<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic curl: (60) SSL certificate problem: unable to get local issuer certificate in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/67763#M13845</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;I have a problem with HTTPS Inspection to access a site.&lt;BR /&gt;When I do a curl_cli I get the error "curl: (60) SSL certificate problem: unable to get local issuer certificate".&lt;BR /&gt;In the dashboard the certificate exists, but when I look inside the bundle certificate via ssh I can't see the root certificate.&lt;BR /&gt;I tried to insert the certificate by hand, and when I curl with the&amp;nbsp;--cacert $CPDIR/conf/ca-bundle.crt parameter no error is displayed, but when I curl without specifying the path, which should take the default path, I get the same error.&lt;BR /&gt;Does anyone have any ideas how to resolve this error?&lt;/P&gt;</description>
    <pubDate>Mon, 18 Nov 2019 20:15:42 GMT</pubDate>
    <dc:creator>Rodrigo_Silva</dc:creator>
    <dc:date>2019-11-18T20:15:42Z</dc:date>
    <item>
      <title>curl: (60) SSL certificate problem: unable to get local issuer certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/67763#M13845</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I have a problem with HTTPS Inspection to access a site.&lt;BR /&gt;When I do a curl_cli I get the error "curl: (60) SSL certificate problem: unable to get local issuer certificate".&lt;BR /&gt;In the dashboard the certificate exists, but when I look inside the bundle certificate via ssh I can't see the root certificate.&lt;BR /&gt;I tried to insert the certificate by hand, and when I curl with the&amp;nbsp;--cacert $CPDIR/conf/ca-bundle.crt parameter no error is displayed, but when I curl without specifying the path, which should take the default path, I get the same error.&lt;BR /&gt;Does anyone have any ideas how to resolve this error?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 20:15:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/67763#M13845</guid>
      <dc:creator>Rodrigo_Silva</dc:creator>
      <dc:date>2019-11-18T20:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: curl: (60) SSL certificate problem: unable to get local issuer certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/67983#M13898</link>
      <description>If you're going through a gateway doing HTTPS Inspection, the only certificate you really need to trust is the gateway CA.&lt;BR /&gt;So why not create a file with just the HTTPS Inspection CA key and refer to that with the --cacert flag?</description>
      <pubDate>Thu, 21 Nov 2019 10:08:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/67983#M13898</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-21T10:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: curl: (60) SSL certificate problem: unable to get local issuer certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/68009#M13905</link>
      <description>&lt;P&gt;I'm catching this error doing a curl_cli straight from the gateway to the site.&lt;BR /&gt;The user cannot open the site, and I only see Inpect in the logs with user source.&lt;BR /&gt;The certificate I am experiencing is Amazon Root CA 1. (&lt;A href="https://docs.aws.amazon.com/iot/latest/developerguide/server-authentication.html#server-authentication-certs" target="_blank"&gt;https://docs.aws.amazon.com/iot/latest/developerguide/server-authentication.html#server-authentication-certs&lt;/A&gt;).&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 13:26:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/68009#M13905</guid>
      <dc:creator>Rodrigo_Silva</dc:creator>
      <dc:date>2019-11-21T13:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: curl: (60) SSL certificate problem: unable to get local issuer certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/68178#M13940</link>
      <description>Is the CA keys specified in the URL you mentioned in the CA Certificate Store for HTTPS Inspection?&lt;BR /&gt;</description>
      <pubDate>Sat, 23 Nov 2019 03:45:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/68178#M13940</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-23T03:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: curl: (60) SSL certificate problem: unable to get local issuer certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/68709#M14013</link>
      <description>&lt;P&gt;Sorry. I found that curl_cli returns certificate error when it is declared with https:// in the URL.&lt;/P&gt;&lt;P&gt;Thanks for your time.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 18:09:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/curl-60-SSL-certificate-problem-unable-to-get-local-issuer/m-p/68709#M14013</guid>
      <dc:creator>Rodrigo_Silva</dc:creator>
      <dc:date>2019-11-27T18:09:19Z</dc:date>
    </item>
  </channel>
</rss>

