curl refused the connection because the server's certificate is self-signed (or your internal CA signed it). Fix by trusting the CA properly, not by disabling verification in production.
The server presents a cert with no trusted chain. Legitimate for internal tooling: import the cert (or your internal CA) into the trust store instead of bypassing checks per command forever.
Corporate environments sign internal certs with a private CA: browsers ship with it via policy, but a server/container won't have it. The error says self-signed but the real issue is the missing CA in the OS trust store.
openssl s_client -connect host:443 -servername host </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer
sudo cp internal-ca.crt /usr/local/share/ca-certificates/ && sudo update-ca-certificates
# Dockerfile: COPY internal-ca.crt /usr/local/share/ca-certificates/ && RUN update-ca-certificates
curl -k https://internal.example.com/ # or --insecure; never in scripts or CI that touches real systems
-k moves the failure from curl to your security posture: it accepts ANY certificate, including an attacker's. For internal CAs, install the CA once; for self-signed dev boxes, add the cert to the trust store. Python requests (verify=), Node (rejectUnauthorized), Java (cacerts) each have their own trust stores — fixing the OS store fixes curl, but per-runtime knobs exist for those.
The browser either has your corporate CA installed via policy or you clicked past its warning once. curl has no warning click-through — it enforces verification strictly, which is correct.
Trusting a specific internal CA you control is standard practice. The risky part is disabling verification (-k), which trusts everything. Scope it: keep the CA internal, and never add it to public-facing systems.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.
One short email when new fixes and production templates drop. No spam, unsubscribe anytime.
Zero-trust access and device security for your whole team — covers the hardening steps above.
Sentry — Catch the error behind this class of bug — exact line, stack and user context.
We earn a commission if you buy through our links — it never costs you extra. More vetted tools on our picks hub · comparing clouds? DigitalOcean vs Vultr and vs AWS · full deals: DigitalOcean · Vultr · NordLayer · Semrush