URLFetch returns SSLHandshakeFailed on Linux when server omits intermediate certificates
0 reputation · 15 Oct 2023, 18:43 UTC
When using URLFetch with VerifyCertificate->True (the default) to access an HTTPS site that presents a certificate chain missing intermediate certificates, the request succeeds on Windows and macOS but fails with an SSLHandshakeFailed error on Linux. The goal is to determine why this platform‑specific difference occurs and whether the bundled CA bundle used by URLFetch on Linux can be inspected or supplemented without reinstalling Wolfram Language.
Because VerifyCertificate->False disables all validation and is unsafe for production, and because Wolfram Language provides no public API to list or refresh its embedded certificates, users lack a supported method to adjust trust anchors on Linux. Additionally, the exact version‑dependent behavior of the CA bundle selection is not documented, leaving uncertainty about how updates to the underlying trust store would affect URLFetch.
What CA bundle does URLFetch employ on Linux by default? Is there a supported way to extend or replace that bundle without a full reinstall? Does setting VerifyCertificate->False affect any other security checks beyond certificate validation?