Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use curl -k or curl --insecure to make a cURL transfer without verifying the server certificate:

curl --insecure https://example.com

This skips peer-certificate verification; it does not repair the certificate, prove the server is legitimate, or make the connection safe for production. Use it only for a tightly scoped diagnostic or local-development test, then remove it. The safer long-term solution is to give cURL the expected CA certificate with --cacert or configure the correct trust store.

What cURL normally verifies

For an HTTPS URL, cURL verifies the server certificate against its configured certificate authorities (CAs) and checks that the certificate identity matches the hostname in the URL. A failure commonly appears as curl: (60) SSL certificate problem: unable to get local issuer certificate, although the exact wording varies by build and TLS backend. Error 60 means cURL could not complete certificate verification with the trust information available to it; it does not by itself prove that the certificate is self-signed.

Other causes include an incomplete certificate chain, an expired certificate, a hostname mismatch, or a CA store that is missing the issuer. The curl project documents this behavior in its SSL CA Certificates guide, man page, and FAQ.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Skip verification for one transfer

Short and long options

These options are equivalent:

curl -k https://example.com
curl --insecure https://example.com

They disable verification of the peer certificate for that cURL invocation. You can combine the option with output, redirects, headers, authentication, or another URL option as usual:

curl --insecure -L https://dev.internal.example/api/health
curl -k -o response.json https://localhost:8443/status

-k is convenient interactively; --insecure is more explicit in scripts. Neither option changes the remote certificate or enables encryption beyond the TLS session itself.

What this does not fix

  • It does not correct a wrong hostname, expired certificate, or broken server chain.
  • It does not authenticate the endpoint. An attacker able to intercept traffic can present a different certificate without cURL rejecting it.
  • It does not automatically disable verification for a separate HTTPS proxy connection.

The curl project warns against using disabled verification in production. Its libcurl security guidance says, “Never ever switch off certificate verification.”

Diagnose the failure before bypassing it

1. Read the complete error

Run a verbose request without -k:

curl -v https://example.com

Look for messages about an unknown issuer, an incomplete chain, an expired certificate, or a name mismatch. A self-signed certificate is expected in some private environments, but a public website normally should provide a chain that reaches a trusted CA.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Check the URL hostname

Make sure the hostname in the URL is the name covered by the certificate. Peer trust and hostname matching are separate checks in libcurl. Turning off peer verification is not a general solution for a name mismatch; use the correct DNS name or issue a certificate containing the required Subject Alternative Name. The hostname check is described by CURLOPT_SSL_VERIFYHOST.

3. Check the server chain

A server may send only its leaf certificate and omit an intermediate CA. Browsers can sometimes fill gaps from cached intermediates, while cURL may fail. Configure the server to send the complete chain rather than teaching every client to bypass checks.

4. Check the local trust store

Corporate, laboratory, and development CAs must be installed or explicitly supplied to the client. cURL builds differ: Schannel builds use the Windows native CA store, some Apple configurations can use Apple SecTrust, and other builds commonly use a file-based bundle. Check your build and operating system before assuming a particular path.

The safer fix: trust the expected CA

Use --cacert for one command

Obtain the CA certificate through a trusted channel from the system or service administrator. Do not download a random PEM file over the same untrusted connection you are trying to secure. Then point cURL at it:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl --cacert path/to/ca.pem https://internal.example

This preserves certificate and hostname checks while adding the CA needed to validate the expected server certificate.

Configure a CA file or directory

For supported cURL command-line builds, CURL_CA_BUNDLE, SSL_CERT_FILE, and SSL_CERT_DIR can select a CA file or directory:

export CURL_CA_BUNDLE=/etc/ssl/private/company-ca.pem
curl https://internal.example

Use the native trust-store management recommended for your platform when possible. The exact environment-variable support and default locations depend on the cURL version, TLS backend, and operating system; confirm with curl -V and your platform documentation.

Compare the two approaches

Approach Effect Security and scope
--cacert or a correctly configured trust store Adds or selects a CA source so the expected certificate can be validated Retains peer and hostname checks; preferred for ongoing use
-k / --insecure Skips peer-certificate verification for the transfer Insecure and limited in confidence; reserve for constrained diagnostics

Proxy connections need separate options

With an HTTPS proxy, there can be two TLS connections: cURL-to-proxy and cURL-to-origin. --insecure and --cacert govern the origin server connection. For the proxy connection, use --proxy-insecure to skip proxy certificate verification or --proxy-cacert to provide the proxy CA:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl --proxy https://proxy.example:8443 
  --proxy-cacert proxy-ca.pem 
  https://origin.example

Avoid applying --proxy-insecure merely because the origin certificate is private; verify each connection independently.

Keep the bypass out of production

Limit its scope

  • Use it on a single command rather than placing it in a global configuration file.
  • Prefer a disposable test environment and a non-sensitive endpoint.
  • Do not send passwords, tokens, cookies, or personal data while verification is disabled.
  • Remove -k from shell history, CI scripts, container images, and copied documentation when testing ends.

Understand HSTS and Alt-Svc implications

The curl documentation notes that disabled verification can allow cURL to trust some server-supplied HSTS or Alt-Svc information without the normal certificate assurance. That is an additional reason not to leave the option enabled in automation.

Prefer an explicit development CA

For local HTTPS, create or obtain a development CA, install its public certificate in the developer machine or container trust store, and issue a certificate for the exact hostname used (such as localhost or a development DNS name). This keeps the same verification path that production code will use.

Common errors and fixes

“SSL certificate problem: self-signed certificate”

If the certificate is intentionally self-signed, save the trusted public certificate and use --cacert. If it is not expected, investigate DNS, interception, and server configuration instead of bypassing the warning.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“unable to get local issuer certificate”

The server chain may be incomplete, or your CA store may lack the issuer. Fix the chain on the server or add the organization’s CA to cURL’s configured store.

“certificate subject name does not match target host name”

Use the hostname listed in the certificate’s Subject Alternative Name, or issue a new certificate containing the requested name. -k would hide the error without establishing endpoint identity.

It works in a browser but not cURL

Compare the browser’s managed trust store with the cURL build’s CA source. On Windows, Schannel generally uses the Windows store; other builds may use a PEM bundle. Check curl -V, the CA path reported by your build, and whether the server sends intermediates.

It works without a proxy but fails through one

Configure the proxy CA with --proxy-cacert or, only for a controlled diagnostic, use --proxy-insecure. Keep origin verification configured separately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A script still fails after adding --cacert

Confirm the file is readable PEM data, contains the issuing CA (not merely the leaf certificate when a CA is required), and is passed to the same cURL binary used by the script. Check quoting and relative paths in the execution environment.

Useful inspection commands

curl -V
curl --help all | grep -E 'insecure|cacert|proxy-cacert'
curl -v https://host.example
curl --cacert ./company-ca.pem -v https://host.example

curl -V shows the version, TLS library, and supported features. The verbose trace helps distinguish trust-store, hostname, chain, and proxy failures without disabling verification.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your actual task is capturing a web page rather than debugging its TLS certificate, ScreenshotNeo provides a one-request screenshot API at screenshotneo.com. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets. Only clean shots are billed; bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and each response reports the result in X-Page-Verdict and X-Billed headers. It also offers an MCP server for AI agents with take_screenshot, get_page_info, and capture_pdf.

For a direct image request, see the ScreenshotNeo API documentation:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

FAQ

Does -k disable HTTPS encryption?

No. TLS can still encrypt the traffic, but cURL no longer verifies that the certificate belongs to the intended server.

Is --insecure safe on localhost?

It can be reasonable for a short, isolated local test, but use a trusted development CA when the command becomes shared, automated, or connected to sensitive data.

Can I disable only hostname verification?

Do not use a partial workaround to conceal a name mismatch. Correct the URL or certificate identity; cURL’s peer and hostname checks protect different properties.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

What is curl error 60?

It means cURL could not verify the server certificate using its configured trust information and hostname checks. A missing CA, incomplete chain, expired certificate, or hostname problem can all cause it.

Where should I put a self-signed certificate?

Use the certificate authority that issued it, obtained through a trusted channel, with –cacert for a single command or your platform/cURL trust store for recurring use.

How do I bypass an HTTPS proxy certificate?

Use –proxy-insecure only for a constrained diagnostic, or preferably provide the proxy CA with –proxy-cacert. These options apply to the proxy TLS connection, not the origin server.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.