Symfony4集成msgraph-sdk-php遇SSL证书错误:unable to get local issuer certificate
Hey there, let's work through this SSL certificate error you're running into. That cURL error 60 means your PHP environment doesn't have the trusted root SSL certificates required to validate Microsoft's OAuth server certificate. Even though you added 'verify' => false to your Guzzle request, it might not be applying correctly, and you should never disable SSL verification in production—it's a major security risk. Here are the right ways to fix this:
1. Configure Trusted CA Certificates (Recommended for All Environments)
This is the safest and most sustainable solution:
- First, download the latest bundle of trusted root CA certificates (like the standard collection maintained by Mozilla). Save this file as
cacert.pemin a secure location in your project (e.g.,config/cacert.pem) or on your server. - Update your Guzzle request to point to this certificate file instead of disabling verification:
$token = json_decode($guzzle->post($url, [ 'form_params' => [ 'client_id' => $clientId, 'client_secret' => $clientSecret, 'resource' => 'https://graph.microsoft.com/', 'grant_type' => 'client_credentials', ], 'verify' => __DIR__ . '/../config/cacert.pem' // Adjust path to match your file location ])->getBody()->getContents()); - For a global fix that applies to all PHP requests, edit your
php.inifile and set these values (replace the path with your actualcacert.pemlocation):
After updating, restart your web server (Apache/Nginx) and PHP-FPM to apply the changes.curl.cainfo = "/path/to/your/cacert.pem" openssl.cafile = "/path/to/your/cacert.pem"
2. Temporarily Disable SSL Verification (Only for Local Testing)
If you're just testing locally and need a quick workaround (again, don't do this in production):
- Double-check that your
'verify' => falsesetting is actually being applied. Sometimes Symfony's global Guzzle client configuration (inconfig/packages/guzzle.yamlif you have it) might override your per-request setting. Make sure there's no conflictingverifyvalue there. - Ensure the
verifyparameter is correctly nested in your Guzzle options array as you have it—typos or misplaced keys can cause it to be ignored.
Quick Side Note: Your Graph API Request Has a Gotcha
One more thing: You're using the client_credentials authorization flow, which doesn't have a user context. That means calling the /me endpoint will fail even after fixing the SSL issue. Instead, you need to target a specific user by ID or email:
$user = $graph->createRequest("GET", "/users/john.doe@yourdomain.com") ->setReturnType(User::class) ->execute();
This will correctly fetch the user's details once your SSL issue is resolved.
内容的提问来源于stack exchange,提问作者VBobCat

