Bug #72186 [Opn->Fbk]: SSL certificate problem: unable to get local issuer certificate

From: Date: Tue, 23 Feb 2021 15:39:44 +0000
Subject: Bug #72186 [Opn->Fbk]: SSL certificate problem: unable to get local issuer certificate
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-232361@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72186&edit=1

 ID:                 72186
 Updated by:         cmb@php.net
 Reported by:        nbhfgq at gmail dot com
 Summary:            SSL certificate problem: unable to get local issuer
                     certificate
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            cURL related
 Operating System:   Windows Server 2012
 PHP Version:        7.0.6
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

I guess this has been resolved in the meantime (I'm using
cacert.pem from curl without problems).  Or is this still an issue
for anyone?


Previous Comments:
------------------------------------------------------------------------
[2018-08-02 12:41:31] anrdaemon at freemail dot ru

I'm using Cygwin-packaged Mozilla trust pack with success.

openssl.cafile =
"C:\Programs\Cygwin_64\etc\pki\ca-trust\extracted\openssl\ca-bundle.trust.crt"
openssl.capath = "C:\Programs\Cygwin_64\usr\ssl\certs"

.capath is for custom certificates. Symlink there and run c_rehash.

------------------------------------------------------------------------
[2016-07-22 23:58:44] nbhfgq at gmail dot com

Any news?

------------------------------------------------------------------------
[2016-06-05 14:02:33] bukka@php.net

I guess the result will be the same for php streams but as this is specifically curl based report,
I'm changing package to cURL related...

------------------------------------------------------------------------
[2016-05-29 18:11:42] nbhfgq at gmail dot com

The source of both the .pem file I have provided is  https://curl.haxx.se/docs/caextract.html. In my
code example, I am explicitly pointing to a .pem file not a os keystore.  So, as I mentioned I also
have a linux instance, running the same php code example.  I do understand my attached .pem files
are not from http://www.cacert.org/?id=3 but I am a client
trying to confirm the certificate presented by google in my example and when using one of the .pem
files (which is just a long list of roots for various CA) it works and anther it does not.

I am not trying to verify a cacert.org signed certificate.

Thanks... Again... George

------------------------------------------------------------------------
[2016-05-29 15:34:24] ab@php.net

I guess this info is useful http://wiki.cacert.org/FAQ/ImportRootCert .
Also, looks like your other cert is not from CAcert, but from some other issuer.

Thanks.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=72186


--
Edit this bug report at https://bugs.php.net/bug.php?id=72186&edit=1


Thread (11 messages)

« previous php.bugs (#232361) next »