5's old yum/curl cannot handle.
Why yum breaks on CentOS 5
CentOS 5 reached end-of-life on March 31, 2017. After that, the CentOS Project shut down public mirror servers and moved all packages to the vault. The /etc/yum.repos.d/CentOS-Base.repo file on your system still points to mirrorlist.centos.org, which no longer carries CentOS 5 entries — so yum errors out immediately.
Additionally, vault.centos.org now forces an HTTP-to-HTTPS redirect. The old curl and openssl bundled with CentOS 5 cannot negotiate modern TLS cipher suites (TLS 1.2/1.3), so even with the correct URL, connections fail.
CentOS 5.11 is the final CentOS 5 release (September 2014). The vault path is vault.centos.org/5.11/ or archive.kernel.org/centos-vault/5.11/.
Working mirrors in 2026
Two options still serve CentOS 5 packages:
| Mirror | Base URL | Protocol | Works with CentOS 5 |
|---|---|---|---|
| archive.kernel.org | http://archive.kernel.org/centos-vault/5.11/ | HTTP | ✓ Recommended |
| vault.centos.org | https://vault.centos.org/5.11/ | HTTPS only | ✗ TLS too old |
archive.kernel.org/centos-vault is the recommended choice for CentOS 5. It serves content over plain HTTP, which the old yum client can download without any SSL/TLS changes.
Fix with sed (fastest method)
Run these commands as root:
# Step 1: backup the original repo file cp /etc/yum.repos.d/CentOS-Base.repo /etc/yum.repos.d/CentOS-Base.repo.bak # Step 2: comment out all mirrorlist lines sed -i 's|^mirrorlist=|#mirrorlist=|g' /etc/yum.repos.d/CentOS-Base.repo # Step 3: point baseurl to kernel.org vault sed -i 's|^#baseurl=http://mirror.centos.org/centos/\$releasever|baseurl=http://archive.kernel.org/centos-vault/5.11|g' /etc/yum.repos.d/CentOS-Base.repo # Step 4: clear cache and verify yum clean all yum repolist
Note: If the baseurl in your .repo file doesn't match the pattern above (custom config or different format), edit it manually using the template in the next section.
Manual fix (if sed pattern doesn't match)
Open the file with vi /etc/yum.repos.d/CentOS-Base.repo and update it to:
[base] name=CentOS-5.11 - Base #mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=os baseurl=http://archive.kernel.org/centos-vault/5.11/os/$basearch/ gpgcheck=1 gpgkey=http://archive.kernel.org/centos-vault/RPM-GPG-KEY-CentOS-5 [updates] name=CentOS-5.11 - Updates #mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=updates baseurl=http://archive.kernel.org/centos-vault/5.11/updates/$basearch/ gpgcheck=1 gpgkey=http://archive.kernel.org/centos-vault/RPM-GPG-KEY-CentOS-5 [extras] name=CentOS-5.11 - Extras #mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=extras baseurl=http://archive.kernel.org/centos-vault/5.11/extras/$basearch/ gpgcheck=1 gpgkey=http://archive.kernel.org/centos-vault/RPM-GPG-KEY-CentOS-5 [centosplus] name=CentOS-5.11 - Plus #mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=centosplus baseurl=http://archive.kernel.org/centos-vault/5.11/centosplus/$basearch/ gpgcheck=1 enabled=0 gpgkey=http://archive.kernel.org/centos-vault/RPM-GPG-KEY-CentOS-5
Then run:
yum clean all yum repolist yum update
Test mirror connectivity first
Before changing the config, verify the mirror is reachable:
curl -I http://archive.kernel.org/centos-vault/5.11/os/x86_64/ # Should return HTTP/1.1 200 OK # Check your server architecture uname -m # x86_64 = 64-bit, i686 = 32-bit
For 32-bit systems, replace x86_64 with i386 in all URLs and repo file entries.
Expected yum repolist output: You should see repo: base, updates, extras with package counts (base typically lists ~2,000–3,000 packages).
Fix GPG key errors
If you encounter GPG key errors such as GPG key retrieval failed, run:
# Import the GPG key directly from the vault rpm --import http://archive.kernel.org/centos-vault/RPM-GPG-KEY-CentOS-5 # Or temporarily skip gpgcheck (not recommended for production) yum --nogpgcheck install [package-name]
If the server has no internet access at all, download RPM packages manually and install them with rpm -ivh package.rpm.
Alternative: CentOS 5 Docker image
For build or test environments, a Docker image is cleaner than maintaining a physical CentOS 5 install:
# Pull a pre-built image with vault repos already configured docker pull astj/centos5-vault docker run -it astj/centos5-vault /bin/bash # 32-bit variant docker pull themattrix/centos5-vault-i386
These images have /etc/yum.repos.d/ already pointing to the vault — run yum install immediately without any config changes.
When to migrate off CentOS 5
CentOS 5 has had no security patches for over eight years. It carries numerous critical, unpatched vulnerabilities. Consider your usage:
- Production web server — migrate as soon as possible; risk is very high
- Legacy app that must stay on CentOS 5 — containerise with Docker and host on a modern Linux VPS
- Lab / test environment — acceptable, but do not expose ports to the internet
- Internal tools — assess your network access exposure before deciding
The closest migration targets are AlmaLinux 9 or Rocky Linux 9, both supported until 2032 and built from the same RHEL source tree as CentOS — making application migration far simpler than moving to Ubuntu or Debian.
Frequently Asked Questions
Can I still use CentOS 5 packages in 2026?
Yes — all historical packages are preserved at vault.centos.org/5.11/ and archive.kernel.org/centos-vault/5.11/. However no security patches have been issued since EOL in March 2017. Use only for legacy systems or test containers.
Why does yum show "cannot find a valid baseurl for repo: base" on CentOS 5?
Because CentOS shut down its public mirror servers after EOL and moved all packages to the vault. Your /etc/yum.repos.d/CentOS-Base.repo still points to mirrorlist.centos.org which no longer has CentOS 5 entries, so yum cannot resolve any package URLs.
What is the difference between vault.centos.org and archive.kernel.org/centos-vault?
vault.centos.org is the official CentOS archive but enforces HTTPS, and CentOS 5's old yum/curl cannot handle modern TLS cipher suites. archive.kernel.org/centos-vault serves the same content over plain HTTP, which the old yum client can connect to without issues.
Can I install new packages after fixing yum?
Yes — yum install and yum update will work normally. However the packages available are limited to what existed at EOL in 2017. No newer versions will appear because the vault is a frozen snapshot.
Should I migrate away from CentOS 5?
Yes, especially for production servers. Consider AlmaLinux 9, Rocky Linux 9, or Ubuntu 22.04/24.04 which receive active security updates. CentOS 5 has had unpatched vulnerabilities for over eight years and should not handle public-facing workloads.
Migrate from CentOS 5 to a Modern VPS with AsiaGB
AsiaGB VPS supports AlmaLinux, Rocky Linux, Ubuntu and Debian on SSD with 99% uptime. Migrate away from legacy CentOS 5 without the headaches.
See VPS Plans