Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Use curl -k or curl --insecure to make a cURL transfer without verifying the server certificate:
curl --insecure https://example.com
This skips peer-certificate verification; it does not repair the certificate, prove the server is legitimate, or make the connection safe for production. Use it only for a tightly scoped diagnostic or local-development test, then remove it. The safer long-term solution is to give cURL the expected CA certificate with --cacert or configure the correct trust store.
What cURL normally verifies
For an HTTPS URL, cURL verifies the server certificate against its configured certificate authorities (CAs) and checks that the certificate identity matches the hostname in the URL. A failure commonly appears as curl: (60) SSL certificate problem: unable to get local issuer certificate, although the exact wording varies by build and TLS backend. Error 60 means cURL could not complete certificate verification with the trust information available to it; it does not by itself prove that the certificate is self-signed.
Other causes include an incomplete certificate chain, an expired certificate, a hostname mismatch, or a CA store that is missing the issuer. The curl project documents this behavior in its SSL CA Certificates guide, man page, and FAQ.
#1 Best Overall
Skip verification for one transfer
Short and long options
These options are equivalent:
curl -k https://example.com
curl --insecure https://example.com
They disable verification of the peer certificate for that cURL invocation. You can combine the option with output, redirects, headers, authentication, or another URL option as usual:
curl --insecure -L https://dev.internal.example/api/health
curl -k -o response.json https://localhost:8443/status
-k is convenient interactively; --insecure is more explicit in scripts. Neither option changes the remote certificate or enables encryption beyond the TLS session itself.
What this does not fix
- It does not correct a wrong hostname, expired certificate, or broken server chain.
- It does not authenticate the endpoint. An attacker able to intercept traffic can present a different certificate without cURL rejecting it.
- It does not automatically disable verification for a separate HTTPS proxy connection.
The curl project warns against using disabled verification in production. Its libcurl security guidance says, “Never ever switch off certificate verification.”
Diagnose the failure before bypassing it
1. Read the complete error
Run a verbose request without -k:
curl -v https://example.com
Look for messages about an unknown issuer, an incomplete chain, an expired certificate, or a name mismatch. A self-signed certificate is expected in some private environments, but a public website normally should provide a chain that reaches a trusted CA.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →2. Check the URL hostname
Make sure the hostname in the URL is the name covered by the certificate. Peer trust and hostname matching are separate checks in libcurl. Turning off peer verification is not a general solution for a name mismatch; use the correct DNS name or issue a certificate containing the required Subject Alternative Name. The hostname check is described by CURLOPT_SSL_VERIFYHOST.
3. Check the server chain
A server may send only its leaf certificate and omit an intermediate CA. Browsers can sometimes fill gaps from cached intermediates, while cURL may fail. Configure the server to send the complete chain rather than teaching every client to bypass checks.
4. Check the local trust store
Corporate, laboratory, and development CAs must be installed or explicitly supplied to the client. cURL builds differ: Schannel builds use the Windows native CA store, some Apple configurations can use Apple SecTrust, and other builds commonly use a file-based bundle. Check your build and operating system before assuming a particular path.
The safer fix: trust the expected CA
Use --cacert for one command
Obtain the CA certificate through a trusted channel from the system or service administrator. Do not download a random PEM file over the same untrusted connection you are trying to secure. Then point cURL at it:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
curl --cacert path/to/ca.pem https://internal.example
This preserves certificate and hostname checks while adding the CA needed to validate the expected server certificate.
Configure a CA file or directory
For supported cURL command-line builds, CURL_CA_BUNDLE, SSL_CERT_FILE, and SSL_CERT_DIR can select a CA file or directory:
export CURL_CA_BUNDLE=/etc/ssl/private/company-ca.pem
curl https://internal.example
Use the native trust-store management recommended for your platform when possible. The exact environment-variable support and default locations depend on the cURL version, TLS backend, and operating system; confirm with curl -V and your platform documentation.
Compare the two approaches
| Approach | Effect | Security and scope |
|---|---|---|
--cacert or a correctly configured trust store |
Adds or selects a CA source so the expected certificate can be validated | Retains peer and hostname checks; preferred for ongoing use |
-k / --insecure |
Skips peer-certificate verification for the transfer | Insecure and limited in confidence; reserve for constrained diagnostics |
Proxy connections need separate options
With an HTTPS proxy, there can be two TLS connections: cURL-to-proxy and cURL-to-origin. --insecure and --cacert govern the origin server connection. For the proxy connection, use --proxy-insecure to skip proxy certificate verification or --proxy-cacert to provide the proxy CA:
Recommended Free Tools
curl --proxy https://proxy.example:8443
--proxy-cacert proxy-ca.pem
https://origin.example
Avoid applying --proxy-insecure merely because the origin certificate is private; verify each connection independently.
Keep the bypass out of production
Limit its scope
- Use it on a single command rather than placing it in a global configuration file.
- Prefer a disposable test environment and a non-sensitive endpoint.
- Do not send passwords, tokens, cookies, or personal data while verification is disabled.
- Remove
-kfrom shell history, CI scripts, container images, and copied documentation when testing ends.
Understand HSTS and Alt-Svc implications
The curl documentation notes that disabled verification can allow cURL to trust some server-supplied HSTS or Alt-Svc information without the normal certificate assurance. That is an additional reason not to leave the option enabled in automation.
Prefer an explicit development CA
For local HTTPS, create or obtain a development CA, install its public certificate in the developer machine or container trust store, and issue a certificate for the exact hostname used (such as localhost or a development DNS name). This keeps the same verification path that production code will use.
Common errors and fixes
“SSL certificate problem: self-signed certificate”
If the certificate is intentionally self-signed, save the trusted public certificate and use --cacert. If it is not expected, investigate DNS, interception, and server configuration instead of bypassing the warning.
“unable to get local issuer certificate”
The server chain may be incomplete, or your CA store may lack the issuer. Fix the chain on the server or add the organization’s CA to cURL’s configured store.
“certificate subject name does not match target host name”
Use the hostname listed in the certificate’s Subject Alternative Name, or issue a new certificate containing the requested name. -k would hide the error without establishing endpoint identity.
Rank #4
It works in a browser but not cURL
Compare the browser’s managed trust store with the cURL build’s CA source. On Windows, Schannel generally uses the Windows store; other builds may use a PEM bundle. Check curl -V, the CA path reported by your build, and whether the server sends intermediates.
It works without a proxy but fails through one
Configure the proxy CA with --proxy-cacert or, only for a controlled diagnostic, use --proxy-insecure. Keep origin verification configured separately.
A script still fails after adding --cacert
Confirm the file is readable PEM data, contains the issuing CA (not merely the leaf certificate when a CA is required), and is passed to the same cURL binary used by the script. Check quoting and relative paths in the execution environment.
Useful inspection commands
curl -V
curl --help all | grep -E 'insecure|cacert|proxy-cacert'
curl -v https://host.example
curl --cacert ./company-ca.pem -v https://host.example
curl -V shows the version, TLS library, and supported features. The verbose trace helps distinguish trust-store, hostname, chain, and proxy failures without disabling verification.
Or skip the browser setup
If your actual task is capturing a web page rather than debugging its TLS certificate, ScreenshotNeo provides a one-request screenshot API at screenshotneo.com. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets. Only clean shots are billed; bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and each response reports the result in X-Page-Verdict and X-Billed headers. It also offers an MCP server for AI agents with take_screenshot, get_page_info, and capture_pdf.
For a direct image request, see the ScreenshotNeo API documentation:
Free tools Windows power users keep installed
One-click scans. No signup required.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
Best Value
FAQ
Does -k disable HTTPS encryption?
No. TLS can still encrypt the traffic, but cURL no longer verifies that the certificate belongs to the intended server.
Is --insecure safe on localhost?
It can be reasonable for a short, isolated local test, but use a trusted development CA when the command becomes shared, automated, or connected to sensitive data.
Can I disable only hostname verification?
Do not use a partial workaround to conceal a name mismatch. Correct the URL or certificate identity; cURL’s peer and hostname checks protect different properties.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallFrequently Asked Questions
What is curl error 60?
It means cURL could not verify the server certificate using its configured trust information and hostname checks. A missing CA, incomplete chain, expired certificate, or hostname problem can all cause it.
Where should I put a self-signed certificate?
Use the certificate authority that issued it, obtained through a trusted channel, with –cacert for a single command or your platform/cURL trust store for recurring use.
How do I bypass an HTTPS proxy certificate?
Use –proxy-insecure only for a constrained diagnostic, or preferably provide the proxy CA with –proxy-cacert. These options apply to the proxy TLS connection, not the origin server.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

