调用Vector Store检索器时遇OPENSSL_internal:CERTIFICATE_VERIFY_FAILED错误
解决Vertex AI向量检索时的OPENSSL_internal:CERTIFICATE_VERIFY_FAILED错误
问题场景
开发GenAI应用,技术栈包含:Vertex AI向量数据库存储私有数据、GPT-4作为大语言模型、LangChain作为编排器。创建向量存储索引时使用的凭证正常可用,但调用vector_store检索器执行相似性搜索时,触发SSL证书验证失败错误。
示例代码:
aiplatform.init(credentials=credentials, project=PROJECT_ID, location=REGION, staging_bucket=BUCKET_URI) my_index = aiplatform.MatchingEngineIndex.list()[0] my_index_endpoint = aiplatform.MatchingEngineIndexEndpoint.list()[0] embedding_model = VertexAIEmbeddings(model_name="textembedding-gecko@003") vector_store = VectorSearchVectorStore.from_components( project_id=PROJECT_ID, region=REGION, gcs_bucket_name=BUCKET, index_id=my_index.name, endpoint_id=my_index_endpoint.name, embedding=embedding_model, ) # Initialize the vectore_store as retriever retriever = vector_store.as_retriever() # perform simple similarity search on retriever result = retriever.invoke("What are my options in breathable fabric?") #<<<<<ERROR here
错误详情:
google.api_core.exceptions.ServiceUnavailable: 503 failed to connect to all addresses; last error: UNKNOWN: ipv4:34.128.134.161:443: Ssl handshake failed (TSI_PROTOCOL_FAILURE): SSL_ERROR_SSL: error:1000007d:SSL routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED
解决方案
1. 更新本地SSL证书库
确保运行环境的SSL根证书为最新版本,Python环境可通过升级certifi库解决:
pip install --upgrade certifi
若使用自定义企业CA证书,可在代码中指定证书路径:
import os os.environ['REQUESTS_CA_BUNDLE'] = '/path/to/your/enterprise-ca.pem' os.environ['SSL_CERT_FILE'] = '/path/to/your/enterprise-ca.pem'
2. 验证网络与防火墙配置
- 测试端点的SSL连通性:
curl -v https://34.128.134.161:443 - 若处于企业内网,确认防火墙未拦截Vertex AI的443端口流量,或已配置代理允许访问Google Cloud服务。
3. 升级依赖包到兼容版本
版本不匹配可能导致SSL握手逻辑异常,升级相关依赖:
pip install --upgrade langchain google-cloud-aiplatform langchain-google-vertexai
4. 确认凭证权限与作用域
确保使用的凭证拥有以下权限:
aiplatform.indexes.getaiplatform.indexEndpoints.predict
同时确认凭证的OAuth2作用域包含https://www.googleapis.com/auth/cloud-platform。
5. 使用完整的端点资源名称
初始化VectorSearchVectorStore时,endpoint_id传入完整的资源名称(而非仅ID),格式为:
endpoint_id=f"projects/{PROJECT_ID}/locations/{REGION}/indexEndpoints/{ENDPOINT_ID}"
这样LangChain会调用Vertex AI的官方域名端点,避免IP地址导致的证书不匹配问题。
内容的提问来源于stack exchange,提问作者Sanjay Nagaraj
相关产品推荐
相关产品推荐

