Azure App Service中OpenAI Python SDK SSL证书验证失败求助
Azure App Service中OpenAI Python SDK的SSL证书验证问题
问题场景与错误信息
在Azure App Service(Linux环境)的FastAPI应用启动阶段,使用OpenAI Python SDK连接部署了公司自签名证书的API网关时,触发SSL证书验证失败错误:
File "/opt/python/3.11.8/lib/python3.11/ssl.py", line 979, in do_handshake self._sslobj.do_handshake() ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get issuer certificate (_ssl.c:1006)
已执行的排查与尝试
1. 自定义证书捆绑包代码
尝试通过代码将自签名证书合并到自定义CA捆绑包,但未生效:
def trust_certificate(cert_path, def_rel_path="app/tmp"): #this did not work since custom_ca_bundle is in read_only filesystem. Let's create a file in local custom_ca_bundle = certifi.where() try: with open(custom_ca_bundle, 'ab') as f: with open(cert_path, 'rb') as cert: f.write(cert.read()) os.environ["REQUESTS_CA_BUNDLE"] = custom_ca_bundle return custom_ca_bundle except OSError: #if cannot open existing certs for write, create aonother cert file local_ca_bundle = os.path.abspath(def_rel_path+"/local_cert.pem") # Get the directory path from the filename directory = os.path.dirname(local_ca_bundle) # Create the directory structure if it doesn't exist os.makedirs(directory, exist_ok=True) with open(local_ca_bundle, 'wb') as local_cert: #this will be our new bundle with open(custom_ca_bundle, 'rb') as python_cert: #these probably could not have been opened before with open(cert_path, 'rb') as cert: #and this is our cert #now all of them go to the new file local_cert.write(python_cert.read()) local_cert.write(cert.read()) os.environ["REQUESTS_CA_BUNDLE"] = local_ca_bundle os.environ["SSL_CERT_FILE"] = local_ca_bundle os.environ['SSL_CERT_DIR'] = directory return local_ca_bundle
2. Azure门户添加证书验证
通过Azure门户将证书添加到App Service后,使用命令openssl s_client -connect <hostname>:443验证返回0(成功),但应用依然无法正常连接。
3. 证书路径检查
添加代码检查Python及OpenSSL使用的证书路径,输出如下:
vp["pyssl_capath"] = openssl_obj.capath vp["pyssl_openssl_capath"] = openssl_obj.openssl_capath vp["pyssl_openssl_capath_env"] = openssl_obj.openssl_capath_env vp["certifi"] = certifi.where() arg0 = ["openssl", "version", "-d"] ssl_cat_obj = subprocess.run(arg0,stdout=subprocess.PIPE, stderr=subprocess.PIPE) openssl_path = ssl_cat_obj.stdout.decode('utf-8').split("\"")[1]+"/certs" vp["openssl"] = openssl_path print(vp) > {'pyssl_capath': '/tmp/8dca2683adac9c1/app/tmp', 'pyssl_openssl_capath': '/usr/lib/ssl/certs', 'pyssl_openssl_capath_env': 'SSL_CERT_DIR', 'certifi': '/agents/python/certifi/cacert.pem', 'openssl': '/usr/lib/ssl/certs'}
openssl s_client使用的证书路径与Pythonssl.get_default_verify_paths()输出路径一致,但问题仍未解决。
4. subprocess调用openssl测试
通过Python的subprocess调用openssl s_client测试连接,代码如下:
# try to connect with default certificates arg1 = ["openssl", "s_client", "-connect", f"{host}:443"] ssl_try_def = subprocess.run(arg1,stdout=subprocess.PIPE, stderr=subprocess.PIPE) # Adding path to folder containing my self-signed cert by hand arg2 = ["openssl", "s_client", "-CApath", path, "-connect", f"{host}:443"] ssl_try_path = subprocess.run(arg2,stdout=subprocess.PIPE, stderr=subprocess.PIPE)
两个调用的stderr返回相同内容:
stderr: b'139809254405440:error:0200206F:system library:connect:Connection refused:../crypto/bio/b_sock2.c:110:\n139809254405440:error:2008A067:BIO routines:BIO_connect:connect error:../crypto/bio/b_sock2.c:111:\n139809254405440:error:02002063:system library:connect:Cannot assign requested address:../crypto/bio/b_sock2.c:110:\n139809254405440:error:2008A067:BIO routines:BIO_connect:connect error:../crypto/bio/b_sock2.c:111:\nconnect:errno=99\n'
补充说明
- 由于SDK内部调用无法修改,无法采用部分Stack Overflow解决方案
- 本人主要从事数据科学工作,对SSL领域不熟悉,找不到错误码errno=99的相关参考信息
内容的提问来源于stack exchange,提问作者Picek
相关产品推荐
相关产品推荐

