Skip Tavakkolian wrote: |root CA certificates. David's reply jogged my memory; if i recall, i cat'ed |/etc/ssl/certs/*.pem of the ubuntu box and it was so i could go get. I've not really followed it but there was a thread on OpenSSL-users which mentioned an issue ([1]). That thread mentioned a go(1) program [2] which was later also suggested as good by Christian Heimes (in [1]). [1] [2] I'm using curl-ca-bundle from curl(1), but that's perl(1). --steffen