Composer安装失败:curl/CACERT证书验证错误求助
解决Composer安装中的SSL证书验证失败问题
错误详情
Composer安装时触发如下错误:
The Composer installer script was not successful [exit code 1]. OpenSSL failed with a 'certificate verify failed' error. This indicates a problem with the Certificate Authority file(s) on your system, which may be out of date. Certificate location [from openssl.cafile ini setting]: C:\php\cacert.pem The php.ini used by your command-line PHP is: C:\xampp\php\php.ini Script Output: The "https://getcomposer.org/versions" file could not be downloaded: SSL operation failed with code 1. OpenSSL Error messages: error:0A000086:SSL routines::certificate verify failed Failed to enable crypto Failed to open stream: operation failed
curl测试同样报错,执行命令 curl --cacert "C:\xampp\apache\bin\curl-ca-bundle.crt" https://getcomposer.org/installer 以及测试amazon.com、google.com时输出:
curl: (60) schannel: CertGetCertificateChain trust error CERT_TRUST_IS_PARTIAL_CHAIN More details here: https://curl.se/docs/sslcerts.html curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the webpage mentioned above.
已尝试的排查操作
- 重新安装XAMPP
- 下载新版CACERT.PEM
- 系统恢复至之前可正常运行的还原点
- 检查所有证书有效期及状态
- 关闭防火墙和杀毒软件后运行Composer安装程序
- 执行
openssl s_client -CAfile "C:\php\cacert.pem" -connect www.amazon.com:443检查OpenSSL,结果正常 - 尝试查找Schannel服务(Windows11中已集成,无法找到)
补充排查与修复步骤
1. 确认PHP CLI的php.ini路径
执行php --ini,查看输出中的Loaded Configuration File,确认是否为你修改的C:\xampp\php\php.ini。部分场景下CLI会加载其他路径的php.ini,导致证书配置未生效。
2. 检查cacert.pem的权限与完整性
- 确认
C:\php\cacert.pem存在,且当前用户拥有读取权限(右键文件→属性→安全,验证账户权限)。 - 重新下载cacert.pem时,直接替换原文件,不要用文本编辑器打开修改(避免编码或格式损坏)。
3. 配置curl使用系统证书存储
Windows下curl可强制使用系统Schannel证书存储,无需指定cacert文件:
- 临时测试命令:
curl --ssl-no-revoke https://getcomposer.org/installer - 永久配置:创建或修改
C:\Users\[你的用户名]\.curlrc文件,添加:ssl-no-revoke = true
4. 修复Windows证书存储的不完整链
- 打开
certmgr.msc,展开受信任的根证书颁发机构→证书,检查是否存在常见根证书(如DigiCert Global Root CA、Amazon Root CA 1等)。 - 若缺失,从浏览器导出对应证书:访问目标网站(如https://getcomposer.org),点击地址栏锁图标→证书→路径,找到根证书,点击「查看证书」→「详细信息」→「复制到文件」,选择DER编码,保存后导入到受信任的根证书颁发机构。
- 运行
certutil -verifyurl -urlfetch https://getcomposer.org/versions,查看证书链的具体错误,定位缺失的中间或根证书。
5. 检查系统代理设置
- 打开设置→网络和Internet→代理,暂时关闭自动/手动代理后测试。
- 检查环境变量中的
HTTP_PROXY、HTTPS_PROXY,若存在则临时删除,重启命令提示符后重试。
6. 重置Windows Schannel配置
以管理员权限打开命令提示符,执行以下命令后重启电脑:
netsh winsock reset netsh advfirewall reset certutil -setreg chain\MinRSAPubKeyBitLength 2048
7. 手动绕过SSL验证安装Composer(临时方案)
仅用于紧急测试,不推荐长期使用:
php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');" -- --disable-tls php composer-setup.php --disable-tls php -r "unlink('composer-setup.php');"
内容的提问来源于stack exchange,提问作者Jeffery Adams
相关产品推荐
相关产品推荐

