# Why does curl not trust letsencrypt?

**URL:** https://community.letsencrypt.org/t/why-does-curl-not-trust-letsencrypt/183585
**Category:** Help
**Created:** [August 29, 2022, 2:24am UTC](https://community.letsencrypt.org/t/why-does-curl-not-trust-letsencrypt/183585 "2022-08-29T02:24:18Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![super](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@super](https://community.letsencrypt.org/u/super)
#### Post date: [August 29, 2022, 2:24am UTC](https://community.letsencrypt.org/t/why-does-curl-not-trust-letsencrypt/183585/1 "2022-08-29T02:24:18Z")

</div>

When a PHP site makes a CURL call into a site protected with a Lets Encrypt cert it fails with this error:

- SSL certificate problem: unable to get local issuer certificate

I took a cursory glance at cacert.pem installed and found no mention of Lets Encrypt. Is it not included in CURL's cacert.pem? Why? Is it possible to add it?

---

<div class="post-metadata">

### Author: ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)
#### Post date: [August 29, 2022, 2:35am UTC](https://community.letsencrypt.org/t/why-does-curl-not-trust-letsencrypt/183585/2 "2022-08-29T02:35:47Z")

</div>

Yes, most modern systems will have the Let's Encrypt root cert.

What operating system are you using?  
What version is it?  
What is an example URL if the failing site? (the site may be mis-configured, we'll check)

What happens with this command? (just show first few lines if not an error)

```nohighlight
curl -I https://community.letsencrypt.org

```

---

<div class="post-metadata">

### Author: ![super](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@super](https://community.letsencrypt.org/u/super)
#### Post date: [August 29, 2022, 2:21pm UTC](https://community.letsencrypt.org/t/why-does-curl-not-trust-letsencrypt/183585/3 "2022-08-29T14:21:09Z")

</div>

CURL can successfully download from sites with other issuers' certs, for example from Youtube. The site is behind a tightly locked FW, so I do not have much freedom in testing other sites.  
The site on which CURL fails is considered secure by browsers, and having reviewed Letsencrypt cert installation documents I do not see any possibility for "misconfiguration": the cert is copied from live folder to Apache SSL.crt and SSL.key folders, then Apache loads them. What specifically could be misconfigured despite modern browsers considering the connection secure?

Meanwhile, are you able to review curl's latest [cert](https://curl.se/ca/cacert.pem) and point me at the specific block within it, for Letsencrypt?

---

<div class="post-metadata">

### Author: ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)
#### Post date: [August 29, 2022, 2:35pm UTC](https://community.letsencrypt.org/t/why-does-curl-not-trust-letsencrypt/183585/4 "2022-08-29T14:35:46Z")

</div>

> [@super](#):
>
> The site on which CURL fails is considered secure by browsers, and having reviewed Letsencrypt cert installation documents I do not see any possibility for "misconfiguration": the cert is copied from live folder to Apache SSL.crt and SSL.key folders, then Apache loads them. What specifically could be misconfigured despite modern browsers considering the connection secure?

If the site is only sending the leaf cert rather than the full chain then browsers often adapt to the wrong config. But, tools like curl and openssl will not adapt and report an error.

- What program did you use to get the Let's Encrypt certs for the server?
- If certbot, what file did you copy to "SSL.crt"? Was it cert.pem or fullchain.pem?
- What is the URL of the failing site? Or at least the domain name.

The CA Root store is part of each OS distribution. When using curl, inside or within php, you can also override the system CA Root store. Let's sort out the server config first and we can advise about the root store after if still needed.

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [August 29, 2022, 2:54pm UTC](https://community.letsencrypt.org/t/why-does-curl-not-trust-letsencrypt/183585/5 "2022-08-29T14:54:40Z")

</div>

> [@super](#):
>
> CURL can successfully download from sites with other issuers' certs, for example from Youtube.

If any root certs in the YouTube's chain is more than 5 years old, it is likely in your CURL `cacert.pem` file.

Search the `cacert.pem` file for this serial# `172886928669790476064670243504169061120`  
[which is for "ISRG Root X1"]

---

<div class="post-metadata">

### Author: ![super](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@super](https://community.letsencrypt.org/u/super)
#### Post date: [August 29, 2022, 4:16pm UTC](https://community.letsencrypt.org/t/why-does-curl-not-trust-letsencrypt/183585/6 "2022-08-29T16:16:50Z")

</div>

> [@MikeMcQ](#):
>
> If certbot, what file did you copy to "SSL.crt"? Was it cert.pem or fullchain.pem?

This is it! It was cert. Copied fullchain and CURL now trusts it. Thanks a whole lot!

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [September 28, 2022, 4:17pm UTC](https://community.letsencrypt.org/t/why-does-curl-not-trust-letsencrypt/183585/7 "2022-09-28T16:17:24Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
