For those who are looking for an immediate solution, here is a bit more technical details on top of the information @preston-phx and @houdi provided:
As mentioned on Paypal's article: https://www.paypal.com/us/smarthelp/article/migration-to-digicert-root-certificates-ts2240
Download the "DigiCert High Assurance EV Root CA" and "DigiCert Global Root G2" certificates from Digicert here:
https://www.digicert.com/kb/digicert-root-certificates.htm
Also, download certificates for all Paypal APIs you are making calls to from:
https://www.paypal.com/us/smarthelp/article/ts1510
(In my case, I only use api.paypal.com so I downloaded api.paypal.com.pem and api.sandbox.paypal.com.pem)
These will give you a set of pem files like:
DigiCertGlobalRootG2.crt.pem
DigiCertHighAssuranceEVRootCA.crt.pem
api.paypal.com.pem
api.sandbox.paypal.com.pem
Merge all your files to a single paypal.crt file, which will look like:
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
...
Put the file somewhere in your project. I put it under data/paypal.crt similar to where the PayPal-Ruby-SDK stores it.
Now you can monkey patch the SDK to use your paypal.crt file instead of the ouut-dated one provided in the SDK by adding the following snippet somewhere before where you initialize your PayPal SDK:
# Monkey patch the paypal certificate file
PayPal::SDK::Core::Util::HTTPHelper.class_eval do
def default_ca_file
File.expand_path("../../data/paypal.crt", __dir__)
end
end
I'm using Rails so I added that directly to the top of my config/initializers/paypal.rb file.
(I'm not providing any direct links to the certificates or the certificates themselves here because you should never trust any certificate provided by a third-party. Download all certificates directly from PayPal and Digicert sites)