Zen Cart Logo
Forums / PayPal Express Checkout support / Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

Views: 4,378

Results 1 to 20 of 20
21 Dec 2015, 10:42 PM
#1
jrobletto avatar

jrobletto

New Zenner

Join Date:
Jun 2014
Location:
Oklahoma City, OK
Posts:
12
Plugin Contributions:
0

Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

I accidentally posted this question in the wrong thread (shipping/payment modules), so I apologize in advance for posting again... The problem is in regards to Paypal Express Checkout.

I have been working on this issue for many days and have read numerous previous posts and attempted several fixes, and to no avail... I will explain everything I can and hopefully some one can help...

I set up my ZC v. 1.5.4 at http://www.oopsheetmusic.com/store about 3 weeks ago. It has not been upgraded. I tried to setup the paypal express checkout and entered all the correct API credentials. The first error was - Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed.

I researched this problem and came across solutions involving updates to the php.ini file. I followed these updates and added the curl.cainfo = "" command pointing towards files such as cacert.pem, cabundle.crt, api_cert_chain.crt, etc... these attempts either gave me an error (77) or a (60).

For the cacert.pem file, I get a Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed as well, although the curltester.php shows Connecting to Zen Cart Support Server (https) ...GOOD: CURL Connection successful. Without the cacert.pem line, this line also gets an error (60).

The cabundle.crt gives me a Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs (including the Connecting to Zen Cart Support Server line.)

My research convinced me this was a server problem, I have hosting with Tierranet, but I have been bothering them and they have told me it is not a problem on their end... I talked to them about the new paypal updates, but they said they are definitely up to date and my SSL's are good. I ran a test of my site at https://www.ssllabs.com/ssltest/ as recommended in the post "PayPal upgrading SSL Certificates in 2015" and got an 'A'. It shows it is updated to reflect SHA256. I tried various other solutions such a 2014 POODLE update, but either they didn't help or I was already updated.

I tried to talk to Paypal about an updated cert that I could try to point the php.ini to but the only file they provided me with (g5.cer) caused an error (60) just as as if the curl.cainfo line wasn't there.

I have tried putting in different API credentials - nothing works.. same two errors. Any suggestions or assistance? I don't know if this is to do with the new Paypal Certs or what... but my site is ready to go other than this problem.

By the way, the error shows on the site as soon as you click pay with paypal... you never get to paypal. The error shows right there on my site... I don't know what to do next.

21 Dec 2015, 11:13 PM
#2
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

Your issue looks similar to this thread:

https://www.zen-cart.com/showthread.php?214105-SSL-certificate-problem-Verify-Failed

What happens if you run the curltester.php on your site?

/extras/curltester.php

Any errors?

22 Dec 2015, 12:35 AM
#3
jrobletto avatar

jrobletto

New Zenner

Join Date:
Jun 2014
Location:
Oklahoma City, OK
Posts:
12
Plugin Contributions:
0

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

I saw that thread... but my hosting company says everything is correct on their end and there is nothing they can do, other than giving me advice to change my php.ini file like I mentioned... but that just causes an Error (77), which is what I'm currently experiencing. Right now, I have the php.ini pointed towards a cabundle.crt I uploaded where they told me to... and when I run the curltester.php, I get:

Testing communications to various destinations. This is a simple diagnostic to determine whether your server can connect to common destinations.
For advanced "details" mode, add ?details=on to the URL.

Connecting to Zen Cart Support Server (http) ...
GOOD: CURL Connection successful.

Connecting to Zen Cart Support Server (https) ...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to USPS (port 80)...
GOOD: CURL Connection successful.

Connecting to USPS Test/Staging/Sandbox Server (port 80)...
GOOD: CURL Connection successful.

Connecting to UPS (port 80)...
GOOD: Socket established

Connecting to UPSXML (SSL) (wwwcie.ups.com) ...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to UPSXML (SSL) (https://www.ups.com) ...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to UPSXML (SSL) (onlinetools.ups.com) ...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to FedEx (port 80)...
GOOD: Socket established

Connecting to PayPal IPN (port 443)...
GOOD: Socket established

Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to PayPal IPN (port 443) Sandbox ...
GOOD: Socket established

Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to PayPal Express/Pro Server ...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to PayPal Express/Pro Sandbox ...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to PayPal Payflowpro Server ...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to AuthorizeNet Production Server ...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to AuthorizeNet Developer/Sandbox Server ...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to First Data GGe4 server (SSL)...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Connecting to LinkPointAPI server (port 1129)...
Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs

Testing completed. See results above.

....

When I take that line (curl.cainfo = "/users/oopsheetmusic.com/access/cabundle.crt") out of the php.ini, which is how it was originally, and run the curltester, it shows...

Testing communications to various destinations. This is a simple diagnostic to determine whether your server can connect to common destinations.
For advanced "details" mode, add ?details=on to the URL.

Connecting to Zen Cart Support Server (http) ...
GOOD: CURL Connection successful.

Connecting to Zen Cart Support Server (https) ...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to USPS (port 80)...
GOOD: CURL Connection successful.

Connecting to USPS Test/Staging/Sandbox Server (port 80)...
GOOD: CURL Connection successful.

Connecting to UPS (port 80)...
GOOD: Socket established

Connecting to UPSXML (SSL) (wwwcie.ups.com) ...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to UPSXML (SSL) (https://www.ups.com) ...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to UPSXML (SSL) (onlinetools.ups.com) ...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to FedEx (port 80)...
GOOD: Socket established

Connecting to PayPal IPN (port 443)...
GOOD: Socket established

Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to PayPal IPN (port 443) Sandbox ...
GOOD: Socket established

Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to PayPal Express/Pro Server ...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to PayPal Express/Pro Sandbox ...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to PayPal Payflowpro Server ...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to AuthorizeNet Production Server ...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to AuthorizeNet Developer/Sandbox Server ...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to First Data GGe4 server (SSL)...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Connecting to LinkPointAPI server (port 1129)...
Error 60: SSL certificate problem, verify that the CA cert is OK. Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
IMPORTANT NOTE: Error 60 or 61 means that this server has an SSL certificate configuration problem. YOU NEED TO ASK YOUR HOSTING COMPANY SERVER ADMIN FOR ASSISTANCE with fixing the server's OpenSSL certificate chain.
This error has nothing to do with Zen Cart. It is a server configuration issue.

(If you are running this test on a localhost/PC/dev/standlone server then you can either ignore this until you put the site on a live production server, or temporarily override things by manually configuring the CURLOPT_CAINFO value with a legitimate CA bundle. If you don't know what that means, just defer your CURL testing until you are on a live production webserver!)

Testing again with less security...
GOOD: CURL Connection successful. (but without being able to verify certificate chain. Again: this is a server issue, not a Zen Cart issue.)

Testing completed. See results above.

......

Do I need a different/updated cert file? Or is there another way to fix this problem? I have been bothering my hosting company for over a week calling and starting chats.. and they have said it's a problem with the intermediate certificate; and to go to paypal... paypal hasn't been able to help either though.

22 Dec 2015, 4:29 AM
#4
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

It is obviously the CA Bundle (intermediate cert) that gives you grief.

If your host is not willing to help further you may want to contact the issuer of your SSL cert and ask them for the correct CA Bundle / intermediate cert.

22 Dec 2015, 4:59 AM
#5
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

Also try this checker (leave port at 443) https://www.sslchecker.com/sslchecker

It tells me

ROOT 1 missing

29 Dec 2015, 6:04 PM
#6
jrobletto avatar

jrobletto

New Zenner

Join Date:
Jun 2014
Location:
Oklahoma City, OK
Posts:
12
Plugin Contributions:
0

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

Thank you for that; I'm still working on the problem... the certs that the SSL company gave me haven't helped... but I see that Root 1 missing error and am talking to the SSL Support about it now... still getting the error (77)...

29 Dec 2015, 6:20 PM
#7
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

Error 77 suggests to me that the CA files/paths you've specified aren't valid, or that CURL can't read them (permissions?).

This thread: https://www.zen-cart.com/showthread.php?216020-%2877%29-Problem-with-the-SSL-CA-cert-%28path-access-rights-%29-Solved talks about a similar issue, which was resolved by changing to a different PHP version ... and while it's not stated in the thread the reason that switching PHP versions solved it was because of the different php.ini used in the other PHP version.

29 Dec 2015, 6:55 PM
#8
jrobletto avatar

jrobletto

New Zenner

Join Date:
Jun 2014
Location:
Oklahoma City, OK
Posts:
12
Plugin Contributions:
0

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

Thanks - It seems a little more complicated than I thought to upgrade the PHP to 5.4. I did do a check of my current version and it is 5.3, so maybe upgrading to 5.4 would fix the problem... doing that seems to be not so easy; I need to use Putty or Terminal from most directions, which I've never done before... is there a site with some simple steps that any one knows of?

29 Dec 2015, 9:23 PM
#9
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

jrobletto:

Thanks - It seems a little more complicated than I thought to upgrade the PHP to 5.4. I did do a check of my current version and it is 5.3, so maybe upgrading to 5.4 would fix the problem... doing that seems to be not so easy; I need to use Putty or Terminal from most directions, which I've never done before... is there a site with some simple steps that any one knows of?
Upgrading the PHP version is a server-admin issue, not a Zen Cart issue. Your hosting company should take care of that. Some hosting companies offer choice of PHP versions ... for example, if the hosting company offers cPanel to administrate your hosting account, they often give you a PHP Selector from which you can simply choose the PHP version you want to use on your site (or even per-directory on your site). Most hosting companies document how to use this option, in their help docs.

30 Dec 2015, 3:29 PM
#10
jrobletto avatar

jrobletto

New Zenner

Join Date:
Jun 2014
Location:
Oklahoma City, OK
Posts:
12
Plugin Contributions:
0

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

I talked with my hosting company and was told that they are unable to upgrade my PHP version until the second quarter of this coming year once the new Ubuntu version is released, whatever that is.... so from talking to the SSL companies, the hosting company, paypal, and zen cart here, I believe I have good certs, SSLs are good, zen cart is set up correctly.. I put in the correct IPN credentials... and the site works fine other than paypal express...so not sure what to do next... wait for the second quarter of next year? That's sad hah... do I just use Paypal Standard? I really don't want to, but I'm running out of options.

30 Dec 2015, 4:57 PM
#11
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

When a hosting company demonstrates incompetence of basic configuration of CURL and secure communications with standard common CA Certificate stuff, it's time to demand support from their more experienced senior tech staff, and if they're also incompetent, demand your money back and move elsewhere. I hate doing that too, but sometimes it's the least painful solution.

Error 77: error setting certificate verify locations: CAfile: /users/oopsheetmusic.com/access/cabundle.crt CApath: /etc/ssl/certs
I do wonder whether they gave you wrong path information for the CAfile and CApath stuff. The error message certainly suggests that.

30 Dec 2015, 8:03 PM
#12
jrobletto avatar

jrobletto

New Zenner

Join Date:
Jun 2014
Location:
Oklahoma City, OK
Posts:
12
Plugin Contributions:
0

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

Thanks for your help; I had an extended chat with the hosting company today and they are supposed to be working in order replicate the problem and give me a solution. They may have given me wrong path info, but I uploaded the cert into the folder that the php.ini file points towards, and it still shows an error 77... and I tried it in different folders besides the one they told me to put it into, and tried it on my computer in C:/ as recommended in some other threads. I still get the error 77 or 60.

Well, hopefully they'll be able to help, otherwise I may do what you mentioned as far as going to another hosting company. I never thought just setting up the paypal payment would cause all this trouble... everything else went so smoothly; setting up the shopping cart, changing the template, updating the photos, inventory, etc. etc... no problems anywhere, except getting paid.. a somewhat important part of any business.

30 Dec 2015, 8:31 PM
#13
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

FWIW the curltester.php file is a standalone PHP file that simply demonstrates whether CURL and SSL and the corresponding CA Certs are working in conjunction with each other when invoked by PHP.
A hosting company can use it to quickly expose which problems exist in their PHP and SSL configuration ... without having to invoke Zen Cart to do "test purchases" as part of their testing.

31 Dec 2015, 12:48 AM
#14
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

DrByte:

When a hosting company demonstrates incompetence of basic configuration of CURL and secure communications with standard common CA Certificate stuff, it's time to demand support from their more experienced senior tech staff, and if they're also incompetent, demand your money back and move elsewhere. I hate doing that too, but sometimes it's the least painful solution.

I do wonder whether they gave you wrong path information for the CAfile and CApath stuff. The error message certainly suggests that.

Yeah, it does not seem to be right.

On most Linux servers with cPanel / WHM the certs/keys etc are installed in the subfolders of /home/username/ssl eg

/home/username/ssl/certs (certs, CA etc)
/home/username/ssl/csrs (certificate signing request)
/home/username/ssl/keys (your private keys)
/home/username/ssl/private (in most cases this folder is empty)

If you are using cPanel / WHM you can generate your own private keys and paste your supplied certs into the appropriate boxes. The certs are then automatically installed in the right locations on the server and your SSL should work almost instantly.

Just my 2 cents.

5 Jan 2016, 12:37 PM
#15
jnabird333 avatar

jnabird333

New Zenner

Join Date:
Dec 2015
Location:
Ohio
Posts:
16
Plugin Contributions:
0

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

I am having the same problem as well...it has already been an exhausting uphill battle to deal with my hosting company and have plans to move. However, in the meantime, I need to get my store working to accept PayPal Express payments.

I purchased my SSL Certificate from a 3rd party and ended up having to have my hosting company install as it kept telling me the certificate was in a wrong format. FWIW I was receiving the 60 error BEFORE the SSL was installed. Now, I am getting it again. They must have made some changes because then it switched to an error 77. Now, I am back to error 60 or 61 per the curltester.php. The hosting company insists everything is installed correctly and that it is a configuration error with zen cart. The only other thing I have done is used the https://www.sslchecker.com/sslchecker and it came back with the Root 1 missing. the hosting company insists this is a bug with that service.

I keep reading about installing/uploading the certs into a particular path and the php.ini paths but I have no idea about these steps. I am on a windows server with a plesk 11 control panel. I am running zen cart 1.5.4 with minimal modifications: custom theme, ckeditor plugin, stock by attribute (that was installed after this issue started). I have limited capabilities but can follow directions fairly well.

Any suggestions?

5 Jan 2016, 3:53 PM
#16
catmint avatar

catmint

New Zenner

Join Date:
Jan 2016
Location:
North Yorks UK
Posts:
6
Plugin Contributions:
0

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

I also am having a similar problem, the error I receive at checkout is

" An error occurred when we tried to contact the payment processor. Please try again, select an alternate payment method, or contact the store owner for assistance. () - (77) Problem with the SSL CA cert (path? access rights?)"

The site went live in october 2015 (https://www.catmint.biz/shop) and it all worked fine until about the 17th of december when these errors first appeared. (and I had not changed anything)

However in contrast to other posts in this and other threads I do not have an SSL certificate - the web shop is simple with low turn over and the customer account side of the website is disabled, so it is easier to use paypal express and let paypal worry about payment security and rely on the basic hoster security until I can get better organised. (there will be a SSL certificate in the near future)

What I have noticed though when I logged into my paypal account ( old style premier account) to double check the API details, is that my account had been reverted back to a standard account and I had to upgrade to a business account to access the API details as the premier option has been phased out, so Paypal is changing stuff. (I also checked the box that said accept payments from non API website as well to see if this helped, but to no avail)

I have spoken to my hoster this morning and they cannot detect any problems at their end, suggesting the problem either lay with zencart or paypal.

Zencart is version 1.5.4 running with php 5.5

The error log for this is Paypal_CURL_1451999353_qtxE8.log

SetExpressCheckout, Elapsed: 208ms -- Failed
(77) Problem with the SSL CA cert (path? access rights?)
Array
(
[url] => https://api-3t.paypal.com/nvp
[content_type] =>
[http_code] => 0
[header_size] => 0
[request_size] => 0
[filetime] => -1
[ssl_verify_result] => 0
[redirect_count] => 0
[total_time] => 0
[namelookup_time] => 0.005825
[connect_time] => 0.168704
[pretransfer_time] => 0
[size_upload] => 0
[size_download] => 0
[speed_download] => 0
[speed_upload] => 0
[download_content_length] => -1
[upload_content_length] => -1
[starttransfer_time] => 0
[redirect_time] => 0
[redirect_url] =>
[primary_ip] => 173.0.84.69
[certinfo] => Array
(
)

)

Any help will be greatly appreciated as it is somewhat frustrating especially as it was all working OK, though unfortunately I have to sit with jnabird333

jnabird333:

I keep reading about installing/uploading the certs into a particular path and the php.ini paths but I have no idea about these steps. I am on a windows server with a plesk 11 control panel. I am running zen cart 1.5.4 with minimal modifications: custom theme, ckeditor plugin, stock by attribute (that was installed after this issue started). I have limited capabilities but can follow directions fairly well.

Many thanks in advance

6 Jan 2016, 8:31 AM
#17
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

jnabird333:

I am having the same problem as well...it has already been an exhausting uphill battle to deal with my hosting company and have plans to move. However, in the meantime, I need to get my store working to accept PayPal Express payments.

I purchased my SSL Certificate from a 3rd party and ended up having to have my hosting company install as it kept telling me the certificate was in a wrong format. FWIW I was receiving the 60 error BEFORE the SSL was installed. Now, I am getting it again. They must have made some changes because then it switched to an error 77. Now, I am back to error 60 or 61 per the curltester.php. The hosting company insists everything is installed correctly and that it is a configuration error with zen cart. The only other thing I have done is used the https://www.sslchecker.com/sslchecker and it came back with the Root 1 missing. the hosting company insists this is a bug with that service.

I keep reading about installing/uploading the certs into a particular path and the php.ini paths but I have no idea about these steps. I am on a windows server with a plesk 11 control panel. I am running zen cart 1.5.4 with minimal modifications: custom theme, ckeditor plugin, stock by attribute (that was installed after this issue started). I have limited capabilities but can follow directions fairly well.

Any suggestions?
These SSL errors ("60", "61", "77") have nothing to do with purchasing an SSL certificate. They have everything to do with how the hosting company has installed and configured OpenSSL and the corresponding set of "root certificate authorities", and how they've then configured PHP to make use of it.

Until you move to a more competent host, it would seem your only solution is to properly specify a valid CAfile and CA path in your custom php.ini they've said you can use.

6 Jan 2016, 8:36 AM
#18
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

catmint:

However in contrast to other posts in this and other threads I do not have an SSL certificateAs I said earlier, this "77" error has nothing to do with a customer-facing SSL certificate. It's strictly related to the webserver configuration of OpenSSL, CA certificate authorities, and PHP's configuration to use them.

catmint:

The site went live in october 2015 ... and it all worked fine until about the 17th of december when these errors first appeared. (and I had not changed anything)It would seem it's your hosting company who's changed things. And if they don't know they did that, then, well, their slip is showing.

catmint:

(77) Problem with the SSL CA cert (path? access rights?)"

I have spoken to my hoster this morning and they cannot detect any problems at their end, suggesting the problem either lay with zencart or paypal.
Sadly, if they "cannot detect any problems at their end" then they don't know how to configure their server to handle secure communications with essential ecommerce services like payment gateways (ala paypal, etc). Thus it's time to either find someone on their staff who actually knows what they're talking about, or find a hosting company who employs such people.

Point them to the /extras/curltester.php script on your site, and let them use that to reveal when they've finally fixed their server configuration. That way they can work on fixing things without mangling your store while learning the basics of secure server administration.

7 Jan 2016, 6:15 AM
#19
jrobletto avatar

jrobletto

New Zenner

Join Date:
Jun 2014
Location:
Oklahoma City, OK
Posts:
12
Plugin Contributions:
0

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

PROBLEM SOLVED!!! :D Thirty years later, the problem is finally solved... after getting sent all over the place (From my hosting company to the SSL company, to the issuer of the intermediate cert company, back to the hosting, then to paypal... I've talked to every customer service rep on the internet by now)... the hosting company finally decided they would be the ones to help me solve this problem...

I don't know if I can help others, because I don't really understand what they did to fix it, but I will tell you what they told me... I eventually gave them my zen cart and ftp credentials so their engineers could get in there and work on it, since nothing I was doing was working... and after several failures, they finally got it working. I was told that...

*"The ultimate solution was updating the "php.ini" to point to a valid bundle
of CA certificates. We found one
named "api_cert_chain.crt" that was a good starting point, but was missing
two necessary certificates. We added these certificates to the file, and
the curlchecker is now returning all green.

What made this really complicated to figure out is there seems to be a
discrepancy between "What Mozilla trusts" and "What Ubuntu says Mozilla
trusts". Essentially, you downloaded a single file that contained all the
root certificates that Mozilla trusts. This file is missing two
certificates to work with major sites (like 'ups.com' and 'paypal.com'). We
identified this last night and added the two missing certificates, but there
was a concern as to why they weren't included in the bundle anymore."*

SO, if you are having this problem, and have tried updating the php.ini file and it is still not working, there is a chance that the cert file you're pointing to is missing certificates... I actually thought this might be the case and started finding every certificate I could possibly find and adding them to the file... just in the hopes that one or some of them would be the right ones.. but evidently I didn't find the right ones and my hosting company did... I don't know if this cert would be good for any one else, or if it's specific to the details of my domain and hosting co...

8 Jan 2016, 8:26 AM
#20
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Errors with Paypal Express Checkout (60)SSL Cert Problem/(77) error setting cert

Congrats. I'm glad it's been resolved for you.

Too bad it doesn't sound like your hosting company has any intention of updating the overall server configuration so that ALL their customers can benefit from the more complete modern configuration.