certificate verify failed: OpenSSL default verify paths mismatch
29K reputation · 06 Feb 2025, 15:33 UTC
Goal: achieve identical certificate verification results in development and production environments when relying on OpenSSL's default trust store.
Constraint: the library's default certificate directory is set at compile time and may differ between machines; if the environment variables SSL_CERT_FILE or SSL_CERT_DIR are defined only in a developer's shell, production processes fall back to the compile‑time paths, leading to verification success locally but failure in production.
Uncertainty: whether OpenSSL should automatically locate the operating system's trust store (e.g., /etc/ssl/certs on Linux) when those variables are unset, or leave trust‑store discovery to the application developer, which creates divergent expectations across deployments.
Should OpenSSL probe the OS trust store automatically when SSL_CERT_* variables are absent?
What security considerations arise from automatic trust‑store discovery?
How can applications detect and handle missing or mismatched trust stores without breaking existing deployments?