Hi, thanks for getting back to me. curl generally works OK, here are the tests:
root@ip-172-31-12-147:/etc/ssl/certs# ls -la ca-certificates.crt
-rw-r–r– 1 root root 233394 Mar 4 2019 ca-certificates.crt
root@ip-172-31-12-147:/etc/ssl/certs#
root@ip-172-31-12-147:/etc/ssl/certs# curl -v https://google.com
* Rebuilt URL to: https://google.com/
* Trying 172.217.167.78…
* Connected to google.com (172.217.167.78) port 443 (#0)
* found 148 certificates in /etc/ssl/certs/ca-certificates.crt
* found 596 certificates in /etc/ssl/certs
* ALPN, offering http/1.1
* SSL connection using TLS1.2 / ECDHE_ECDSA_AES_128_GCM_SHA256
* server certificate verification OK
* server certificate status verification SKIPPED
* common name: *.google.com (matched)
* server certificate expiration date OK
* server certificate activation date OK
* certificate public key: EC
* certificate version: #3
* subject: C=US,ST=California,L=Mountain View,O=Google LLC,CN=*.google.com
* start date: Wed, 01 Apr 2020 12:58:27 GMT
* expire date: Wed, 24 Jun 2020 12:58:27 GMT
* issuer: C=US,O=Google Trust Services,CN=GTS CA 1O1
* compression: NULL
* ALPN, server accepted to use http/1.1
> GET / HTTP/1.1
> Host: google.com
> User-Agent: curl/7.47.0
> Accept: */*
>
< HTTP/1.1 301 Moved Permanently
< Location: https://www.google.com/
< Content-Type: text/html; charset=UTF-8
< Date: Mon, 20 Apr 2020 12:11:45 GMT
< Expires: Wed, 20 May 2020 12:11:45 GMT
< Cache-Control: public, max-age=2592000
< Server: gws
< Content-Length: 220
< X-XSS-Protection: 0
< X-Frame-Options: SAMEORIGIN
< Alt-Svc: quic=”:443″; ma=2592000; v=”46,43″,h3-Q050=”:443″; ma=2592000,h3-Q049=”:443″; ma=2592000,h3-Q048=”:443″; ma=2592000,h3-Q046=”:443″; ma=2592000,h3-Q043=”:443″; ma=2592000,h3-T050=”:443″; ma=2592000
<
<HTML><HEAD><meta http-equiv=”content-type” content=”text/html;charset=utf-8″>
<TITLE>301 Moved</TITLE></HEAD><BODY>
<H1>301 Moved</H1>
The document has moved
here.
</BODY></HTML>
* Connection #0 to host google.com left intact