Over the weekend, the Sectigo AddTrust External CA Root expired. For modern browsers, this should not have made any difference for users of affected sites.
Our PHP application connects to a site which we don't control, which includes this expired root in its certificate bundle. We connect using curl, and verify the certificates. But since this root is now expired, curl is now refusing to connect, with an error that the certificate is expired.
There is a sample site which exhibits the same behaviour at https://addtrustchain.test.certificatetest.com/
And sample code which exhibits the same behaviour is
$ch = curl_init();
$url = 'https://addtrustchain.test.certificatetest.com/';
//$url = 'https://google.com';
$caPath = '/path/to/cacert.pem';
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch,CURLOPT_SSL_VERIFYPEER, true);
curl_setopt($ch,CURLOPT_SSL_VERIFYHOST, 2);
curl_setopt($ch,CURLOPT_CAINFO, $caPath);
$output = curl_exec($ch);
var_dump($output);
var_dump(curl_getinfo($ch));
var_dump(curl_errno($ch));
var_dump(curl_error($ch));
curl_close($ch);
Is there a workaround from the php side where we can ignore the expired root certificate provided in the bundle? We're trying to work with the parties on the other side to remove/update the expired root from their bundle, but it would be great to have a solution from our side for the next time this comes up.
I have tried updating our local cacert.pem to include the actual certificate itself, and the provided intermediaries, but neither of those seems to fix the issue.