How to Ignore SSL Certificate Errors With Wget (and Trust One Instead)

Rewritten as a tested reference. Every command below was run by the example package against three local HTTPS servers (a self-signed certificate, an expired one, and one issued by a local internal CA) and the output is copied from that run: wget 1.25.0 built with OpenSSL on macOS, plus the same core cases on Debian's GnuTLS build of wget 1.21.3 in a container. The 2024 version presented SSL_CERT_FILE as a wget feature; measured, it works on the OpenSSL build and is ignored on the GnuTLS build. New: the error messages and their causes on both builds, .wgetrc, --ca-directory, --pinnedpubkey, the internal-CA case, exit codes. Gone: a stray "Meta Description" section, unsourced breach statistics, and a wrapper script.
The flag you are looking for, run against the package's self-signed test server (substitute your URL):
wget -nv -O- --no-check-certificate https://localhost:8443/index.html
WARNING: cannot verify localhost's certificate, issued by 'CN=localhost':
Self-signed certificate encountered.
<!doctype html><title>self-signed fixture</title><p>served over HTTPS</p>
<time> URL:https://localhost:8443/index.html [74/74] -> "-" [1]
exit=0
The download proceeds and the warning stays. The one-line way to make the error go away without switching verification off, when you have the server's certificate or your CA file:
wget -nv -O- --ca-certificate=certs/localhost.pem https://localhost:8443/index.html
<!doctype html><title>self-signed fixture</title><p>served over HTTPS</p>
<time> URL:https://localhost:8443/index.html [74/74] -> "-" [1]
exit=0
The rest of this page shows what each option does with the real output, how to read the different error messages, how to make a setting permanent, and what does and does not work depending on how your wget was built. Prefer curl? See How to ignore SSL certificate errors in cURL; the same problem in Python is in Python Requests: ignore SSL certificate errors.



