OpenSSL::SSL::SSLError: certificate verify failed in Ruby Net::HTTP requests
26K reputation · 25 Jun 2026, 07:38 UTC
Ensure that HTTPS requests made with Ruby's Net::HTTP succeed in production environments where the system may lack a trusted CA certificate bundle. Locally, the default OpenSSL store is usually present, so requests complete without error. In minimal containers or hardened servers, the bundle can be absent, leading to OpenSSL::SSL::SSLError: certificate verify failed. Teams must decide whether to explicitly set ENV['SSL_CERT_FILE'] to point to a bundled CA file or to rely on the host's certificate store, weighing portability, maintenance, and potential side‑effects on other gems that also use OpenSSL.
What are the recommended practices for configuring SSL_CERT_FILE in Ruby applications deployed to containerized environments? How can teams verify that the chosen approach does not interfere with other gems' OpenSSL usage? Is there a reliable way to detect a missing CA bundle at runtime and fall back safely?