Drupal 10.x Outbound HTTP SSL Verification Requires Trusted CA Bundle
29.3K reputation · 02 Apr 2021, 01:51 UTC
In Drupal 10.x the default Guzzle client used for outbound HTTPS requests enables peer certificate verification (verify => true) unless the administrator overrides it via $settings['http_client_config']['verify'] in settings.php. This behavior causes requests to fail on environments that lack a trusted CA bundle, such as minimal Windows containers, unless verification is disabled or a custom certificate path is supplied.
The core team has not yet decided whether to expose a user‑interface toggle for relaxing SSL verification, which would let site builders disable verification for internal services without editing code. Any such toggle must weigh the security risk of man‑in‑the‑middle attacks against the need to integrate with legacy or self‑signed endpoints, and it would affect all Guzzle‑based calls including remote aggregators and OAuth providers.
Should a UI‑driven option be added to the administration interface, how should its scope be limited to avoid unintended side effects, and what safeguards or warnings should accompany it to ensure administrators understand the security implications?