You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用OpenAI API执行CrewAI Agent时遭遇SSL证书验证错误

MacBook Pro上CrewAI调用OpenAI时SSL证书验证失败问题排查

问题描述

执行以下CrewAI调用OpenAI的代码:

result = crew.kickoff(inputs={"topic": "Artificial Intelligence"})

from IPython.display import Markdown
Markdown(result)

运行后抛出错误:

APIConnectionError: Connection error

底层错误栈显示多次SSL证书验证失败:

- ---------------------------------------------------------------------------
SSLCertVerificationError                  
Traceback (most recent call last)
File /opt/anaconda3/lib/python3.11/site-packages/httpcore/_exceptions.py:10, in map_exceptions(map)
      9 try:
---> 10     yield
     11 except Exception as exc:  # noqa: PIE786

SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006)

The above exception was the direct cause of the following exception:

ConnectError                              
Traceback (most recent call last)
File /opt/anaconda3/lib/python3.11/site-packages/httpx/_transports/default.py:67, in map_httpcore_exceptions()
     66 try:
---> 67     yield
     68 except Exception as exc:

ConnectError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006)

The above exception was the direct cause of the following exception:

ConnectError                              
Traceback (most recent call last)
File /opt/anaconda3/lib/python3.11/site-packages/openai/_base_client.py:952, in SyncAPIClient._request(self, cast_to, options, remaining_retries, stream, stream_cls)
    951 try:
--> 952     response = self._client.send(
    953         request,
    954         stream=stream or self._should_stream_response_body(request=request),
    955         **kwargs,
    956     )
    957 except httpx.TimeoutException as err:

File /opt/anaconda3/lib/python3.11/site-packages/httpx/_transports/default.py:84, in map_httpcore_exceptions()
     83 message = str(exc)
---> 84 raise mapped_exc(message) from exc

ConnectError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006)

During handling of the above exception, another exception occurred:

SSLCertVerificationError                  
Traceback (most recent call last)
File /opt/anaconda3/lib/python3.11/site-packages/httpcore/_exceptions.py:10, in map_exceptions(map)
      9 try:
---> 10     yield
     11 except Exception as exc:  # noqa: PIE786

File /opt/anaconda3/lib/python3.11/ssl.py:1108, in SSLSocket._create(cls, sock, server_side, do_handshake_on_connect, suppress_ragged_eofs, server_hostname, context, session)
   1107             raise ValueError("do_handshake_on_connect should not be specified for non-blocking sockets")
-> 1108         self.do_handshake()
   1109 except (OSError, ValueError):

File /opt/anaconda3/lib/python3.11/ssl.py:1383, in SSLSocket.do_handshake(self, block)
   1382         self.settimeout(None)
-> 1383     self._sslobj.do_handshake()
   1384 finally:

SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006)

The above exception was the direct cause of the following exception:

ConnectError                              
Traceback (most recent call last)
File /opt/anaconda3/lib/python3.11/site-packages/httpx/_transports/default.py:67, in map_httpcore_exceptions()
     66 try:
---> 67     yield
     68 except Exception as exc:

问题仅出现在Anaconda的Jupyter Notebook和VSCode本地环境,在线Lightning AI编辑器可正常运行,怀疑是Mac钥匙串证书问题,需排查修复。

修复方法

1. 手动安装Anaconda环境的SSL证书

Mac自带Python与Anaconda Python的证书存储路径不同,执行以下步骤:

  • 终端激活目标Anaconda环境:
    conda activate your_env_name
    
  • 运行certifi证书安装脚本(路径需匹配你的Anaconda和Python版本):
    /opt/anaconda3/bin/python3.11 /opt/anaconda3/lib/python3.11/site-packages/certifi/__main__.py
    

2. 临时禁用SSL验证(应急方案)

仅用于验证问题根源,不推荐长期使用:
修改OpenAI客户端初始化代码,添加verify=False参数:

from openai import OpenAI

client = OpenAI(
    api_key="your_api_key",
    verify=False
)

若使用CrewAI,需确保其调用的OpenAI客户端配置了该参数。

3. 更新Mac钥匙串根证书

  • 打开「钥匙串访问」应用,切换到「系统」钥匙串的「证书」分类。
  • 检查是否缺失常见根证书(如DigiCert Global Root CA),若缺失,下载官方证书后双击导入到「系统」钥匙串,设置「信任」为「始终信任」。

4. 重置Anaconda SSL配置

  • 重置conda ssl验证配置:
    conda config --remove-key ssl_verify
    conda config --add ssl_verify True
    
  • 或直接指定certifi证书路径:
    conda config --add ssl_verify /opt/anaconda3/lib/python3.11/site-packages/certifi/cacert.pem
    

5. 检查代理设置

若使用网络代理,可能导致证书验证失败:

  • 临时关闭系统代理后测试代码。
  • 需使用代理时,配置环境变量:
    export HTTP_PROXY=http://your_proxy:port
    export HTTPS_PROXY=http://your_proxy:port
    export REQUESTS_CA_BUNDLE=/path/to/proxy/certificate.pem
    

内容的提问来源于stack exchange,提问作者Sri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 19:48:09