You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Vector Store检索器时遇OPENSSL_internal:CERTIFICATE_VERIFY_FAILED错误

解决Vertex AI向量检索时的OPENSSL_internal:CERTIFICATE_VERIFY_FAILED错误

问题场景

开发GenAI应用,技术栈包含:Vertex AI向量数据库存储私有数据、GPT-4作为大语言模型、LangChain作为编排器。创建向量存储索引时使用的凭证正常可用,但调用vector_store检索器执行相似性搜索时,触发SSL证书验证失败错误。

示例代码:

aiplatform.init(credentials=credentials, project=PROJECT_ID, location=REGION, staging_bucket=BUCKET_URI)
my_index = aiplatform.MatchingEngineIndex.list()[0]
my_index_endpoint = aiplatform.MatchingEngineIndexEndpoint.list()[0]
embedding_model = VertexAIEmbeddings(model_name="textembedding-gecko@003")
vector_store = VectorSearchVectorStore.from_components(
    project_id=PROJECT_ID,
    region=REGION,
    gcs_bucket_name=BUCKET,
    index_id=my_index.name,
    endpoint_id=my_index_endpoint.name,
    embedding=embedding_model,
)

# Initialize the vectore_store as retriever
retriever = vector_store.as_retriever()
# perform simple similarity search on retriever
result = retriever.invoke("What are my options in breathable fabric?") #<<<<<ERROR here

错误详情:

google.api_core.exceptions.ServiceUnavailable: 503 failed to connect to all addresses; last error: UNKNOWN: ipv4:34.128.134.161:443: Ssl handshake failed (TSI_PROTOCOL_FAILURE): SSL_ERROR_SSL: error:1000007d:SSL routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED

解决方案

1. 更新本地SSL证书库

确保运行环境的SSL根证书为最新版本,Python环境可通过升级certifi库解决:

pip install --upgrade certifi

若使用自定义企业CA证书,可在代码中指定证书路径:

import os
os.environ['REQUESTS_CA_BUNDLE'] = '/path/to/your/enterprise-ca.pem'
os.environ['SSL_CERT_FILE'] = '/path/to/your/enterprise-ca.pem'

2. 验证网络与防火墙配置

  • 测试端点的SSL连通性:
    curl -v https://34.128.134.161:443
    
  • 若处于企业内网,确认防火墙未拦截Vertex AI的443端口流量,或已配置代理允许访问Google Cloud服务。

3. 升级依赖包到兼容版本

版本不匹配可能导致SSL握手逻辑异常,升级相关依赖:

pip install --upgrade langchain google-cloud-aiplatform langchain-google-vertexai

4. 确认凭证权限与作用域

确保使用的凭证拥有以下权限:

  • aiplatform.indexes.get
  • aiplatform.indexEndpoints.predict
    同时确认凭证的OAuth2作用域包含https://www.googleapis.com/auth/cloud-platform。

5. 使用完整的端点资源名称

初始化VectorSearchVectorStore时,endpoint_id传入完整的资源名称(而非仅ID),格式为:

endpoint_id=f"projects/{PROJECT_ID}/locations/{REGION}/indexEndpoints/{ENDPOINT_ID}"

这样LangChain会调用Vertex AI的官方域名端点,避免IP地址导致的证书不匹配问题。

内容的提问来源于stack exchange,提问作者Sanjay Nagaraj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 08:03:10