Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

cURL error 60 means certificate verification failed. It does not, by itself, mean that your proxy is unreachable. cURL could not build a trusted certificate chain (or validate the hostname) for the server it was connecting to. When a proxy is involved, identify whether the failed TLS connection is between cURL and the destination site or between cURL and an HTTPS proxy; each connection has its own trust settings.

What error 60 is actually telling you

cURL verifies TLS certificates by default. Error 60 (often displayed as “SSL certificate problem: unable to get local issuer certificate”) means the certificate presented on the failing connection was not verifiable with the CA certificates available to that cURL build. Typical causes include:

  • An old, missing or incorrectly selected CA bundle.
  • A server that sends an incomplete certificate chain.
  • A certificate signed by a private corporate CA that is not in your trust store.
  • An expired, wrong or hostname-mismatched certificate.
  • An HTTPS proxy performing TLS inspection and presenting a certificate signed by the company’s internal CA.

There can be two independent TLS relationships:

Connection When it exists Trust that must be configured
cURL → proxy When the proxy URL itself uses https:// The proxy’s CA, using proxy-specific options
cURL → origin For the destination HTTPS site, including an HTTP proxy carrying a CONNECT tunnel The destination server’s CA, using normal CA options

Fixing the wrong side leaves error 60 unchanged.

1. Inspect the transfer before changing trust

Run the same request with verbose output:

curl -v -x http://proxy.example:8080 https://example.com/

For an HTTPS proxy, use its scheme explicitly:

curl -v -x https://proxy.example:8443 https://example.com/

Read the output for the selected proxy, the CA file or directory cURL reports, and the certificate at which verification stops. Do not paste credentials, authorization headers, cookies, private URLs or other sensitive request data when sharing a verbose log. If you set both a command-line proxy and environment variables, the command line normally makes your intent clearer; still inspect the output rather than assuming the expected route was used.

2. Check which proxy cURL selected

Proxy settings frequently come from environment variables. Protocol-specific variables such as https_proxy and the general ALL_PROXY can affect a request; when both apply, the protocol-specific variable takes precedence. Display the relevant values without exposing embedded passwords:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
GL.iNet GL-MT300N-V2 (Mango) Portable Mini Travel Wireless Pocket VPN WiFi Router - 2X Ethernet Ports | USB 2.0 | OpenWrt | OpenVPN/Wireguard for Public & Hotel Wi-Fi | Easy to Set up via Admin Panel
  • 【WIRELESS MOBILE MINI TRAVEL ROUTER】 Convert a public network (wired or wireless) to a private Wi-Fi for secure surfing. Tethering. Powered by any laptop USB, power banks or 5V/2A DC adapters (sold separately). 39g (1.41 Oz) only, portable and pocket friendly. 2.4GHz ONLY
  • 【OPEN SOURCE & PROGRAMMABLE】 OpenWrt pre-installed, USB disk extendable.
  • 【LARGER STORAGE & EXTENDABILITY】 128MB RAM, 16MB Flash ROM, dual Ethernet ports, UART and GPIOs available for hardware DIY.
  • 【OPENVPN CLIENT】 OpenVPN client pre-installed, compatible with 30+ VPN service providers.
  • 【PACKAGE CONTENTS】 GL-MT300N-V2 (Mango) mini router (2-year Warranty), USB cable, Ethernet cable, User Manual. Please update to the latest firmware.
env | grep -iE '^(http|https|all|no)_proxy='

On systems where that command is unavailable, inspect the variables through your shell’s normal environment-listing command. A quick controlled test can bypass environment selection for one request:

env -u http_proxy -u https_proxy -u ALL_PROXY curl -v https://example.com/

If the direct request succeeds but the proxied request fails, concentrate on the proxy path and its certificate. If both fail, investigate the origin certificate or local CA configuration as well.

3. Fix a certificate problem on the destination connection

Use an approved CA bundle for one transfer

Obtain the CA certificate or bundle from the site administrator or the organization that operates the TLS-inspecting proxy. Then pass it explicitly:

curl --cacert /path/to/approved-ca-bundle.pem 
  -x http://proxy.example:8080 
  https://example.com/

The file must contain a CA certificate that legitimately verifies the server’s chain; adding the server’s leaf certificate or an unverified file copied from an error message is not a sound trust decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure the CA source used by cURL

Depending on the build, cURL supports CA configuration through CURL_CA_BUNDLE, SSL_CERT_FILE and SSL_CERT_DIR. For a temporary test:

Rank #2
Sale
UGREEN NAS DXP2800 2-Bay for Advanced Home Users, Remote Workers & Creators
  • 【Advanced Home Data & Media Hub】For advanced home users who need phone backup, file storage, and centralized data management. Centralize family photos, 4K videos, movies, computer backups, and personal files in one place while running multiple apps for home entertainment and everyday data management. Suitable for households with growing digital libraries and multiple NAS use cases.
  • 【Built for Creators, Media Servers & Advanced Apps】Powered by the Intel N100 Quad-Core CPU, 8GB DDR5 RAM, 2.5GbE networking, and dual M.2 NVMe slots, DXP2800 handles large files and heavier workloads with ease. Run Docker, virtual machines, and media server applications compatible with Plex—ideal for content creators, tech enthusiasts, and advanced home users managing 4K videos, RAW photos, personal media libraries, and multiple NAS apps.
  • 【Up to 80TB for Growing Digital Libraries】 Supports up to 80TB of storage using two HDD bays and two M.2 NVMe SSD slots for family photos, movies, RAW photos, 4K videos, work files, and device backups. AI photo management supports recognition of people, objects, scenes, and locations, album organization, and duplicate photo detection. HDDs and SSDs are not included.
  • 【AI-powered Home Surveillance】Turn DXP2800 into a centralized home surveillance hub by connecting compatible network cameras and storing recordings locally on your NAS. AI-powered features include Face Recognition, People Detection, and Pet Detection, helping advanced home users review important events more efficiently while managing home surveillance and personal data in one place.
  • 【One data Center Across Your Devices】Keep files from desktops, laptops, phones, tablets, and other devices together instead of scattered across cloud accounts and external drives. Access, back up, organize, and share data across Windows, macOS, Android, iOS, web browsers, and compatible smart TVs—ideal for creators and advanced home users working across multiple devices.
CURL_CA_BUNDLE=/path/to/approved-ca-bundle.pem 
curl -x http://proxy.example:8080 https://example.com/

Environment support and precedence vary with the TLS backend and package build. Confirm the active CA source in verbose output and in the documentation for the cURL executable you actually run.

Check the server chain and identity

If a public site fails for everyone using your cURL build, the server may be omitting an intermediate certificate. An expired certificate, a certificate issued for another hostname, or a system clock that is wrong can also cause verification to fail. Supplying a random CA does not repair any of those conditions; the site administrator must correct a broken server chain or certificate.

4. Fix certificate verification for an HTTPS proxy

An HTTPS proxy has its own TLS handshake before cURL reaches the destination. Supply the CA that verifies the proxy certificate with a proxy-specific option:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl --proxy-cacert /path/to/proxy-ca.pem 
  -x https://proxy.example:8443 
  https://example.com/

Some cURL versions and TLS backends support the native certificate store for proxy verification through --proxy-ca-native. Check curl --help and the installed version’s manual before relying on that switch. The proxy CA setting does not replace --cacert for the origin connection when both sides need separate private trust roots.

For a corporate inspection proxy, request the approved root or intermediate CA from the organization’s IT or security team and verify its authenticity through that organization’s established process. Never trust a certificate merely because it appeared in an untrusted network exchange.

Rank #3
Sale
Synology DS223 Home & Office Backup Hub - Centralize Files, Protect Data & Monitor Property (2-Bay Diskless NAS)
  • One Place for All Your Data - Consolidate scattered files from multiple computers, phones and external drives into one accessible hub with 100% ownership
  • Professional File Collaboration - Share projects with clients, sync documents across teams and maintain version control without Dropbox fees
  • Automated Backup Protection - Set-and-forget backups for Macs, PCs and mobile devices to multiple destinations including cloud and external drives
  • DIY Surveillance System - Transform IP cameras into a professional monitoring solution with motion alerts, recording schedules and remote viewing
  • 2-Year Warranty - Reliable hardware backed by Synology's expert customer support team and ongoing software updates

5. Account for your operating system, TLS backend and application

There is no universal installation command for a CA bundle. cURL built with Schannel on Windows uses the Windows certificate store. Other builds commonly use a file-based bundle, while some TLS backends can use a platform store when enabled. Apple systems likewise behave differently depending on whether the binary uses Apple SecTrust. The available options, including --ca-native and --proxy-ca-native, depend on the installed cURL version and TLS backend.

Check the build before choosing a permanent fix:

curl --version

Look for the TLS backend in the output, then consult the documentation for that build and your operating system’s certificate-store procedure. Installing a CA in the operating system may not change a separately packaged cURL binary that carries its own bundle.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The same distinction matters in PHP, Python applications, deployment agents and other software using libcurl. A command-line fix does not automatically change the runtime’s CA file, native-store mode or bundled libcurl. Verify the application’s libcurl/TLS configuration separately and use that runtime’s official configuration guidance.

6. Retest without weakening TLS

Repeat the original command with the intended proxy and CA settings, keeping verification enabled:

curl -v --cacert /path/to/approved-ca-bundle.pem 
  -x http://proxy.example:8080 
  https://example.com/

The verbose trace should show the expected proxy and CA source, followed by a successful certificate verification and HTTP response. If an HTTPS proxy is involved, include its proxy CA option as well. Test the exact hostname your application uses; a certificate valid for one name is not automatically valid for another.

Rank #4
Master Vpn - Free Unlimited VPN Proxy Server
  • Unlimited bandwidth, unlimited data.
  • Super-fast VPN and one tap connect.
  • Free worldwide multiple servers.
  • Works with all type of data carries. (Wi-Fi, 4G, LTE, 3G).
  • No registration, sign up needed.

Why --insecure is not the fix

-k and --insecure disable certificate and hostname verification. That can make a test request appear to work, but it permits a man-in-the-middle to impersonate the destination or proxy. Encryption without authenticating the peer does not establish who is receiving the data. cURL’s documentation strongly recommends avoiding this option and says never to skip verification in production. If you use it briefly to isolate a problem in a controlled development environment, remove it immediately and replace it with the correct CA configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common symptoms and targeted fixes

Symptom Likely cause Action
Direct HTTPS works; HTTPS-proxy request fails Proxy certificate is signed by an untrusted private CA Use the approved proxy CA with --proxy-cacert or supported native-store mode.
HTTP proxy plus HTTPS destination fails Origin CA, incomplete chain or hostname problem Use --cacert, inspect the origin chain and verify the hostname.
Works in a browser but not cURL Browser and cURL use different stores or backends Identify cURL’s backend and CA path; import the approved CA into the store cURL actually uses.
Changing the system store has no effect cURL uses a bundled file or a different runtime Check curl --version and verbose output, then configure that bundle or application runtime.
Unexpected proxy appears in verbose output Environment variable selection Inspect https_proxy, ALL_PROXY and related variables; set or unset them deliberately.
Error persists after adding a CA Wrong CA, missing intermediate, expired certificate or hostname mismatch Re-check the certificate chain and obtain the correct CA from the responsible administrator.

Performance, reliability and maintenance

  • Use a per-command --cacert first when validating a change; move to a managed store only after the CA provenance and scope are clear.
  • Keep private corporate roots limited to the systems and applications that require them. A broad trust-store change affects every HTTPS request made by that trust domain.
  • After CA rotation, test both the proxy and origin paths. During a transition, an organization may need old and new intermediates temporarily, according to its security policy.
  • Record the cURL version, TLS backend, proxy URL scheme and CA source in deployment documentation so another operator can reproduce the fix.
  • Do not infer reachability from error 60 alone: cURL may have reached the peer and rejected its identity during TLS verification.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your broader task is obtaining a dependable website image rather than debugging a local browser or proxy stack, ScreenshotNeo provides a single HTTP request. Its API accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the result with X-Page-Verdict and X-Billed headers. An MCP server lets Claude, Cursor and other MCP clients call take_screenshot, get_page_info and capture_pdf.

cURL example (see the ScreenshotNeo API documentation):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo includes full-page and selector capture, device presets and custom viewports, dark mode, retina scale, PDF controls, HTML/CSS rendering, custom JavaScript and CSS, clicks, waits, request blocking, headers, cookies, user agents, authorization, timezone and geolocation, transparent backgrounds, resizing, TTL caching, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, a usage API and an OpenAPI specification. Existing parameter names used by other screenshot APIs also work, which can simplify migration.

The Free plan includes 1,000 screenshots each month with no card; paid plans start at $5 for 3,000 screenshots. Create a free ScreenshotNeo account to start.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FAQ

Does error 60 prove the proxy is down?

No. It identifies a certificate-verification failure. The network connection may have reached the proxy or destination successfully before identity validation failed.

Best Value
Synology DS124 Personal Backup & File Hub - Protect Photos, Secure Home Surveillance (1-Bay Diskless NAS)
  • Complete Phone & Computer Backup - Automatically protect photos, documents and videos from iPhone android, Mac and Windows to one secure location
  • Your Private File Cloud - Access files from anywhere and share large projects with family or clients without relying on expensive cloud subscriptions
  • Smart Home Security Hub - Monitor your home 24/7 with AI-powered surveillance that detects people, vehicles and sends instant alerts
  • 100% Data Ownership - Keep full control of your personal data with multi-platform access and no monthly subscription fees
  • 2-Year Warranty - Reliable hardware backed by Synology's expert customer support team and ongoing software updates

Can I use one CA file for both TLS hops?

Only if that file legitimately contains trust anchors for both certificates. Configure origin and proxy trust independently so an accidental change on one connection does not mask a problem on the other.

Why does a browser succeed while cURL fails?

They may use different certificate stores, proxy settings or TLS libraries. Compare the actual cURL backend and CA source rather than assuming the browser’s trust decisions apply.

What should I give my network administrator?

Provide the cURL version, TLS backend, proxy URL scheme, sanitized verbose output and the exact hostname. Do not send passwords, tokens or private request data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Does error 60 prove the proxy is down?

No. It identifies a certificate-verification failure. The network connection may have reached the proxy or destination successfully before identity validation failed.

Can I use one CA file for both TLS hops?

Only if that file legitimately contains trust anchors for both certificates. Configure origin and proxy trust independently so an accidental change on one connection does not mask a problem on the other.

Why does a browser succeed while cURL fails?

They may use different certificate stores, proxy settings or TLS libraries. Compare the actual cURL backend and CA source rather than assuming the browser’s trust decisions apply.

What should I give my network administrator?

Provide the cURL version, TLS backend, proxy URL scheme, sanitized verbose output and the exact hostname. Do not send passwords, tokens or private request data.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

Resolve error 60 by identifying the failing TLS hop and supplying the verified CA through the trust store or option used by that cURL build. Keep peer and hostname verification enabled; --insecure only hides the underlying problem.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.