{"id":13159905,"date":"2020-07-23T10:48:08","date_gmt":"2020-07-23T10:48:08","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/curl-error-60-due-to-expired-addtrust-certificate-with-openssl-1-0\/"},"modified":"2020-07-23T14:52:27","modified_gmt":"2020-07-23T14:52:27","slug":"curl-error-60-due-to-expired-addtrust-certificate-with-openssl-1-0","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/curl-error-60-due-to-expired-addtrust-certificate-with-openssl-1-0\/","title":{"rendered":"cURL error 60 due to expired AddTrust certificate with openSSL 1.0"},"content":{"rendered":"<p>My plugin uses WP_Http to make requests to another server. If this server has an SSL certificate from COMODO (now Sectigo), the WP request returns an error:<\/p>\n<p>cURL error 60: SSL certificate problem: certificate has expired<\/p>\n<p>This only happens on hosting environments with older openSSL (&lt; 1.1.1), which I already saw on two lower-end shared hosts.<\/p>\n<p>I found information from Sectigo explaining the <a href=\"https:\/\/support.sectigo.com\/articles\/Knowledge\/Sectigo-AddTrust-External-CA-Root-Expiring-May-30-2020\">AddTrust certificate is expired as of May 30<\/a>. According to this information, it is not needed to reissue or reinstall the certificate on the server.<\/p>\n<p>However, in <a href=\"https:\/\/wordpress.slack.com\/archives\/C02RQC6RW\/p1590942720418300\">slack<\/a> I came across a discussion pointing to <a href=\"https:\/\/www.agwa.name\/blog\/post\/fixing_the_addtrust_root_expiration\">https:\/\/www.agwa.name\/blog\/post\/fixing_the_addtrust_root_expiration<\/a>, that explains, if I understand it correctly, that the server certificate should be fixed if it contains the expired AddTrust in the chain.<\/p>\n<p>Also in this slack discussion it is pointed out that it would not help if WordPress would fix its ca-bundle.crt. I don&#8217;t understand why. If I temporarily remove the &#8220;AddTrust External Root&#8221; entry there, the error is gone.<\/p>\n<p>I would like to understand better which side could\/should do something to fix this. Possible candidates, I think:<\/p>\n<ul>\n<li>The server administrator could reinstall the certificate so the expired AddTrust is no longer part of the chain.<\/li>\n<li>WordPress could update its wp-includes\/certificates\/ca-bundle.crt, removing the AddTrust External Root entry<\/li>\n<li>The hosting company could update their openSSL version to &gt; 1.1.1.<\/li>\n<\/ul>\n<p>Any lights shining on this issue are most welcome&#8230; Thanks!<\/p>\n","protected":false},"template":"","class_list":["post-13159905","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/13159905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":2,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/13159905\/revisions"}],"predecessor-version":[{"id":13161173,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/13159905\/revisions\/13161173"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=13159905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}