Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

cURL error 60 means curl could not verify a TLS certificate. It does not, by itself, mean the proxy is unreachable. Find out whether verification failed on the connection to the destination website or to an HTTPS proxy, then configure curl to trust the correct, verified certificate authority (CA). Keep certificate and hostname verification enabled; -k is not a safe fix.

What cURL error 60 means

curl verifies certificates by default. Error 60 indicates that this check failed: curl could not establish that the certificate chain belongs to the intended peer. A missing or outdated CA bundle can cause the error. So can an untrusted certificate authority, an incomplete certificate chain, an expired certificate, or a certificate that does not match the hostname. See curl’s certificate verification documentation.

When a proxy is involved, there may be two separate TLS connections to consider. A regular HTTP proxy can carry a CONNECT tunnel to the destination; the TLS certificate curl verifies inside that tunnel is ordinarily the destination’s. An HTTPS proxy has its own TLS connection, whose certificate curl must verify in addition to the destination certificate. Those checks have separate trust settings. See libcurl’s proxy TLS verification documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Diagnose the failing connection first

Run a verbose request

Add -v to the failing command and inspect which proxy curl selects, what certificate authority file or store it reports, and where verification fails:

#1 Best Overall
Sale
TP-Link USB to Ethernet Adapter,Support Nintendo Switch,1Gbps,Plug and Play
  • 𝐇𝐢𝐠𝐡-𝐒𝐩𝐞𝐞𝐝 𝐔𝐒𝐁 𝐄𝐭𝐡𝐞𝐫𝐧𝐞𝐭 𝐀𝐝𝐚𝐩𝐭𝐞𝐫 - UE306 is a USB 3.0 Type-A to RJ45 Ethernet adapter that adds a reliable wired network port to your laptop, tablet, or Ultrabook. It delivers fast and stable 10/100/1000 Mbps wired connections to your computer or tablet via a router or network switch, making it ideal for file transfers, HD video streaming, online gaming, and video conferencing.
  • 𝐔𝐒𝐁 𝟑.𝟎 𝐟𝐨𝐫 𝐅𝐚𝐬𝐭𝐞𝐫, 𝐌𝐨𝐫𝐞 𝐒𝐭𝐚𝐛𝐥𝐞 𝐃𝐚𝐭𝐚 𝐓𝐫𝐚𝐧𝐬𝐟𝐞𝐫𝐬- Powered via USB 3.0, this adapter provides high-speed Gigabit Ethernet without the need for external power(10/100/1000Mbps). Backward compatible with USB 2.0/1.1, it ensures reliable performance across a wide range of devices.
  • 𝐒𝐮𝐩𝐩𝐨𝐫𝐭𝐬 𝐍𝐢𝐧𝐭𝐞𝐧𝐝𝐨 𝐒𝐰𝐢𝐭𝐜𝐡- Easily connect your Nintendo Switch to a wired network for faster downloads and a more stable online gaming experience compared to Wi-Fi.
  • 𝐏𝐥𝐮𝐠 𝐚𝐧𝐝 𝐏𝐥𝐚𝐲- No driver required for Nintendo Switch, Windows 11/10/8.1/8, and Linux. Simply connect and enjoy instant wired internet access without complicated setup.
  • 𝐁𝐫𝐨𝐚𝐝 𝐃𝐞𝐯𝐢𝐜𝐞 𝐂𝐨𝐦𝐩𝐚𝐭𝐢𝐛𝐢𝐥𝐢𝐭𝐲- Supports Nintendo Switch, PCs, laptops, Ultrabooks, tablets, and other USB-powered web devices; works with network equipment including modems, routers, and switches.

curl -v -x http://proxy.example:8080 https://example.com/

Substitute your actual proxy and destination. Verbose output can expose proxy details, headers, or other sensitive request information. Redact credentials, tokens, private hostnames, and sensitive URLs before sharing logs. The output can also indicate the CA source curl is using.

Check which proxy is actually selected

Proxy settings may come from command-line options or environment variables, including https_proxy and ALL_PROXY. When a protocol-specific proxy variable and the general variable both apply, curl gives the protocol-specific setting precedence. Check the variables and options in the shell or runtime that launches curl rather than assuming a particular proxy is active. See curl’s environment-variable documentation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a quick check in a Unix-like shell, print the relevant variables without posting the output publicly:

Rank #2
Amazon Basics USB 3.0 to 10/100/1000 Gigabit Ethernet Internet Adapter, Compatible with Windows and macOS, Black
  • Connects a USB 3.0 device (computer/laptop) to a router, modem, or network switch to deliver Gigabit Ethernet to your network connection. Does not support Smart TV or gaming consoles (e.g.Nintendo Switch).
  • Supported features include Wake-on-LAN function, Green Ethernet & IEEE 802.3az-2010 (Energy Efficient Ethernet)
  • Supports IPv4/IPv6 pack Checksum Offload Engine (COE) to reduce Cental Processing Unit (CPU) loading
  • Compatible with Windows 8.1 or higher, Mac OS

env | grep -i proxy

On Windows, inspect the environment in the same command prompt or PowerShell session that runs curl. Avoid putting proxy credentials into shared logs.

Distinguish HTTP and HTTPS proxy URLs

  • HTTP proxy: A URL such as http://proxy.example:8080 does not itself use TLS. For an HTTPS destination, curl normally establishes a CONNECT tunnel and then verifies the destination’s TLS certificate.
  • HTTPS proxy: A URL such as https://proxy.example:8443 adds a TLS connection to the proxy. Curl must trust that proxy certificate and the destination certificate inside the tunnel; the relevant CA option depends on which check failed.

A corporate proxy may inspect TLS and present a destination certificate signed by an organization-specific CA. In that case, curl may report an origin verification failure even though the certificate was issued by the inspecting proxy. The organization operating the proxy is the right source for its approved CA.

Fix an origin-server certificate failure

If the failed verification is for the destination, supply a CA bundle containing the legitimate CA certificate needed to verify the destination’s chain. For a single request, use --cacert:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

curl --cacert /path/to/approved-ca-bundle.pem -x http://proxy.example:8080 https://example.com/

Rank #3
USB A/C to Ethernet Adapter, 3xUSB3.0 and 1000M RJ45 Network hub for Laptop
  • [Expansion Ports] The USB C to Ethernet Adapter expands the device to three USB 3.0 ports and one Gigabit Ethernet port. Provides you more peripheral ports while maintaining a stable network connection, plug and play, no driver required.
  • [Gigabit Network Port] ALL-LUCKY USB Ethernet Adapter transmission rate up to 1000Mbps, also compatible with 10/100Mbps bandwidth. It allows you to enjoy a smooth and stable network connection and avoid too much lag. (Note: To reach 1Gbps, please use CAT6 or above Ethernet cable connection)
  • [Convertible Connector]This usb hub with ethernet not only has USB-A connector, but also can be converted to USB-C connector, so that you can easily convert the connector according to the device port, improve the convenience of use.
  • [High-Speed Data Transfer] The usb to ethernet adapter adopts USB 3.0 transmission technology, supports up to 5Gbps transmission rate, and is compatible with USB 2.0(480Gbps),USB 1.0(12Mbps), easily transfer video, files and other data for you in seconds. (Note: Maximum output current is 900mA, does not support charging devices.)
  • [Widely Compatible]The usb c ethernet adapter for iMac, MacBook Pro, iPad Pro, XPS and many other devices. Compatible with Windows 11/10/8.1/8, Mac OS, iPad OS, Chrome OS.(Note: Driver is required on Win 7) It can be used in office, school, library and other occasions, compact and portable, easy to carry around.

Use a bundle from a source you trust, such as the destination administrator or your organization’s IT team. Do not treat a certificate copied from an error message or an unverified network connection as trustworthy. A certificate can be genuine but still be the wrong CA for the connection.

For builds that support them, curl also documents CA environment variables such as CURL_CA_BUNDLE, SSL_CERT_FILE, and SSL_CERT_DIR. Their effect depends on the build and TLS backend; see curl’s certificate documentation and verify the active CA source with verbose output.

Fix an HTTPS proxy certificate failure

If the error is on curl’s TLS connection to an HTTPS proxy, configure trust for the proxy separately. Use --proxy-cacert with the CA that verifies the proxy certificate:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

curl --proxy-cacert /path/to/approved-proxy-ca.pem -x https://proxy.example:8443 https://example.com/

Rank #4
Anker USB C to Ethernet Adapter, Portable 1 Gbps Network Hub
  • The Anker Advantage: Join the 65 million+ powered by our leading technology.
  • Instant Internet: Connect to the internet instantly from virtually any USB-C 3.0 device, and enjoy stable connection speeds of up to 1 Gbps.
  • Lightweight and Compact: The space-saving and portable design measures just over half an inch thick and weighs about the same as a AA battery.
  • Premium Build: Features a sleek aluminum exterior and braided-nylon cable to complement the design of high-end devices.
  • What You Get: PowerExpand USB-C to Gigabit Ethernet Adapter, welcome guide, 18-month worry-free warranty, and friendly customer service.

Some curl versions and TLS backends support using the native system certificate store for the proxy connection with --proxy-ca-native. Confirm that the installed curl supports the option and that its TLS backend can use the native store before relying on it. Proxy-specific trust is distinct from the destination’s trust; if both connections need a non-default CA, configure each appropriately.

Apply the right fix for your platform or application

Check curl’s TLS backend and version

There is no single CA-installation command that applies to every operating system and curl build. On Windows, curl built with Schannel uses the Windows native certificate store. Other builds may use a CA bundle file, while some TLS backends can use a platform store when supported. Apple-system behavior also depends on whether the curl build uses Apple SecTrust. Options such as --ca-native, --proxy-ca-native, and proxy-specific CA options are version- and backend-dependent. Consult curl’s documentation and the installed version’s help before applying a platform-specific fix.

Separate command-line curl from application runtimes

A command-line request succeeding does not prove that PHP or another application using libcurl has the same CA configuration. The application may use a different libcurl build, TLS backend, bundle path, or runtime configuration. Check the runtime’s official documentation and inspect its actual CA settings; do not assume changing the command-line curl setup changes the application’s trust store.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Retest without weakening verification

  1. Run the request with verbose output and confirm the intended proxy and CA source are in use.
  2. Keep certificate and hostname checks enabled, and repeat the request with the appropriate origin or proxy CA configuration.
  3. Confirm that the response succeeds and that the certificate chain and hostname validate. If it still fails, investigate an incomplete server chain, expiration, hostname mismatch, the wrong CA, an unexpected proxy, or a different runtime trust store.

curl strongly recommends avoiding --insecure and says not to skip verification in production, even if using it for experimentation or development. Disabling verification can let a man-in-the-middle communicate with the client without the client knowing; encryption alone does not establish that the peer is the intended endpoint. See curl’s certificate guidance and its proxy verification warning.

Best Value
Sale
BENFEI USB 3.0 to Ethernet Adapter, USB C to RJ45 Gigabit LAN (1000Mbps) Network Adapter, Compatible with MacBook/Pro/Air, Surface Pro, Windows 11/10/8/7, Mac OS [Aluminium Shell&Nylon Cable]
  • COMPACT DESIGN - The compact-designed portable BENFEI USB A/C to Ethernet adapter connects your computer or tablet to a router,modem or network switch for network connection. It adds a standard RJ45 port to your Ultrabook, notebook or Macbook Air for file transferring, video conferencing, gaming, and HD video streaming.
  • SUPERIOR STABILITY - Built-in advanced IC chip works as the bridge between RJ45 Ethernet cable and your USB A/C devices. The driver-free installation with native driver support in Chrome, Mac, and Windows OS; The USB A/C Ethernet adapter dongle supports important performance features including Wake-on-Lan (WoL), Full-Duplex (FDX) and Half-Duplex (HDX) Ethernet, Crossover Detection, Backpressure Routing, Auto-Correction (Auto MDIX).
  • INCREDIBLE PERFORMANCE - Supports full 10/100/1000Mbps gigabit ethernet performance over USB A/C's 5Gbps bus, faster and more reliable than most wireless connections. Link and Activity LEDs. USB powered, no external power required. Backward compatible with USB 2.0/1.1.✅ To reach 1Gbps, make sure to use CAT6 & up Ethernet cables.
  • BROAD COMPATIBILITY - The USB A/C-Ethernet adapter is compatible with Windows 11/10/8.1/8/7/Vista/XP, Mac OSX 10.6/10.7/10.8/10.9/10.10/10.11/10.12, Linux kernel 3.x/2.6, Android and Chrome OS.Compatible with IEEE 802.3, IEEE 802.3u and IEEE 802.3ab. Supports IEEE 802.3az (Energy Efficient Ethernet).❌Do Not Support Windows RT. (NOT compatible with Nintendo Switch.)
  • 18 MONTH WARRANTY - Exclusive BENFEI Unconditional 18-month Warranty ensures long-time satisfaction of your purchase; Friendly and easy-to-reach customer service to solve your problems timely.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common causes and what to do

Symptom or cause What to check Safer next step
CA bundle missing or outdated Verbose output’s CA path or store, plus curl build and TLS backend. Update or configure the trusted CA source for that build, or supply an approved bundle with --cacert.
Organization’s TLS-inspecting proxy signs the destination certificate Whether the proxy is managed and whether its approved CA is installed for curl’s trust source. Obtain and authenticate the organization’s CA through its approved process; configure the trust source used by the failing connection.
HTTPS proxy certificate is untrusted Whether the proxy URL uses https:// and whether verification fails on the proxy TLS connection. Use the correct proxy CA with --proxy-cacert, or a supported native-store option.
Unexpected proxy is active Command-line proxy options and applicable environment variables such as https_proxy or ALL_PROXY. Correct the selected proxy and rerun the verbose request.
Certificate expired, chain incomplete, or hostname does not match The certificate chain, validity, and hostname for the peer whose verification failed. Ask the destination or proxy administrator to correct the certificate or chain; adding an unrelated CA will not repair it.
Terminal works but PHP or another application fails The application’s libcurl build, TLS backend, and CA configuration. Configure the application’s runtime separately using its official documentation.

Performance and reliability considerations

Providing a CA bundle for one command limits the change to that transfer; configuring a system or runtime trust store can help multiple requests but affects a broader scope. Choose the narrowest appropriate scope and preserve the CA’s provenance. A correct trust configuration resolves verification without removing the identity check that TLS is meant to provide. When the cause is a server-side certificate problem, the destination or proxy operator may need to fix its chain rather than asking clients to trust an unrelated certificate.

Or skip the browser setup

If your goal is to capture a website screenshot rather than troubleshoot a curl-based browser workflow, ScreenshotNeo offers a one-request screenshot API and an MCP server for AI agents. Its capture flow accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before the shot; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify the page verdict and billing status in headers.

For a screenshot response, use the documented API parameters and an access key:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for parameters and response details. An MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. The free plan includes 1,000 screenshots a month without a card; paid plans start at $5 for 3,000. Sign up for ScreenshotNeo’s free plan.

Frequently Asked Questions

Does error 60 mean my proxy is down?

No. It indicates certificate verification failed; the proxy may be reachable even when curl cannot validate a certificate.

Can I use the same CA option for the proxy and website?

Not necessarily. An HTTPS proxy and the destination have separate TLS connections and trust settings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Will fixing terminal curl automatically fix PHP?

Not necessarily. An application using libcurl may use a different build, TLS backend, or CA configuration.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.