Then I determined to install another CA indicated in the error log(G4 above may not be needed): [[email protected] ~]# wget --no-check-certificate 'https://www.symantec.com/content/en/us/enterprise/verisign/roots/VeriSign-Class%203-Public-Primary-Certification-Authority-G5.pem' [[email protected] ~]# openssl x509 -text -in "VeriSign-Class 3-Public-Primary-Certification-Authority-G5.pem" >>

WARNING: cannot verify example.com's certificate, issued by "/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA": Unable to locally verify the issuer's authority.

If this HTTPS server uses a certificate signed by a CA represented in the bundle, the certificate verification probably failed due to a problem with the certificate (it might be expired, or the certificate chain is incomplete). If you'd like to turn off curl's verification of the certificate, use the -k (or --insecure) option.

It sounds like something is wrong with my local certificate store, but I have no idea how to proceed from here. MXToolbox Lists Ten of the Best Email Related Tools Online [+] October (6) How to Utilize More than 4GB of RAM in 32-bit Fedora 14 How Does a Windows Administrator React Wget Unable To Get Local Issuer Certificate You can use the nightly if you'd like: https://github.com/wp-cli/wp-cli/wiki/Alternative-Install-Methods#installing-nightly-via-phar Sign up for free to join this conversation on GitHub. Unable To Locally Verify The Issuer's Authority Ubuntu Instead, I chose to use the --ca-certificate=file option of wget.

I tried both versions of wget 1.11.4 (http://gnuwin32.sourceforge.net/packages/wget.htm) and 1.16.1 (https://eternallybored.org/misc/wget/) and both gave this error.

Please check the openssl configuration file and confirm that the paths are correct.

They also aren't presenting the full certificate chain, just their issuer's certificate; not 100% up to par, but certainly nothing that should stop you from validating the chain. connected. If not, you'll need to acquire them and either append them to your main certificate file, or create a separate file and point to it with your wget command using the check my blog It looks that wget doesn't know how to verify SSL certificates any more.

tcpdump is better and will provide the full story, but next best thing is the headers w/o full packet payload. Home About Me Contact Me The Nubby Admin Home About Me Contact Me Solving wget "ERROR: cannot verify site certificate. wp-cli member danielbachhuber commented Mar 5, 2015 #1636 defaults to curl, but hasn't been released yet. This is a sample output: wget https://www.google.com --2011-09-23 00:11:13-- https://www.google.com/ Resolving www.google.com...,,, ...