PHP stream_context_create证书验证失败,SSL连接服务器遇阻求助
Let’s break down this verification error and fix it step by step—here are the most likely issues and actionable solutions:
1. You’re using the wrong certificate file for cafile
This is the most critical mistake here. Your fullchain.pem is the server-side certificate chain (your site’s certificate + Let’s Encrypt intermediate certificates), but the client needs a file containing trusted root CA certificates to validate that the server’s certificate was issued by a legitimate authority.
To fix this:
- Use your system’s default trusted CA bundle. On most Linux systems, this lives at
/etc/ssl/certs/ca-certificates.crt. Update your context to use this path:$context = stream_context_create([ 'ssl' => [ 'verify_peer' => true, 'verify_peer_name' => true, 'cafile' => '/etc/ssl/certs/ca-certificates.crt', ] ]); - If your system doesn’t have this file, you can use the official Let’s Encrypt root CA bundle (which includes trusted roots like ISRG Root X1/X2) instead.
2. Verify the server’s certificate chain is complete
Even with the right client CA bundle, the server might not be sending the full certificate chain. Run this command to check:
openssl s_client -connect bch.curalle.ovh:50002 -showcerts
Look for these key details in the output:
- A final line that says
Verify return code: 0 (ok)—a non-zero code means the server’s chain is broken. - Confirm the output includes multiple certificates (your server cert + Let’s Encrypt intermediate certs). If only one certificate is listed, the server isn’t sending the full chain, and you’ll need to update its SSL configuration to use
fullchain.peminstead of just the standalonecert.pem.
3. Ensure certificate file permissions are correct
If you ever need to use a custom CA file (unlikely here, but worth checking), make sure the PHP process has read access to it:
chmod 644 /var/www/mywebsite/fullchain.pem chown www-data:www-data /var/www/mywebsite/fullchain.pem
Replace www-data with the user/group your PHP process runs as (e.g., apache on some systems).
4. Double-check host and port validity
Confirm there’s no typo in bch.curalle.ovh or port 50002, and that the server is actually listening on that port with SSL enabled. Test basic connectivity with:
telnet bch.curalle.ovh 50002
Or verify SSL functionality directly:
openssl s_client -connect bch.curalle.ovh:50002
Start with fixing the cafile path to use a trusted root CA bundle—this will almost certainly resolve your verification failure.
内容的提问来源于stack exchange,提问作者JackSmith

