*

krallen

  • ***
  • 48 posts
Hello everyone,

I encountered a blocking issue while using this Facebook Login plugin for Osclass, and I wanted to share the fix in case other users face the same problem.

 Problem

During Facebook Login callback, I was getting this error:

Facebook SDK returned an error:
SSL certificate problem: unable to get local issuer certificate


Everything else seemed fine (HTTPS working, cURL enabled, Facebook app configured correctly).

After debugging, I found that the plugin hardcodes a single DigiCert root certificate in:

src/HttpClients/FacebookCurlHttpClient.php

CURLOPT_CAINFO => __DIR__ . '/certs/DigiCertHighAssuranceEVRootCA.pem',


On modern hosting environments (cPanel / CloudLinux / AlmaLinux / RHEL), this root certificate alone is not sufficient for Facebook’s current TLS certificate chain.

Solution (tested & working)

Replacing the hardcoded CA file with the system CA bundle fixed the issue completely.

Change this:

CURLOPT_CAINFO => __DIR__ . '/certs/DigiCertHighAssuranceEVRootCA.pem',


To this:

CURLOPT_CAINFO => '/etc/pki/tls/cert.pem',


(Alternatively, using a readable check / fallback works as well.)

After this change:

SSL verification stays enabled

Facebook Login works correctly

The error disappears

Why this matters

Many shared hosting users:

Don’t have access to php.ini or MultiPHP INI Editor

Can’t set curl.cainfo globally

May hit this issue without a clear explanation

Using the system CA bundle instead of a single hardcoded root avoids these problems.

I hope this helps other users and improves compatibility.

Best regards,

*

MB Themes

Try this:
Changing CURLOPT_CAINFO to the system CA bundle (/etc/pki/tls/cert.pem) works perfectly — SSL verification stays enabled and Facebook login works without errors.

Otherwise I would just check with hosting.
  To get fast support, we need following details: Detail description, URL to reproduce problem, Screenshots