You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用SAM CLI部署Lambda时遇SSL证书验证失败问题求助

解决Windows 11 VPN环境下SAM CLI部署Lambda的SSL验证失败问题

你遇到的SSL验证错误是因为企业VPN/防火墙的自签名证书未被SAM CLI正确识别,即便设置了EXPORT_CA_BUNDLE也无效——这是因为Windows环境下该变量并非SAM CLI优先读取的配置项,结合你的场景,可尝试以下方案:

1. 替换为Windows兼容的环境变量

Windows下SAM CLI优先识别AWS_CA_BUNDLE或CURL_CA_BUNDLE,而非Linux系统的EXPORT_CA_BUNDLE,执行以下命令设置(替换为你的证书路径):

setx AWS_CA_BUNDLE "C:\path\to\your\enterprise-cert.pem"

设置完成后重启终端,让环境变量生效。

2. 直接配置SAM CLI全局参数

通过SAM CLI内置命令指定CA证书,这种方式更可靠,不会受系统环境变量影响:

sam configure set ca_bundle "C:\path\to\your\enterprise-cert.pem"

3. 确保证书文件格式正确

  • 确认.pem文件包含完整的证书链:将企业根CA证书和中间CA证书合并到同一个文件中,每行分隔,不要有多余空行或格式错误。
  • 可以用curl测试证书有效性:
curl --cacert "C:\path\to\your\enterprise-cert.pem" https://abcdef123456.s3.amazonaws.com/876ed1028a53c46e927f91e930c0b238

如果curl能正常返回内容,说明证书本身没问题。

4. 配置VPN代理(若需要)

企业防火墙通常会强制走代理,需为SAM CLI配置代理参数:

sam configure set http_proxy http://your-proxy-server:port
sam configure set https_proxy https://your-proxy-server:port
# 若代理需要认证
sam configure set proxy_username "your-proxy-username"
sam configure set proxy_password "your-proxy-password"

错误信息参考

Error: Unable to upload artifact ABCDEF_Api referenced by CodeUri parameter of ABCDEF_Api resource.
SSL validation failed for https://abcdef123456.s3.amazonaws.com/876ed1028a53c46e927f91e930c0b238 [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)

内容的提问来源于stack exchange,提问作者Tom Baxter

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 02:40:00