You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP stream_context_create证书验证失败,SSL连接服务器遇阻求助

Fixing "SSL operation failed with certificate verify failed" in PHP stream_socket_client

Let’s break down this verification error and fix it step by step—here are the most likely issues and actionable solutions:

1. You’re using the wrong certificate file for cafile

This is the most critical mistake here. Your fullchain.pem is the server-side certificate chain (your site’s certificate + Let’s Encrypt intermediate certificates), but the client needs a file containing trusted root CA certificates to validate that the server’s certificate was issued by a legitimate authority.

To fix this:

  • Use your system’s default trusted CA bundle. On most Linux systems, this lives at /etc/ssl/certs/ca-certificates.crt. Update your context to use this path:
    $context = stream_context_create([
        'ssl' => [
            'verify_peer' => true,
            'verify_peer_name' => true,
            'cafile' => '/etc/ssl/certs/ca-certificates.crt',
        ]
    ]);
    
  • If your system doesn’t have this file, you can use the official Let’s Encrypt root CA bundle (which includes trusted roots like ISRG Root X1/X2) instead.

2. Verify the server’s certificate chain is complete

Even with the right client CA bundle, the server might not be sending the full certificate chain. Run this command to check:

openssl s_client -connect bch.curalle.ovh:50002 -showcerts

Look for these key details in the output:

  • A final line that says Verify return code: 0 (ok)—a non-zero code means the server’s chain is broken.
  • Confirm the output includes multiple certificates (your server cert + Let’s Encrypt intermediate certs). If only one certificate is listed, the server isn’t sending the full chain, and you’ll need to update its SSL configuration to use fullchain.pem instead of just the standalone cert.pem.

3. Ensure certificate file permissions are correct

If you ever need to use a custom CA file (unlikely here, but worth checking), make sure the PHP process has read access to it:

chmod 644 /var/www/mywebsite/fullchain.pem
chown www-data:www-data /var/www/mywebsite/fullchain.pem

Replace www-data with the user/group your PHP process runs as (e.g., apache on some systems).

4. Double-check host and port validity

Confirm there’s no typo in bch.curalle.ovh or port 50002, and that the server is actually listening on that port with SSL enabled. Test basic connectivity with:

telnet bch.curalle.ovh 50002

Or verify SSL functionality directly:

openssl s_client -connect bch.curalle.ovh:50002

Start with fixing the cafile path to use a trusted root CA bundle—this will almost certainly resolve your verification failure.

内容的提问来源于stack exchange,提问作者JackSmith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:59:26