# Php api and self signed certs

**URL:** <https://discuss.elastic.co/t/php-api-and-self-signed-certs/22052>\
**Category:** Elasticsearch\
**Created:** [February 9, 2015, 11:05pm UTC](https://discuss.elastic.co/t/php-api-and-self-signed-certs/22052 "2015-02-09T23:05:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_Halliday](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_halliday/32/916_2.png) [@Paul\_Halliday](https://discuss.elastic.co/u/Paul_Halliday)\
**Post date:** [February 9, 2015, 11:05pm UTC](https://discuss.elastic.co/t/php-api-and-self-signed-certs/22052/1 "2015-02-09T23:05:34Z")

</div>

Hi,

I am trying to get the configuration example from here to work:

[http://www.elasticsearch.org/guide/en/elasticsearch/client/php-api/current/\_security.html#\_guzzleconnection\_self\_signed\_certificate](http://www.elasticsearch.org/guide/en/elasticsearch/client/php-api/current/_security.html#_guzzleconnection_self_signed_certificate)

My settings look like this:

19 // Elasticsearch  
20 $clientparams = array();  
21 $clientparams['hosts'] = array(  
22 '[https://host01:443](https://host01:443)'  
23 );  
24  
25 $clientparams['guzzleOptions'] = array(  
26 '\Guzzle\Http\Client::SSL\_CERT\_AUTHORITY' =\> 'system',  
27 '\Guzzle\Http\Client::CURL\_OPTIONS' =\> [  
28 'CURLOPT\_SSL\_VERIFYPEER' =\> true,  
29 'CURLOPT\_SSL\_VERIFYHOST' =\> 2,  
30 'CURLOPT\_CAINFO' =\> '.inc/cacert.pem',  
31 'CURLOPT\_SSLCERTTYPE' =\> 'PEM',  
32 ]  
33 );

The error:

PHP Fatal error: Uncaught exception  
'Elasticsearch\Common\Exceptions\TransportException' with message 'SSL  
certificate problem: self signed certificate'

What did I miss?

Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/85316e18-cc6b-49b1-8f72-6d0476cfd166%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/85316e18-cc6b-49b1-8f72-6d0476cfd166%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Paul\_Halliday](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_halliday/32/916_2.png) [@Paul\_Halliday](https://discuss.elastic.co/u/Paul_Halliday)\
**Post date:** [February 10, 2015, 3:42pm UTC](https://discuss.elastic.co/t/php-api-and-self-signed-certs/22052/2 "2015-02-10T15:42:05Z")

</div>

Well, I got it working but had to make the declarations in CurlHandle.php

I added:

$curlOptions[CURLOPT\_SSL\_VERIFYPEER] = true;  
$curlOptions[CURLOPT\_CAINFO] = '/full/path/to/cacert.pem';

directly above:

curl\_setopt\_array($handle, $curlOptions);  
return new static($handle, $curlOptions);  
...

What's strange is that I also tried placing them in the default  
$curlOptions but those seemed to get dumped somewhere prior to  
curl\_setopt\_array()

Yucky, but working.

On Monday, February 9, 2015 at 7:05:34 PM UTC-4, Paul Halliday wrote:

> Hi,
> 
> I am trying to get the configuration example from here to work:
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/client/php-api/current/_security.html#_guzzleconnection_self_signed_certificate)
> 
> My settings look like this:
> 
> 19 // Elasticsearch  
> 20 $clientparams = array();  
> 21 $clientparams['hosts'] = array(  
> 22 '[https://host01:443](https://host01:443)'  
> 23 );  
> 24  
> 25 $clientparams['guzzleOptions'] = array(  
> 26 '\Guzzle\Http\Client::SSL\_CERT\_AUTHORITY' =\> 'system',  
> 27 '\Guzzle\Http\Client::CURL\_OPTIONS' =\> [  
> 28 'CURLOPT\_SSL\_VERIFYPEER' =\> true,  
> 29 'CURLOPT\_SSL\_VERIFYHOST' =\> 2,  
> 30 'CURLOPT\_CAINFO' =\> '.inc/cacert.pem',  
> 31 'CURLOPT\_SSLCERTTYPE' =\> 'PEM',  
> 32 ]  
> 33 );
> 
> The error:
> 
> PHP Fatal error: Uncaught exception  
> 'Elasticsearch\Common\Exceptions\TransportException' with message 'SSL  
> certificate problem: self signed certificate'
> 
> What did I miss?
> 
> Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4dfff5aa-8040-44d5-af8e-5c2380c4ac55%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4dfff5aa-8040-44d5-af8e-5c2380c4ac55%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ian\_MacLennan](https://avatars.discourse-cdn.com/v4/letter/i/7993a0/32.png) [@Ian\_MacLennan](https://discuss.elastic.co/u/Ian_MacLennan)\
**Post date:** [February 11, 2015, 3:17am UTC](https://discuss.elastic.co/t/php-api-and-self-signed-certs/22052/3 "2015-02-11T03:17:20Z")

</div>

I suspect that it is because you put your constant names in quotes, and as  
a result the keys are going to be wrong. i.e. you  
have 'CURLOPT\_SSL\_VERIFYPEER' =\> true, while it should probably be  
CURLOPT\_SSL\_VERIFYPEER =\> true as shown in the link you provided.

Ian

On Tuesday, February 10, 2015 at 10:42:05 AM UTC-5, Paul Halliday wrote:

> Well, I got it working but had to make the declarations in CurlHandle.php
> 
> I added:
> 
> $curlOptions[CURLOPT\_SSL\_VERIFYPEER] = true;  
> $curlOptions[CURLOPT\_CAINFO] = '/full/path/to/cacert.pem';
> 
> directly above:
> 
> curl\_setopt\_array($handle, $curlOptions);  
> return new static($handle, $curlOptions);  
> ...
> 
> What's strange is that I also tried placing them in the default  
> $curlOptions but those seemed to get dumped somewhere prior to  
> curl\_setopt\_array()
> 
> Yucky, but working.
> 
> On Monday, February 9, 2015 at 7:05:34 PM UTC-4, Paul Halliday wrote:
> 
> > Hi,
> > 
> > I am trying to get the configuration example from here to work:
> > 
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/client/php-api/current/_security.html#_guzzleconnection_self_signed_certificate)
> > 
> > My settings look like this:
> > 
> > 19 // Elasticsearch  
> > 20 $clientparams = array();  
> > 21 $clientparams['hosts'] = array(  
> > 22 '[https://host01:443](https://host01:443)'  
> > 23 );  
> > 24  
> > 25 $clientparams['guzzleOptions'] = array(  
> > 26 '\Guzzle\Http\Client::SSL\_CERT\_AUTHORITY' =\> 'system',  
> > 27 '\Guzzle\Http\Client::CURL\_OPTIONS' =\> [  
> > 28 'CURLOPT\_SSL\_VERIFYPEER' =\> true,  
> > 29 'CURLOPT\_SSL\_VERIFYHOST' =\> 2,  
> > 30 'CURLOPT\_CAINFO' =\> '.inc/cacert.pem',  
> > 31 'CURLOPT\_SSLCERTTYPE' =\> 'PEM',  
> > 32 ]  
> > 33 );
> > 
> > The error:
> > 
> > PHP Fatal error: Uncaught exception  
> > 'Elasticsearch\Common\Exceptions\TransportException' with message 'SSL  
> > certificate problem: self signed certificate'
> > 
> > What did I miss?
> > 
> > Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/8df0c2ba-daa8-4a77-b1e8-60f00ed28ed7%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/8df0c2ba-daa8-4a77-b1e8-60f00ed28ed7%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Paul\_Halliday](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_halliday/32/916_2.png) [@Paul\_Halliday](https://discuss.elastic.co/u/Paul_Halliday)\
**Post date:** [February 11, 2015, 12:09pm UTC](https://discuss.elastic.co/t/php-api-and-self-signed-certs/22052/4 "2015-02-11T12:09:57Z")

</div>

That is the hint I needed.

I had it w/o quotes at first and the page was failing. I just assumed this  
was because of the lack of quotes, which once added allowed the page to  
load. I should have looked at the error console, which was showing the  
missing include 🙂

All is good and working as expected.

On Tuesday, February 10, 2015 at 11:17:20 PM UTC-4, Ian MacLennan wrote:

> I suspect that it is because you put your constant names in quotes, and as  
> a result the keys are going to be wrong. i.e. you  
> have 'CURLOPT\_SSL\_VERIFYPEER' =\> true, while it should probably be  
> CURLOPT\_SSL\_VERIFYPEER =\> true as shown in the link you provided.
> 
> Ian
> 
> On Tuesday, February 10, 2015 at 10:42:05 AM UTC-5, Paul Halliday wrote:
> 
> > Well, I got it working but had to make the declarations in CurlHandle.php
> > 
> > I added:
> > 
> > $curlOptions[CURLOPT\_SSL\_VERIFYPEER] = true;  
> > $curlOptions[CURLOPT\_CAINFO] = '/full/path/to/cacert.pem';
> > 
> > directly above:
> > 
> > curl\_setopt\_array($handle, $curlOptions);  
> > return new static($handle, $curlOptions);  
> > ...
> > 
> > What's strange is that I also tried placing them in the default  
> > $curlOptions but those seemed to get dumped somewhere prior to  
> > curl\_setopt\_array()
> > 
> > Yucky, but working.
> > 
> > On Monday, February 9, 2015 at 7:05:34 PM UTC-4, Paul Halliday wrote:
> > 
> > > Hi,
> > > 
> > > I am trying to get the configuration example from here to work:
> > > 
> > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/client/php-api/current/_security.html#_guzzleconnection_self_signed_certificate)
> > > 
> > > My settings look like this:
> > > 
> > > 19 // Elasticsearch  
> > > 20 $clientparams = array();  
> > > 21 $clientparams['hosts'] = array(  
> > > 22 '[https://host01:443](https://host01:443)'  
> > > 23 );  
> > > 24  
> > > 25 $clientparams['guzzleOptions'] = array(  
> > > 26 '\Guzzle\Http\Client::SSL\_CERT\_AUTHORITY' =\> 'system',  
> > > 27 '\Guzzle\Http\Client::CURL\_OPTIONS' =\> [  
> > > 28 'CURLOPT\_SSL\_VERIFYPEER' =\> true,  
> > > 29 'CURLOPT\_SSL\_VERIFYHOST' =\> 2,  
> > > 30 'CURLOPT\_CAINFO' =\> '.inc/cacert.pem',  
> > > 31 'CURLOPT\_SSLCERTTYPE' =\> 'PEM',  
> > > 32 ]  
> > > 33 );
> > > 
> > > The error:
> > > 
> > > PHP Fatal error: Uncaught exception  
> > > 'Elasticsearch\Common\Exceptions\TransportException' with message 'SSL  
> > > certificate problem: self signed certificate'
> > > 
> > > What did I miss?
> > > 
> > > Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a83720d1-5840-48c3-a952-ea6c38619ba5%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a83720d1-5840-48c3-a952-ea6c38619ba5%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [February 11, 2015, 7:01pm UTC](https://discuss.elastic.co/t/php-api-and-self-signed-certs/22052/5 "2015-02-11T19:01:49Z")

</div>

Glad you got it working! Just a note, I don't monitor the ES mailing list  
very closely...but if you have any more problems/questions with the PHP  
client in the future, feel free to just open a tick at the repo and I would  
be happy to help 🙂

-Z

On Wednesday, February 11, 2015 at 7:09:57 AM UTC-5, Paul Halliday wrote:

> That is the hint I needed.
> 
> I had it w/o quotes at first and the page was failing. I just assumed this  
> was because of the lack of quotes, which once added allowed the page to  
> load. I should have looked at the error console, which was showing the  
> missing include 🙂
> 
> All is good and working as expected.
> 
> On Tuesday, February 10, 2015 at 11:17:20 PM UTC-4, Ian MacLennan wrote:
> 
> > I suspect that it is because you put your constant names in quotes, and  
> > as a result the keys are going to be wrong. i.e. you  
> > have 'CURLOPT\_SSL\_VERIFYPEER' =\> true, while it should probably be  
> > CURLOPT\_SSL\_VERIFYPEER =\> true as shown in the link you provided.
> > 
> > Ian
> > 
> > On Tuesday, February 10, 2015 at 10:42:05 AM UTC-5, Paul Halliday wrote:
> > 
> > > Well, I got it working but had to make the declarations in CurlHandle.php
> > > 
> > > I added:
> > > 
> > > $curlOptions[CURLOPT\_SSL\_VERIFYPEER] = true;  
> > > $curlOptions[CURLOPT\_CAINFO] = '/full/path/to/cacert.pem';
> > > 
> > > directly above:
> > > 
> > > curl\_setopt\_array($handle, $curlOptions);  
> > > return new static($handle, $curlOptions);  
> > > ...
> > > 
> > > What's strange is that I also tried placing them in the default  
> > > $curlOptions but those seemed to get dumped somewhere prior to  
> > > curl\_setopt\_array()
> > > 
> > > Yucky, but working.
> > > 
> > > On Monday, February 9, 2015 at 7:05:34 PM UTC-4, Paul Halliday wrote:
> > > 
> > > > Hi,
> > > > 
> > > > I am trying to get the configuration example from here to work:
> > > > 
> > > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/client/php-api/current/_security.html#_guzzleconnection_self_signed_certificate)
> > > > 
> > > > My settings look like this:
> > > > 
> > > > 19 // Elasticsearch  
> > > > 20 $clientparams = array();  
> > > > 21 $clientparams['hosts'] = array(  
> > > > 22 '[https://host01:443](https://host01:443)'  
> > > > 23 );  
> > > > 24  
> > > > 25 $clientparams['guzzleOptions'] = array(  
> > > > 26 '\Guzzle\Http\Client::SSL\_CERT\_AUTHORITY' =\> 'system',  
> > > > 27 '\Guzzle\Http\Client::CURL\_OPTIONS' =\> [  
> > > > 28 'CURLOPT\_SSL\_VERIFYPEER' =\> true,  
> > > > 29 'CURLOPT\_SSL\_VERIFYHOST' =\> 2,  
> > > > 30 'CURLOPT\_CAINFO' =\> '.inc/cacert.pem',  
> > > > 31 'CURLOPT\_SSLCERTTYPE' =\> 'PEM',  
> > > > 32 ]  
> > > > 33 );
> > > > 
> > > > The error:
> > > > 
> > > > PHP Fatal error: Uncaught exception  
> > > > 'Elasticsearch\Common\Exceptions\TransportException' with message 'SSL  
> > > > certificate problem: self signed certificate'
> > > > 
> > > > What did I miss?
> > > > 
> > > > Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4821d7fc-5ce0-4b1a-a46f-fb20c61eb475%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4821d7fc-5ce0-4b1a-a46f-fb20c61eb475%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:33am UTC](https://discuss.elastic.co/t/php-api-and-self-signed-certs/22052/6 "2017-07-06T00:33:26Z")

</div>


