---
title: 'Error: certificate verify failed (unable to get certificate CRL) (OpenSSL::SSL::SSLError)'
url: https://calvin.my/posts/error-certificate-verify-failed-unable-to-get-certificate-crl-openssl-ssl-sslerror
published: 2025-10-15
updated: 2026-09-13
category: Development
tags:
- Rails
- OpenSSL
summary: Ruby applications connecting to Google services may encounter an OpenSSL certificate verification failure related to certificate revocation lists. The problem stems from a behavior change in the underlying OpenSSL library rather than the service connection itself. A fix is available in version 3.3.1 of Ruby’s OpenSSL gem. To ensure the patched release is selected, applications should explicitly include the OpenSSL gem in their dependency configuration.
---

# Error: certificate verify failed (unable to get certificate CRL) (OpenSSL::SSL::SSLError)

An error appears in Ruby's OpenSSL gem when trying to connect to a Google Service.

```bash
certificate verify failed (unable to get certificate CRL) (OpenSSL::SSL::SSLError)
```

This issue is introduced by a behavioral change in the underlying OpenSSL library, and a patch for the OpenSSL gem (v3.3.1) is available. The detail is documented here: https://github.com/ruby/openssl/issues/949

* * *

To apply the fix, you should explicitly declare the openssl gem in your Gemfile. Otherwise, it might still be resolved to the older version.

```ruby
gem "openssl"
```

&nbsp;
