Hello everyone,
I encountered a blocking issue while using this Facebook Login plugin for Osclass, and I wanted to share the fix in case other users face the same problem.
Problem
During Facebook Login callback, I was getting this error:
Facebook SDK returned an error:
SSL certificate problem: unable to get local issuer certificate
Everything else seemed fine (HTTPS working, cURL enabled, Facebook app configured correctly).
After debugging, I found that the plugin hardcodes a single DigiCert root certificate in:
src/HttpClients/FacebookCurlHttpClient.php
CURLOPT_CAINFO => __DIR__ . '/certs/DigiCertHighAssuranceEVRootCA.pem',
On modern hosting environments (cPanel / CloudLinux / AlmaLinux / RHEL), this root certificate alone is not sufficient for Facebook’s current TLS certificate chain.
Solution (tested & working)
Replacing the hardcoded CA file with the system CA bundle fixed the issue completely.
Change this:
CURLOPT_CAINFO => __DIR__ . '/certs/DigiCertHighAssuranceEVRootCA.pem',
To this:
CURLOPT_CAINFO => '/etc/pki/tls/cert.pem',
(Alternatively, using a readable check / fallback works as well.)
After this change:
SSL verification stays enabled
Facebook Login works correctly
The error disappears
Why this matters
Many shared hosting users:
Don’t have access to php.ini or MultiPHP INI Editor
Can’t set curl.cainfo globally
May hit this issue without a clear explanation
Using the system CA bundle instead of a single hardcoded root avoids these problems.
I hope this helps other users and improves compatibility.
Best regards,