You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure App Service中OpenAI Python SDK SSL证书验证失败求助

Azure App Service中OpenAI Python SDK的SSL证书验证问题

问题场景与错误信息

在Azure App Service(Linux环境)的FastAPI应用启动阶段,使用OpenAI Python SDK连接部署了公司自签名证书的API网关时,触发SSL证书验证失败错误:

File "/opt/python/3.11.8/lib/python3.11/ssl.py", line 979, in do_handshake
self._sslobj.do_handshake()
ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get issuer certificate (_ssl.c:1006)

已执行的排查与尝试

1. 自定义证书捆绑包代码

尝试通过代码将自签名证书合并到自定义CA捆绑包,但未生效:

def trust_certificate(cert_path, def_rel_path="app/tmp"):
    #this did not work since custom_ca_bundle is in read_only filesystem. Let's create a file in local
    custom_ca_bundle = certifi.where()
    try:
        with open(custom_ca_bundle, 'ab') as f:
            with open(cert_path, 'rb') as cert:
                f.write(cert.read())
        os.environ["REQUESTS_CA_BUNDLE"] = custom_ca_bundle
        return custom_ca_bundle
    except OSError:
        #if cannot open existing certs for write, create aonother cert file
        local_ca_bundle = os.path.abspath(def_rel_path+"/local_cert.pem")
        # Get the directory path from the filename
        directory = os.path.dirname(local_ca_bundle)
        # Create the directory structure if it doesn't exist
        os.makedirs(directory, exist_ok=True)
        with open(local_ca_bundle, 'wb') as local_cert:
            #this will be our new bundle
            with open(custom_ca_bundle, 'rb') as python_cert:
                #these probably could not have been opened before
                with open(cert_path, 'rb') as cert:
                    #and this is our cert
                    #now all of them go to the new file
                    local_cert.write(python_cert.read())
                    local_cert.write(cert.read())
                    os.environ["REQUESTS_CA_BUNDLE"] = local_ca_bundle
                    os.environ["SSL_CERT_FILE"] = local_ca_bundle
                    os.environ['SSL_CERT_DIR'] = directory
                    return local_ca_bundle

2. Azure门户添加证书验证

通过Azure门户将证书添加到App Service后,使用命令openssl s_client -connect <hostname>:443验证返回0(成功),但应用依然无法正常连接。

3. 证书路径检查

添加代码检查Python及OpenSSL使用的证书路径,输出如下:

vp["pyssl_capath"] = openssl_obj.capath
vp["pyssl_openssl_capath"] = openssl_obj.openssl_capath
vp["pyssl_openssl_capath_env"] = openssl_obj.openssl_capath_env
vp["certifi"] = certifi.where()
arg0 = ["openssl", "version", "-d"]
ssl_cat_obj = subprocess.run(arg0,stdout=subprocess.PIPE, stderr=subprocess.PIPE)
openssl_path = ssl_cat_obj.stdout.decode('utf-8').split("\"")[1]+"/certs"
vp["openssl"] = openssl_path
print(vp)
> {'pyssl_capath': '/tmp/8dca2683adac9c1/app/tmp', 'pyssl_openssl_capath': '/usr/lib/ssl/certs', 'pyssl_openssl_capath_env': 'SSL_CERT_DIR', 'certifi': '/agents/python/certifi/cacert.pem', 'openssl': '/usr/lib/ssl/certs'}

openssl s_client使用的证书路径与Pythonssl.get_default_verify_paths()输出路径一致,但问题仍未解决。

4. subprocess调用openssl测试

通过Python的subprocess调用openssl s_client测试连接,代码如下:

# try to connect with default certificates
arg1 = ["openssl", "s_client", "-connect", f"{host}:443"]
ssl_try_def = subprocess.run(arg1,stdout=subprocess.PIPE, stderr=subprocess.PIPE)
# Adding path to folder containing my self-signed cert by hand
arg2 = ["openssl", "s_client", "-CApath", path, "-connect", f"{host}:443"]
ssl_try_path = subprocess.run(arg2,stdout=subprocess.PIPE, stderr=subprocess.PIPE)

两个调用的stderr返回相同内容:

stderr: b'139809254405440:error:0200206F:system library:connect:Connection refused:../crypto/bio/b_sock2.c:110:\n139809254405440:error:2008A067:BIO routines:BIO_connect:connect error:../crypto/bio/b_sock2.c:111:\n139809254405440:error:02002063:system library:connect:Cannot assign requested address:../crypto/bio/b_sock2.c:110:\n139809254405440:error:2008A067:BIO routines:BIO_connect:connect error:../crypto/bio/b_sock2.c:111:\nconnect:errno=99\n'

补充说明

  • 由于SDK内部调用无法修改,无法采用部分Stack Overflow解决方案
  • 本人主要从事数据科学工作,对SSL领域不熟悉,找不到错误码errno=99的相关参考信息

内容的提问来源于stack exchange,提问作者Picek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 01:42:04