In my PHP code, at some point I perform a cURL to an external website. Today, all of a sudden I got this error:
SSL certificate problem: unable to get local issuer certificate
This is the relevant part of my code:
//downloaded from https://curl.haxx.se/docs/caextract.html
//(latest version Wed Oct 14 03:12:15 2020 GMT)
$cacert_pem = realpath("some/path/to/cacert.pem");
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_POST, TRUE);
curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($query_data));
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, TRUE);
curl_setopt($ch, CURLOPT_HEADER, FALSE);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, TRUE);
curl_setopt($ch, CURLOPT_CAINFO, $cacert_pem);
Searching the web for this issue, I came across a lot of questions from this site but none of them really explains what is going on, they just tell to edit php.ini and point to the cacert file, or to update the file to a newer version or do something like this:
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
Which is obviously not recommended...
Then I landed here https://www.offset101.com/fix-ssl-certificate-problem/ and one of the solutions is:
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, $cacert_pem);
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, $cacert_pem);
and the error is gone!
So, my questions are:
- Why is this happening in the first place? I mean, why the code was working yesterday but not today. If I understand correctly, the problem is on my side and not on the external website.
- Is the solution described really fixing the issue or is the same like setting the value to
0? According to the documentation https://www.php.net/manual/es/function.curl-setopt.php, the possible values forCURLOPT_SSL_VERIFYHOSTare either 0, 1 or 2. - And of course...how can I fix this?