Skip to content

Getting "SSL server verification failed" on Windows as of late #2596

Description

@ungive

Me and other people who are using my software are getting this error lately (on Windows only):

httplib: Request failed: SSL server verification failed ssl_error=0 ssl_backend_error=20

Sometimes ssl_backend_error is 10 and sometimes it seems to be a garbage value (16777312), at least it's not defined here.

The code is simple (ignore the incorrect use of the API here, the method and parameters don't matter):

httplib::Client cli("https://accounts.spotify.com");
cli.enable_windows_certificate_verification(true);
auto result = cli.Get("/api/token");
if (result.error() != httplib::Error::Success) {
    std::cerr << "httplib: Request failed: "
        << httplib::to_string(result.error())
        << " ssl_error=" << result.ssl_error()
        << " ssl_backend_error=" << result.ssl_backend_error()
        // Use this when testing with some older versions of httplib:
        // << " ssl_openssl_error=" << result.ssl_openssl_error()
        << std::endl;
}

It works fine with other APIs, e.g. the iTunes API, Apple Music API and Deezer API.

This has never been an issue in the past. It works when using a recent CA bundle downloaded from here:

httplib::Client cli("https://accounts.spotify.com");
cli.set_ca_cert_path("C:\\Users\\User\\Downloads\\cacert-2026-09-25.pem");
auto result = cli.Get("/api/token");

FWIW, the issue also occurs with libcpr:

cpr::Response result = cpr::Get(
    cpr::Url{std::string("https://accounts.spotify.com") + "/api/token"});
if (result.error.code != cpr::ErrorCode::OK) {
    std::cerr << "libcpr: Request failed: "
        << result.error.message << std::endl;
}
libcpr: Request failed: SSL certificate problem: unable to get local issuer certificate

Here's a minimum reproduction example: https://github.com/ungive/httplib-bug-ssl-server-verification-failed

When I tested this earlier it worked with httplib version 0.30.2 and didn't anymore with 0.31.0. I can't reproduce that anymore though, it doesn't work with any httplib version I tested (0.30.2, 0.27.0 and 0.58.0). Version 0.31.0 changed certificate handling significantly: https://github.com/yhirose/cpp-httplib/releases?page=4#release-v0.31.0. Could it be that something went wrong there?

I would expect the library to properly use the Windows Certificate Store and not require me to add my own bundle.

This issue happened to one guy on my Discord server, then I saw it in application logs of people who had other issues and now I was even able to reproduce it on my own device. My app uses OpenSSL 3.0, I updated to 3.5 though and the issue persists, so I don't think this an OpenSSL issue.

Do you have an idea what might be going on? Is this expected behavior? I'd like to avoid explicitly bundling certificates in my app, as this was never necessary in the past. Thank you for any insights!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions