Rocky Linux下Python3.10导入ssl报错libssl.so.1.1缺失求助
问题:Python 3.10.14 导入 ssl 模块失败
系统中安装了Python 3.12、3.11、3.10三个版本,其中3.12和3.11可正常执行import ssl,但Python 3.10.14执行该操作时抛出如下错误:
[user@computer ~]$ python3.10 Python 3.10.14 (main, Jun 21 2024, 12:39:03) [GCC 11.4.1 20231218 (Red Hat 11.4.1-3)] on linux Type "help", "copyright", "credits" or "license" for more information. >>> import ssl Traceback (most recent call last): File "<stdin>", line 1, in <module> File "/usr/local/lib/python3.10/ssl.py", line 99, in <module> import _ssl # if we can't import it, let the error propagate ImportError: libssl.so.1.1: cannot open shared object file: No such file or directory >>> exit()
安装背景
在Rocky Linux上通过Ansible完成安装:
- OpenSSL、Python 3.11、Python 3.12通过DNF安装,对应Ansible任务:
--- - name: Installing Packages via DNF ansible.builtin.dnf: name: - openssl - python3.11 - python3.11-pip - python3.12 - python3.12-pip state: present ...
- Python 3.10.14为手动编译安装,对应Ansible任务:
--- - name: Create Directory /usr/bin/ ansible.builtin.file: path: /usr/bin/ state: directory - name: Unarchive Python 3.10.14 Tar File into /usr/bin ansible.builtin.unarchive: src: 'https://www.python.org/ftp/python/3.10.14/Python-3.10.14.tar.xz' dest: /usr/bin/ remote_src: yes - name: Configure Python 3.10.14 ansible.builtin.shell: cmd: 'cd /usr/bin/Python-3.10.14/; ./configure --enable-optimizations' - name: Install Python 3.10.14 via Make ansible.builtin.shell: cmd: 'cd /usr/bin/Python-3.10.14/; make -j 2 ; nproc ; make altinstall ;' ...
解决方案
原因分析
Python 3.10编译时默认依赖OpenSSL 1.1版本,但当前Rocky Linux通过DNF安装的OpenSSL为3.x版本(适配Python 3.11+),系统中缺少libssl.so.1.1库,导致编译后的Python 3.10无法找到依赖。
修复步骤
方法1:重新编译Python 3.10并指定OpenSSL 3路径
修改Ansible中编译Python 3.10的configure命令,明确指向系统已安装的OpenSSL 3路径:
- name: Configure Python 3.10.14 with OpenSSL 3 support ansible.builtin.shell: cmd: | cd /usr/bin/Python-3.10.14/ ./configure --enable-optimizations \ --with-openssl=/usr \ --with-openssl-rpath=auto
然后更新编译安装任务:
- name: Reinstall Python 3.10.14 via Make ansible.builtin.shell: cmd: 'cd /usr/bin/Python-3.10.14/; make clean; make -j $(nproc); make altinstall;'
方法2:安装OpenSSL 1.1兼容库
无需重新编译,直接安装OpenSSL 1.1包并创建软链接:
- 安装OpenSSL 1.1:
sudo dnf install openssl11
- 创建软链接让Python 3.10找到库:
sudo ln -s /usr/lib64/libssl.so.1.1 /usr/lib/libssl.so.1.1 sudo ln -s /usr/lib64/libcrypto.so.1.1 /usr/lib/libcrypto.so.1.1
- 永久生效:将路径添加到系统库配置
echo "/usr/lib64/openssl11/" | sudo tee /etc/ld.so.conf.d/openssl11.conf sudo ldconfig
方法3:通过SCL源安装预编译的Python 3.10
替代手动编译,使用Software Collections源安装适配系统环境的Python 3.10:
- name: Enable SCL repository ansible.builtin.dnf: name: centos-release-scl state: present - name: Install Python 3.10 via SCL ansible.builtin.dnf: name: python310 state: present
安装后可通过scl enable python310 bash启用环境,或直接使用python3.10命令。
内容的提问来源于stack exchange,提问作者Daniel Arapi
相关产品推荐
相关产品推荐

