CPanel中SSL证书问题:PHP Curl仍报无法获取本地颁发者证书错误
Let’s work through resolving this common SSL error with your Curl setup. Here are the most effective fixes to try:
1. Make Sure Your abc.crt Has a Complete Certificate Chain
This error almost always stems from an incomplete trust chain in your CA file. Your abc.crt shouldn’t only contain the website’s SSL certificate—it needs to include all intermediate certificates plus the root CA certificate, concatenated in this order:
- First: The end-entity (website) certificate
- Next: Intermediate CA certificates (ordered from closest to the website to the root)
- Last: The root CA certificate
You can grab the full chain from your SSL provider, or use this command to extract all certificates from the live site and save them into abc.crt:
openssl s_client -connect website.com:443 -showcerts > abc.crt
2. Use an Absolute Path for CURLOPT_CAINFO
getcwd() might not point to the directory you expect (especially in a cPanel environment, where PHP’s working directory could differ from your script’s location). Replace the dynamic path with a full absolute path to eliminate confusion:
// Replace with your actual file path (e.g., /home/yourcpaneluser/public_html/abc.crt) curl_setopt($ch, CURLOPT_CAINFO, "/full/path/to/abc.crt");
3. Verify php.ini Configurations Are Applied
Even if you updated php.ini, changes won’t take effect until you restart your web server (Apache or Nginx in cPanel). Double-check these two settings in your php.ini:
curl.cainfo = "/path/to/your/ca-bundle.pem" openssl.cafile = "/path/to/your/ca-bundle.pem"
After updating, restart the web server via cPanel’s "Restart Services" section, then run phpinfo() to confirm the settings are active.
4. Debug with Temporary Disabling (Testing Only!)
To confirm the issue is certificate-related, you can temporarily disable peer verification (never do this in production—it’s insecure):
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
If the request works with this setting, you know the problem lies with your CA certificate chain or path—head back to steps 1-3 to fix it properly.
Your Code with Suggested Adjustments
Here’s your original code with the absolute path fix added:
$fields['username'] = "Pass@1234"; $fields['password'] = "harsha"; $POSTFIELDS = http_build_query($fields); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, 'https://website.com'); curl_setopt($ch, CURLOPT_POSTFIELDS,$POSTFIELDS); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_COOKIEJAR, "cookies.txt"); curl_setopt($ch, CURLOPT_COOKIEFILE, "cookies.txt"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); // Use absolute path here curl_setopt($ch, CURLOPT_CAINFO, "/home/yourcpaneluser/public_html/abc.crt"); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3"); curl_setopt($ch, CURLOPT_REFERER, "https://website.com"); $page = curl_exec($ch) or die(curl_error($ch)); echo $page;
内容的提问来源于stack exchange,提问作者harsha ambadkar

