Keep TLS certificate and hostname verification enabled. To fix an SSL verification error in a PHP HTTP client, first identify the client, transport, and PHP process making the request; then make sure that process trusts the certificate authority (CA) that issued the server’s certificate. PHP streams, Guzzle, and Symfony HttpClient use different configuration paths, so a fix for one is not automatically right for another.
What an SSL verification error means
For an HTTPS request, the client checks whether the server certificate chains to a trusted CA and whether the certificate is valid for the requested hostname. An error means one or both checks could not be completed successfully. The right fix is to correct the certificate, hostname, or trust configuration—not to turn off authentication of the server.
A request that works in a browser can still fail in PHP. Symfony HttpClient, for example, validates against the system certificate store, while browsers use their own stores. The PHP process may therefore have a different set of trusted certificates from the browser you tested. See the Symfony HttpClient documentation.
Diagnose the failing PHP process first
- Capture the exact error. Record the exception or warning, request hostname, and where it occurs. Avoid treating every TLS error as a missing-CA problem: a wrong hostname or an incomplete or untrusted chain can also prevent validation.
- Identify the HTTP client and transport. Determine whether the request uses PHP’s native streams, Guzzle, or Symfony HttpClient, and which handler or transport is active. Symfony supports PHP streams and cURL; transport differences matter when diagnosing a failure.
- Identify the runtime and environment. Check whether the failing request comes from CLI PHP, a web server, or a container, and inspect the PHP configuration and trust store available to that process. These environments can differ; verify the one that actually runs the request.
- Confirm the URL hostname. Check that the requested hostname is the one the server certificate is valid for. Do not disable hostname verification to work around a mismatch.
- Check the trust source and file access. Confirm that the selected CA file or directory exists, contains the intended trust material, and can be read by the PHP process. For a CA directory used by PHP streams, certificates must be correctly hashed.
Fix certificate trust in native PHP streams
PHP’s SSL context options verify_peer and verify_peer_name default to true. Keep both enabled. Set cafile to a CA bundle file when the process needs a specific file, or use capath for a correctly hashed certificate directory. The PHP manual describes these options and their behavior: SSL context options.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
<?php
$url = 'https://example.com/';
$context = stream_context_create([
'ssl' => [
'verify_peer' => true,
'verify_peer_name' => true,
'cafile' => '/path/to/ca-bundle.pem',
],
]);
$response = file_get_contents($url, false, $context);
if ($response === false) {
$error = error_get_last();
throw new RuntimeException($error['message'] ?? 'HTTPS request failed');
}
echo $response;
Replace the example URL and CA path with values appropriate to the deployment. The path is not universal. If using capath, point to a directory prepared in the format PHP expects; an ordinary directory of certificate files is not necessarily sufficient. PHP documents allow_self_signed as false by default and notes that it requires verify_peer; it is not a substitute for establishing a trusted CA.
Fix certificate trust in Guzzle
Guzzle’s verify request option defaults to true. Use true to retain the default verification behavior, or provide the path to a CA bundle when you need a specific bundle. The option and its security implications are documented in Guzzle request options.
<?php
require __DIR__ . '/vendor/autoload.php';
use GuzzleHttpClient;
$url = 'https://example.com/';
$client = new Client();
$response = $client->request('GET', $url, [
'verify' => '/path/to/ca-bundle.pem',
]);
echo $response->getBody();
The bundle path is an example, not a universal location. Which default bundle is available depends on the installed Guzzle version, handler, operating system, and PHP configuration. Guzzle’s FAQ answers “Why am I getting an SSL verification error?” by advising that you specify the CA bundle path used to verify the peer certificate: Guzzle FAQ.
Rank #2
Do not set 'verify' => false as a production fix. Guzzle explicitly describes that setting as insecure because it disables certificate verification.
Recommended Free Tools
Fix certificate trust in Symfony HttpClient
Symfony HttpClient uses the system certificate store to validate certificates. If the certificate authority is not trusted in that store, configure the relevant system trust source for the environment running PHP. Because Symfony can use PHP streams or cURL, identify the active transport when investigating differences between environments. See Symfony HttpClient documentation for its current guidance.
For a self-signed development service, Symfony recommends creating a CA and adding that CA to the system store. Trust the intended CA rather than treating an arbitrary self-signed leaf certificate as trustworthy. Symfony states that disabling verify_host and verify_peer is not recommended in production.
Handling private and self-signed development certificates
For an internal service or local development endpoint, establish a development CA and configure the relevant trust store or client to trust that CA. This keeps peer-chain and hostname checks meaningful. Make sure the certificate presented by the endpoint chains to the CA you intend to trust and is valid for the hostname used in the request.
- Use the trust store that the actual PHP process and selected transport consult.
- For native streams, configure a suitable
cafileor correctly hashedcapath. - For Guzzle, pass the CA bundle path through
verifywhen a custom bundle is needed. - For Symfony HttpClient, add the development CA to the relevant system certificate store as Symfony recommends.
Common causes and fixes
| Symptom or situation | Likely check | Safe next step |
|---|---|---|
| Browser succeeds, PHP fails | The browser and PHP may use different trust stores. | Check the trust source used by the actual PHP process and client transport. |
| Guzzle reports an SSL verification error | The selected process may not have a usable default CA bundle, or the chain may not validate. | Check the Guzzle FAQ and configure a valid CA bundle path with verify if appropriate. |
| Only CLI or only web requests fail | The runtimes may have different PHP configuration, filesystem access, or trust stores. | Inspect the failing runtime rather than changing a different PHP installation. |
| A custom CA path changes nothing | The path may be wrong, unreadable, unsuitable for the selected option, or not the transport’s active trust source. | Confirm the path, permissions, bundle contents, client, and transport. |
| Certificate is for a different hostname | The URL hostname does not match the certificate identity. | Use the correct hostname or repair the server certificate; keep hostname verification on. |
| Private service uses a self-signed certificate | The issuer is not trusted in the process’s certificate store. | Create and trust a development CA in the relevant store or provide it as the client’s CA bundle. |
Why disabling verification is not a fix
Settings such as verify => false, verify_peer => false, or verify_host => false stop the client from properly authenticating the remote endpoint. A successful request after such a change does not resolve the certificate problem; it suppresses the check that exposed it. Do not use these settings in production. Restore verification and repair the certificate chain, hostname, or trusted CA configuration instead.
Performance, reliability, and cost considerations
Certificate verification is a security requirement, not an optional performance feature. Avoid weakening it to make a request succeed. For reliability, configure the correct trust source for each deployed runtime and make sure the PHP process can read it. If you use a private CA, plan how that CA is installed and maintained in the system or supplied to the client; the appropriate method depends on the client, handler, and deployment environment.
Rank #4
When troubleshooting, separate three questions: is the certificate valid for the requested hostname, does its chain lead to a CA the client trusts, and is the process consulting the trust source you expect? That narrows the investigation without trading away endpoint authentication.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
For a different task—capturing a webpage as an image or PDF rather than making a PHP HTTP request—ScreenshotNeo is a website screenshot API and MCP server for developers. A one-call request can return a screenshot or PDF; the response also identifies page verdict and billing status in headers. See the ScreenshotNeo documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo accepts cookie or consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 shots. These are ScreenshotNeo product details, not a replacement for configuring TLS verification in your PHP HTTP client.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Sign up for ScreenshotNeo’s free plan.
Frequently Asked Questions
Does a browser working prove that PHP trusts the HTTPS certificate?
No. Browsers may use their own certificate stores, while PHP clients can use the system store or another trust source.
Can I turn off certificate verification just to test a production request?
Do not use disabled verification in production. It prevents the client from properly authenticating the endpoint; repair the trust configuration or certificate instead.
Where should I get a CA bundle path?
There is no universal path. Use a bundle available to the deployed runtime and verify that the PHP process can read it; check the installed client and transport’s documentation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems

