# FTP Secure transfer with CURL isn't working

**URL:** https://forum.infinityfree.com/t/ftp-secure-transfer-with-curl-isnt-working/71316
**Category:** Hosting Support
**Created:** [January 18, 2023, 11:59am UTC](https://forum.infinityfree.com/t/ftp-secure-transfer-with-curl-isnt-working/71316 "2023-01-18T11:59:09Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![prahladyeri](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/prahladyeri/32/31210_2.png) [@prahladyeri](https://forum.infinityfree.com/u/prahladyeri)
#### Post date: [January 18, 2023, 11:59am UTC](https://forum.infinityfree.com/t/ftp-secure-transfer-with-curl-isnt-working/71316/1 "2023-01-18T11:59:09Z")

</div>

### Username (e.g. epiz\_XXX) or Website URL

epiz\_33357877

### Error Message

```auto
curl: (60) SSL certificate problem: unable to get local issuer certificate
More details here: https://curl.haxx.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the web page mentioned above.

```

### Other Information

First, let me start by saying super thank you for providing this wonderful hosting facility for us plebs 👍

So the usual/recommended FTP transfer method using [FileZilla](https://filezilla-project.org/download.php?type=client) works perfectly for me. Even the curl transfer works but only as long as I’m using the plain ftp and not “ftp secure” route (SSL over TLS). While trying to use the secure version, I’m getting below error:

```auto
>curl --ftp-ssl --cacert /path/to/cacert.pem -u epiz_33357877:<password> -T test.txt ftp://ftpupload.net/htdocs/
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
  0 0 0 0 0 0 0 0 --:--:-- 0:00:02 --:--:-- 0
curl: (60) SSL certificate problem: unable to get local issuer certificate
More details here: https://curl.haxx.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the web page mentioned above.

```

I’ve tried using the latest CA certificate from the curl website as described in [this stackoverflow link](https://stackoverflow.com/questions/24611640/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate) but I’m still getting this same error. I’ve also tried both `--ssl` and `ftp-ssl` switches with the same result.

Finally, I also tried the “ftps” protocol instead of plain “ftp” on port 21. This time, I got the “wrong version number” error like this:

```auto
>curl --ftp-ssl --cacert /path/to/cacert.pem -u epiz_33357877:<password> -T test.txt ftps://ftpupload.net:21/htdocs/
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
  0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0
curl: (35) error:1408F10B:SSL routines:ssl3_get_record:wrong version number

```

The [FileZilla](https://filezilla-project.org/download.php?type=client) method works perfectly, but I’m trying to automate my build and deployment tooling so that for every few PHP file uploads, I don’t have to open [FileZilla](https://filezilla-project.org/download.php?type=client) but be able to run this command in a batch script or something. Can you suggest something to get rid of this error?

---

<div class="post-metadata">

### Author: ![Greenreader9](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/greenreader9/32/22847_2.png) [@Greenreader9](https://forum.infinityfree.com/u/Greenreader9)
#### Post date: [January 18, 2023, 1:14pm UTC](https://forum.infinityfree.com/t/ftp-secure-transfer-with-curl-isnt-working/71316/2 "2023-01-18T13:14:57Z")

</div>

Free hosting does not support SFTP, only FTP over port 21.

There is a security certificate installed in the domain [ftpupload.net](http://ftpupload.net).

---

<div class="post-metadata">

### Author: ![prahladyeri](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/prahladyeri/32/31210_2.png) [@prahladyeri](https://forum.infinityfree.com/u/prahladyeri)
#### Post date: [January 18, 2023, 1:39pm UTC](https://forum.infinityfree.com/t/ftp-secure-transfer-with-curl-isnt-working/71316/3 "2023-01-18T13:39:02Z")

</div>

> [@Greenreader9](#):
>
> Free hosting does not support SFTP, only FTP over port 21.

I’m not talking about SFTP which, as I understand, requires a proper SSH server access and free hosting doesn’t provide that. I’m talking about FTPS which is different. It’s a secure version of that plain FTP but served using TLS encryption on port 21.

To the best of my knowledge Infinity does support FTPS. One way to verify this is that when you connect using FileZilla for first time, it does ask you to confirm/trust the remote certificate.

[Difference between SFTP and FTPS](https://www.geeksforgeeks.org/difference-between-ftps-and-sftp/)

---

<div class="post-metadata">

### Author: ![ChrisPAR](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/chrispar/32/8743_2.png) [@ChrisPAR](https://forum.infinityfree.com/u/ChrisPAR)
#### Post date: [January 18, 2023, 2:13pm UTC](https://forum.infinityfree.com/t/ftp-secure-transfer-with-curl-isnt-working/71316/4 "2023-01-18T14:13:28Z")

</div>

> [@prahladyeri](#):
>
> Can you suggest something to get rid of this error?

Unless you want to avoid it for some reason, [disabling the verification (using -k)](https://curl.se/docs/sslcerts.html#:~:text=With%20the%20curl%20command%20line%20tool%2C%20you%20disable%20this%20with%20%2Dk/%2D%2Dinsecure.) would work.

---

<div class="post-metadata">

### Author: ![Admin](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/admin/32/36437_2.png) [@Admin](https://forum.infinityfree.com/u/Admin)
#### Post date: [January 19, 2023, 3:15pm UTC](https://forum.infinityfree.com/t/ftp-secure-transfer-with-curl-isnt-working/71316/5 "2023-01-19T15:15:56Z")

</div>

Our FTP server uses a certificate from Sectigo. However, it appears that the CA chain was not installed on the server, so cURL cannot verify the certificate with a standard CA bundle.

You can verify it if you use the signing certificate from Sectigo. You can get that one from Sectigo directly here: [Comodo Knowledge Base](https://support.sectigo.com/articles/Knowledge/Sectigo-Intermediate-Certificates) (you’ll need the “Sectigo RSA Domain Validation Secure Server CA” one).

---

<div class="post-metadata">

### Author: ![prahladyeri](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/prahladyeri/32/31210_2.png) [@prahladyeri](https://forum.infinityfree.com/u/prahladyeri)
#### Post date: [January 19, 2023, 5:00pm UTC](https://forum.infinityfree.com/t/ftp-secure-transfer-with-curl-isnt-working/71316/6 "2023-01-19T17:00:19Z")

</div>

Thank you, that works perfectly 👍  
Not on its own but only when you add the Sectigo cert to the CA bundle obtained from curl website. Here is the working command:

```bash
>curl --ftp-ssl --cacert d:\keys\ftpupload.net\bundle.pem -u epiz_33357877:<password> -T CHANGE.log ftp://ftpupload.net/htdocs/
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
100 1298 0 0 100 1298 0 215 0:00:06 0:00:06 --:--:-- 324

```

Note that “bundle.pem” is the curl CA bundle in which the Sectigo cert is appended in the end.

---

<div class="post-metadata">

### Author: ![system](https://infinityfree-forum-uploads.s3.dualstack.eu-central-1.amazonaws.com/original/3X/b/0/b024fd3fa88bae093c9576e55c2c94e33f890206.svg) [@system](https://forum.infinityfree.com/u/system)
#### Post date: [January 26, 2023, 5:01pm UTC](https://forum.infinityfree.com/t/ftp-secure-transfer-with-curl-isnt-working/71316/7 "2023-01-26T17:01:10Z")

</div>

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.
