Bug #72186 [Com]: SSL certificate problem: unable to get local issuer certificate

From: Date: Thu, 02 Aug 2018 12:41:31 +0000
Subject: Bug #72186 [Com]: SSL certificate problem: unable to get local issuer certificate
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-216537@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72186&edit=1 ID: 72186 Comment by: anrdaemon at freemail dot ru Reported by: nbhfgq at gmail dot com Summary: SSL certificate problem: unable to get local issuer certificate Status: Open Type: Bug Package: cURL related Operating System: Windows Server 2012 PHP Version: 7.0.6 Block user comment: N Private report: N New Comment: I'm using Cygwin-packaged Mozilla trust pack with success. openssl.cafile = "C:\Programs\Cygwin_64\etc\pki\ca-trust\extracted\openssl\ca-bundle.trust.crt" openssl.capath = "C:\Programs\Cygwin_64\usr\ssl\certs" .capath is for custom certificates. Symlink there and run c_rehash. Previous Comments: ------------------------------------------------------------------------ [2016-07-22 23:58:44] nbhfgq at gmail dot com Any news? ------------------------------------------------------------------------ [2016-06-05 14:02:33] bukka@php.net I guess the result will be the same for php streams but as this is specifically curl based report, I'm changing package to cURL related... ------------------------------------------------------------------------ [2016-05-29 18:11:42] nbhfgq at gmail dot com The source of both the .pem file I have provided is https://curl.haxx.se/docs/caextract.html. In my code example, I am explicitly pointing to a .pem file not a os keystore. So, as I mentioned I also have a linux instance, running the same php code example. I do understand my attached .pem files are not from http://www.cacert.org/?id=3 but I am a client trying to confirm the certificate presented by google in my example and when using one of the .pem files (which is just a long list of roots for various CA) it works and anther it does not. I am not trying to verify a cacert.org signed certificate. Thanks... Again... George ------------------------------------------------------------------------ [2016-05-29 15:34:24] ab@php.net I guess this info is useful http://wiki.cacert.org/FAQ/ImportRootCert . Also, looks like your other cert is not from CAcert, but from some other issuer. Thanks. ------------------------------------------------------------------------ [2016-05-26 05:52:42] nbhfgq at gmail dot com Sorry for that... will use gist.github.com next time. For what it is worth, I tried the same thing on a virtual box running linux (Ubuntu 32bit). Installed LAMP and eclipse and tried to run the same code using the same two certs. If it is reasonable I am willing to give you a snapshot of the linux image. I am not sure how php as a client and openssl would be impacted by the fact that the new cacert.pem is not in the windows trust store. Maybe you can point me to a source that can inform me. Thanks... George ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72186 -- Edit this bug report at https://bugs.php.net/bug.php?id=72186&edit=1

« previous php.bugs (#216537) next »