If you see this error when updating WordPress plugins or themes, this guide will help you fix it:
Update Failed: Download failed. cURL error 60: SSL certificate problem: unable to get local issuer certificate
What you’ll do: Replace an outdated SSL certificate file in WordPress using cPanel File Manager. Takes about 5 minutes, no technical experience needed.
Quick Navigation
- What Causes This Error?
- Alternative: Update WordPress Using WordPress Manager
- Manual Fix: Step-by-Step
- Troubleshooting
What Causes This Error?
When WordPress updates plugins or themes, it downloads files from WordPress.org using a secure SSL connection. To verify the connection is safe, WordPress checks the server’s SSL certificate against a trusted list stored in ca-bundle.crt.
The cURL error 60 means WordPress doesn’t recognise the certificate authority that issued WordPress.org’s certificate. This happens on older WordPress installations where the ca-bundle.crt file is outdated.
The fix: Replace the old certificate bundle with the latest version—or update WordPress itself, which does this automatically.
Alternative: Update WordPress Using WordPress Manager
If your WordPress core is outdated, the easiest fix is to update WordPress itself. This automatically replaces the outdated certificate file.
Use Ecenica WordPress Manager to update safely:
- Log in to your Ecenica Dashboard
- Click Manage next to your hosting service
- Click WordPress Manager
- Find your WordPress site and click Update if available
WordPress Manager handles the update safely and replaces outdated files automatically.
Full guide: How to Upgrade WordPress via WordPress Manager
If you can’t update WordPress (or still see the error after updating), follow the manual fix below.
Manual Fix: Step-by-Step
If updating WordPress doesn’t resolve the issue, or you need to keep your current WordPress version, follow these steps to replace the certificate file manually.
Before You Start
You’ll need:
- Access to cPanel — see Where do I log in to my hosting control panel?
- Your WordPress installation path (usually
public_html)
Step 1: Download the New Certificate File
- Download the latest certificate bundle from WordPress:
-
Your browser will display the file contents. Right-click and select Save As
- Save to your Downloads folder
Important: The filename must be exactly ca-bundle.crt. Some browsers add .txt to the end. If this happens, rename the file and remove .txt.
Step 2: Open File Manager for your Ecenica web hosting service
- Log in to Ecenica Dashboard
- Click Services > My Services.
- Click Manage next to your Ecenica web hosting service.
- Click File Manager.
File Manager will open in a new browser tab showing your web hosting files.
Step 3: Find the Certificates Folder
Navigate to:
public_html/wp-includes/certificates
WordPress in a subfolder? Adjust the path:
subfolder/wp-includes/certificates
Step 4: Backup the Old Certificate File
Before replacing the file, rename the old one as a backup.
- Find
ca-bundle.crt - Right-click and select Rename
- Add bak:
ca-bundle.crt.bak - Click Rename File
If anything goes wrong, you can restore this backup by renaming it back to ca-bundle.crt.
Step 5: Upload the New Certificate File
- Ensure you’re in the
/certificatesfolder - Click Upload
- Click Select File and choose the
ca-bundle.crtyou downloaded in Step 1 - Wait for upload to complete
- Click the back arrow to return to
/certificates - Confirm the new
ca-bundle.crtappears in the file list
Step 6: Test Your WordPress Updates
- Log in to your WordPress Dashboard
- Go to Dashboard > Updates
- Try updating a plugin or theme
The cURL error 60 should no longer appear.
You’re Done!
Your WordPress site can now securely download updates from WordPress.org. The error is fixed.
Still seeing issues? See Troubleshooting below.
Troubleshooting
The Error Still Appears
Check:
- File is named exactly
ca-bundle.crt(notca-bundle.crt.txt) - File is in
/wp-includes/certificates/ - Permissions are set to 644
I Don’t Have a Certificates Folder
Your WordPress installation may be damaged or non-standard. Contact Ecenica support for help.
I’m Not Sure Where WordPress is Installed
If you used Ecenica WordPress Manager, your site is likely in public_html. Check for a wp-includes directory in File Manager.
I Deleted the Old File Without Backing It Up
Download the file from the GitHub link in Step 1 and upload it. The file is the same for all WordPress installations.
File Manager Won’t Let Me Upload
Check your storage space. If full, delete unnecessary files or upgrade your plan.
Updates Still Fail After Replacing the File
Your WordPress version may be significantly outdated. Try updating WordPress using WordPress Manager (see Alternative: Update WordPress above).
If you’re unsure how to proceed, contact Ecenica support.
Frequently Asked Questions
Will this affect my live website?
No. You’re updating a file WordPress uses internally. Your site continues working normally.
Do I need to do this for every WordPress site?
Yes, if each site shows the error. Each WordPress installation has its own certificate file.
Is it safe to delete the backup file?
Yes, once updates work. Delete the renamed backup (e.g., ca-bundle.crt.20250321) after confirming everything works.
How often does this file need updating?
Rarely. Updating WordPress core refreshes this file automatically. Manual replacement is only needed when WordPress is outdated.
Need Help?
If you’re experiencing issues or need assistance, contact Ecenica support.