浏览器外所有HTTPS连接均报“unable to get local issuer certificate”错误求助
全局SSL证书验证失败问题排查与解决
问题现象
今日所有浏览器外的HTTPS连接均报错 SSL certificate problem: unable to get local issuer certificate,覆盖Python requests、Node.js fetch、curl等所有工具,仅浏览器可正常访问HTTPS站点。
Windows下的curl测试
❯ curl https://stackoverflow.com curl: (35) schannel: next InitializeSecurityContext failed: CRYPT_E_NO_REVOCATION_CHECK (0x80092012)
WSL下的curl测试
$ curl https://stackoverflow.com curl: (60) SSL certificate problem: unable to get local issuer certificate More details here: https://curl.se/docs/sslcerts.html curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the web page mentioned above.
Node.js fetch测试
> fetch("https://stackoverflow.com") Promise { <pending>, [Symbol(async_id_symbol)]: 108, [Symbol(trigger_async_id_symbol)]: 86 } > Uncaught [TypeError: fetch failed] { [cause]: Error: unable to get local issuer certificate at TLSSocket.onConnectSecure (node:_tls_wrap:1674:34) at TLSSocket.emit (node:events:519:28) at TLSSocket.emit (node:domain:551:15) at TLSSocket._finishInit (node:_tls_wrap:1085:8) at ssl.onhandshakedone (node:_tls_wrap:871:12) at TLSWrap.callbackTrampoline (node:internal/async_hooks:130:17) { code: 'UNABLE_TO_GET_ISSUER_CERT_LOCALLY' } }
诊断操作
执行OpenSSL命令检查证书链:
openssl s_client -connect google.com:443
输出显示证书链完整,但验证时无法获取本地根证书:
Connecting to 2404:6800:4012:2::200e CONNECTED(000001F8) depth=2 C=US, O=Google Trust Services LLC, CN=GTS Root R1 verify error:num=20:unable to get local issuer certificate verify return:1 depth=1 C=US, O=Google Trust Services, CN=WR2 verify return:1 depth=0 CN=*.google.com verify return:1 --- Certificate chain 0 s:CN=*.google.com i:C=US, O=Google Trust Services, CN=WR2 a:PKEY: id-ecPublicKey, 256 (bit); sigalg: RSA-SHA256 v:NotBefore: Jul 1 06:35:43 2024 GMT; NotAfter: Sep 23 06:35:42 2024 GMT 1 s:C=US, O=Google Trust Services, CN=WR2 i:C=US, O=Google Trust Services LLC, CN=GTS Root R1 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Dec 13 09:00:00 2023 GMT; NotAfter: Feb 20 14:00:00 2029 GMT 2 s:C=US, O=Google Trust Services LLC, CN=GTS Root R1 i:C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA a:PKEY: rsaEncryption, 4096 (bit); sigalg: RSA-SHA256 v:NotBefore: Jun 19 00:00:42 2020 GMT; NotAfter: Jan 28 00:00:42 2028 GMT Server certificate -----BEGIN CERTIFICATE----- ... -----END CERTIFICATE----- subject=CN=*.google.com issuer=C=US, O=Google Trust Services, CN=WR2 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: ECDSA Server Temp Key: X25519, 253 bits --- SSL handshake has read 6552 bytes and written 398 bytes Verification error: unable to get local issuer certificate --- New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384 Server public key is 256 bit This TLS version forbids renegotiation. Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 20 (unable to get local issuer certificate) ---
已尝试的无效操作
使用命令更新系统CA证书并手动导入,但问题未解决:
Certutil.exe -generateSSTFromWU roots.sst
解决方案建议
1. 检查系统根证书存储完整性
- 打开Windows证书管理器(
certmgr.msc),展开「受信任的根证书颁发机构」→「证书」,确认是否存在GlobalSign Root CA和GTS Root R1等根证书 - 若缺失,可直接从浏览器导出对应根证书:访问任意HTTPS站点,点击地址栏锁图标→「证书」→「证书路径」,选中根证书→「查看证书」→「详细信息」→「复制到文件」,选择DER编码格式保存后导入到系统根证书存储
2. 修复WSL的CA证书同步
WSL默认使用Windows的CA证书,但可能出现同步异常:
- 在WSL终端执行以下命令重新同步CA证书:
sudo update-ca-certificates --fresh - 若仍无效,可手动将Windows系统证书导出为PEM格式,复制到WSL的
/etc/ssl/certs/目录并更新证书索引:# 导出Windows根证书为PEM(在PowerShell中执行) certutil -dump -f -encode "%USERPROFILE%\Desktop\roots.sst" "%USERPROFILE%\Desktop\roots.pem" # 复制到WSL cp /mnt/c/Users/你的用户名/Desktop/roots.pem /etc/ssl/certs/ sudo update-ca-certificates
3. 排查系统代理或安全软件干扰
- 检查是否启用了全局代理,代理可能篡改SSL证书导致验证失败,尝试关闭代理后测试
- 暂停杀毒软件、防火墙或终端安全防护工具,确认是否是这类软件拦截了证书验证流程
4. 修复系统加密服务
打开命令提示符(管理员权限)执行以下命令:
net stop cryptsvc ren %systemroot%\System32\catroot2 catroot2.old net start cryptsvc
重启系统后重新测试HTTPS连接
内容的提问来源于stack exchange,提问作者henry777
相关产品推荐
相关产品推荐

