根本原因是php openssl扩展无法验证远程仓库tls证书链,因ca证书缺失或路径配置错误;需通过php -r "print_r(openssl_get_cert_locations());"确认default_cert_file有效性,并在php.ini中正确设置openssl.cafile指向权威cacert.pem绝对路径。

为什么 composer install 会卡在 SSL handshake failed?
根本原因不是 Composer 本身有问题,而是 PHP 的 OpenSSL 扩展在发起 HTTPS 请求时,无法验证远程仓库(如 packagist.org)的 TLS 证书链。常见现象是报错:SSL operation failed with code 1. OpenSSL Error messages: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed。这通常意味着系统缺少可信 CA 证书,或 PHP 没有正确加载它们。
确认 PHP 是否用了系统 CA 包(而非内置空包)
PHP 默认可能用的是编译时自带的、过期或为空的 cafile。先查当前生效的配置:
php -r "print_r(openssl_get_cert_locations());"
重点关注 ["capath"] 和 ["default_cert_file"] 路径是否存在、是否可读。Ubuntu/Debian 上通常是 /etc/ssl/certs/ca-certificates.crt;macOS(Homebrew PHP)可能是 /opt/homebrew/etc/openssl@3/cert.pem。如果 default_cert_file 是空路径或指向不存在文件,就得手动指定。
- 临时修复:运行
composer install --no-plugins --no-scripts前加环境变量export PHP_SSL_CAFILE=/etc/ssl/certs/ca-certificates.crt - 永久修复:修改
php.ini,添加或修正openssl.cafile=/etc/ssl/certs/ca-certificates.crt(路径按实际调整) - 别改
curl.cainfo—— Composer 不走 cURL 的 CA 配置,只认 OpenSSL 的
Windows 上 WAMP/XAMPP 用户的典型陷阱
WAMP/XAMPP 自带的 PHP 往往把 openssl.cafile 指向一个不存在的 cacert.pem 文件(比如 C:\wamp64\bin\php\php8.2.12\extras\ssl\cacert.pem),而这个路径下压根没这个文件。
- 去 https://www.php.cn/link/5fe4dadcdb001d8566cd20e6d8a20251 下载最新
cacert.pem,保存到对应目录 - 检查
php.ini中openssl.cafile是否指向该文件的**绝对路径**(不能用相对路径) - 重启 Apache 或 CLI PHP 进程,再运行
php -m | grep openssl确认模块已加载 - 避免用
composer config --global cafile ...—— 这个设置只影响 Composer 自己的 HTTP 客户端,不解决 PHP 底层 OpenSSL 的证书验证问题
CI/CD 环境(Docker、GitHub Actions)中证书缺失的快速补救
Alpine 或精简镜像常删掉 ca-certificates 包,导致 PHP 的 OpenSSL 没 CA 可用。不能只装 PHP,得确保基础证书信任链完整。
- Alpine:在 Dockerfile 中加
apk add --no-cache ca-certificates,并确认/etc/ssl/certs/ca-certificates.crt存在 - Ubuntu/Debian:确保安装了
ca-certificates包,且执行过update-ca-certificates - GitHub Actions:用
actions/setup-php时,加参数extensions: ['openssl']并显式指定php-version,它会自动处理 CA - 别在 CI 中设
COMPOSER_DISABLE_TLS=1—— 这等于关掉 HTTPS,存在中间人风险,只是掩盖问题
真正要盯住的,永远是 PHP 进程启动时看到的 openssl.cafile 路径是否真实、有效、可读。其他所有“跳过验证”的方案,都是在绕开证书信任机制本身。











