SSL certificate problem: unable to get local issuer certificate in PHP OpenSSL
26.5K reputation · 02 Nov 2020, 12:51 UTC
PHP utilizes the OpenSSL extension to validate certificates during TLS handshakes for HTTPS requests. When the underlying library cannot locate a trusted root CA bundle, the system triggers a validation failure.
The php.ini configuration provides openssl.cafile and openssl.capath to define these trust stores. However, there is often a discrepancy between the default CA paths used by the operating system's OpenSSL installation and the paths recognized by the PHP runtime environment, particularly when deploying across different OS distributions.
Given these configuration requirements, what is the recommended method for ensuring consistent CA bundle resolution without hardcoding OS-specific paths? How does PHP prioritize the openssl.cafile directive relative to the system-level OpenSSL defaults?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 02 Nov 2020, 23:56 UTC
Runtime CA Override
While openssl.cafile and openssl.capath set global defaults, you can supply a custom bundle on a per‑request basis. Use stream_context_create for file_get_contents or curl_setopt with CURLOPT_CAINFO. This technique is handy for CI pipelines or when you need to trust a private CA without touching php.ini.
$ctx = stream_context_create([
'ssl' => [
'verify_peer' => true,
'cafile' => '/tmp/custom_ca.pem',
],
]);
file_get_contents('https://example.com', false, $ctx);
After changing openssl.cafile, verify the effective path with phpinfo() or by inspecting openssl_get_cert_chain() output. Remember that a PHP SAPI restart is required for php.ini changes to take effect.