使用SAM CLI部署Lambda时遇SSL证书验证失败问题求助
解决Windows 11 VPN环境下SAM CLI部署Lambda的SSL验证失败问题
你遇到的SSL验证错误是因为企业VPN/防火墙的自签名证书未被SAM CLI正确识别,即便设置了EXPORT_CA_BUNDLE也无效——这是因为Windows环境下该变量并非SAM CLI优先读取的配置项,结合你的场景,可尝试以下方案:
1. 替换为Windows兼容的环境变量
Windows下SAM CLI优先识别AWS_CA_BUNDLE或CURL_CA_BUNDLE,而非Linux系统的EXPORT_CA_BUNDLE,执行以下命令设置(替换为你的证书路径):
setx AWS_CA_BUNDLE "C:\path\to\your\enterprise-cert.pem"
设置完成后重启终端,让环境变量生效。
2. 直接配置SAM CLI全局参数
通过SAM CLI内置命令指定CA证书,这种方式更可靠,不会受系统环境变量影响:
sam configure set ca_bundle "C:\path\to\your\enterprise-cert.pem"
3. 确保证书文件格式正确
- 确认.pem文件包含完整的证书链:将企业根CA证书和中间CA证书合并到同一个文件中,每行分隔,不要有多余空行或格式错误。
- 可以用curl测试证书有效性:
curl --cacert "C:\path\to\your\enterprise-cert.pem" https://abcdef123456.s3.amazonaws.com/876ed1028a53c46e927f91e930c0b238
如果curl能正常返回内容,说明证书本身没问题。
4. 配置VPN代理(若需要)
企业防火墙通常会强制走代理,需为SAM CLI配置代理参数:
sam configure set http_proxy http://your-proxy-server:port sam configure set https_proxy https://your-proxy-server:port # 若代理需要认证 sam configure set proxy_username "your-proxy-username" sam configure set proxy_password "your-proxy-password"
错误信息参考
Error: Unable to upload artifact ABCDEF_Api referenced by CodeUri parameter of ABCDEF_Api resource.
SSL validation failed for https://abcdef123456.s3.amazonaws.com/876ed1028a53c46e927f91e930c0b238 [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)
内容的提问来源于stack exchange,提问作者Tom Baxter
相关产品推荐
相关产品推荐

