You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

浏览器外所有HTTPS连接均报“unable to get local issuer certificate”错误求助

全局SSL证书验证失败问题排查与解决

问题现象

今日所有浏览器外的HTTPS连接均报错 SSL certificate problem: unable to get local issuer certificate,覆盖Python requests、Node.js fetch、curl等所有工具,仅浏览器可正常访问HTTPS站点。

Windows下的curl测试

❯ curl https://stackoverflow.com
curl: (35) schannel: next InitializeSecurityContext failed: CRYPT_E_NO_REVOCATION_CHECK (0x80092012)

WSL下的curl测试

$ curl https://stackoverflow.com
curl: (60) SSL certificate problem: unable to get local issuer certificate
More details here: https://curl.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the web page mentioned above.

Node.js fetch测试

> fetch("https://stackoverflow.com")
Promise {
  <pending>,
  [Symbol(async_id_symbol)]: 108,
  [Symbol(trigger_async_id_symbol)]: 86
}
> Uncaught [TypeError: fetch failed] {
  [cause]: Error: unable to get local issuer certificate
      at TLSSocket.onConnectSecure (node:_tls_wrap:1674:34)
      at TLSSocket.emit (node:events:519:28)
      at TLSSocket.emit (node:domain:551:15)
      at TLSSocket._finishInit (node:_tls_wrap:1085:8)
      at ssl.onhandshakedone (node:_tls_wrap:871:12)
      at TLSWrap.callbackTrampoline (node:internal/async_hooks:130:17) {
    code: 'UNABLE_TO_GET_ISSUER_CERT_LOCALLY'
  }
}

诊断操作

执行OpenSSL命令检查证书链:

openssl s_client -connect google.com:443

输出显示证书链完整,但验证时无法获取本地根证书:

Connecting to 2404:6800:4012:2::200e
CONNECTED(000001F8)
depth=2 C=US, O=Google Trust Services LLC, CN=GTS Root R1
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=1 C=US, O=Google Trust Services, CN=WR2
verify return:1
depth=0 CN=*.google.com
verify return:1
---
Certificate chain
 0 s:CN=*.google.com
   i:C=US, O=Google Trust Services, CN=WR2
   a:PKEY: id-ecPublicKey, 256 (bit); sigalg: RSA-SHA256
   v:NotBefore: Jul  1 06:35:43 2024 GMT; NotAfter: Sep 23 06:35:42 2024 GMT
 1 s:C=US, O=Google Trust Services, CN=WR2
   i:C=US, O=Google Trust Services LLC, CN=GTS Root R1
   a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
   v:NotBefore: Dec 13 09:00:00 2023 GMT; NotAfter: Feb 20 14:00:00 2029 GMT
 2 s:C=US, O=Google Trust Services LLC, CN=GTS Root R1
   i:C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
   a:PKEY: rsaEncryption, 4096 (bit); sigalg: RSA-SHA256
   v:NotBefore: Jun 19 00:00:42 2020 GMT; NotAfter: Jan 28 00:00:42 2028 GMT
Server certificate
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
subject=CN=*.google.com
issuer=C=US, O=Google Trust Services, CN=WR2
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: ECDSA
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 6552 bytes and written 398 bytes
Verification error: unable to get local issuer certificate
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Server public key is 256 bit
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 20 (unable to get local issuer certificate)
---

已尝试的无效操作

使用命令更新系统CA证书并手动导入,但问题未解决:

Certutil.exe -generateSSTFromWU roots.sst

解决方案建议

1. 检查系统根证书存储完整性

  • 打开Windows证书管理器(certmgr.msc),展开「受信任的根证书颁发机构」→「证书」,确认是否存在GlobalSign Root CA和GTS Root R1等根证书
  • 若缺失,可直接从浏览器导出对应根证书:访问任意HTTPS站点,点击地址栏锁图标→「证书」→「证书路径」,选中根证书→「查看证书」→「详细信息」→「复制到文件」,选择DER编码格式保存后导入到系统根证书存储

2. 修复WSL的CA证书同步

WSL默认使用Windows的CA证书,但可能出现同步异常:

  • 在WSL终端执行以下命令重新同步CA证书:
    sudo update-ca-certificates --fresh
    
  • 若仍无效,可手动将Windows系统证书导出为PEM格式,复制到WSL的/etc/ssl/certs/目录并更新证书索引:
    # 导出Windows根证书为PEM(在PowerShell中执行)
    certutil -dump -f -encode "%USERPROFILE%\Desktop\roots.sst" "%USERPROFILE%\Desktop\roots.pem"
    # 复制到WSL
    cp /mnt/c/Users/你的用户名/Desktop/roots.pem /etc/ssl/certs/
    sudo update-ca-certificates
    

3. 排查系统代理或安全软件干扰

  • 检查是否启用了全局代理,代理可能篡改SSL证书导致验证失败,尝试关闭代理后测试
  • 暂停杀毒软件、防火墙或终端安全防护工具,确认是否是这类软件拦截了证书验证流程

4. 修复系统加密服务

打开命令提示符(管理员权限)执行以下命令:

net stop cryptsvc
ren %systemroot%\System32\catroot2 catroot2.old
net start cryptsvc

重启系统后重新测试HTTPS连接


内容的提问来源于stack exchange,提问作者henry777

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 08:14:54