调用OpenAI API执行CrewAI Agent时遭遇SSL证书验证错误
MacBook Pro上CrewAI调用OpenAI时SSL证书验证失败问题排查
问题描述
执行以下CrewAI调用OpenAI的代码:
result = crew.kickoff(inputs={"topic": "Artificial Intelligence"}) from IPython.display import Markdown Markdown(result)
运行后抛出错误:
APIConnectionError: Connection error
底层错误栈显示多次SSL证书验证失败:
- --------------------------------------------------------------------------- SSLCertVerificationError Traceback (most recent call last) File /opt/anaconda3/lib/python3.11/site-packages/httpcore/_exceptions.py:10, in map_exceptions(map) 9 try: ---> 10 yield 11 except Exception as exc: # noqa: PIE786 SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006) The above exception was the direct cause of the following exception: ConnectError Traceback (most recent call last) File /opt/anaconda3/lib/python3.11/site-packages/httpx/_transports/default.py:67, in map_httpcore_exceptions() 66 try: ---> 67 yield 68 except Exception as exc: ConnectError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006) The above exception was the direct cause of the following exception: ConnectError Traceback (most recent call last) File /opt/anaconda3/lib/python3.11/site-packages/openai/_base_client.py:952, in SyncAPIClient._request(self, cast_to, options, remaining_retries, stream, stream_cls) 951 try: --> 952 response = self._client.send( 953 request, 954 stream=stream or self._should_stream_response_body(request=request), 955 **kwargs, 956 ) 957 except httpx.TimeoutException as err: File /opt/anaconda3/lib/python3.11/site-packages/httpx/_transports/default.py:84, in map_httpcore_exceptions() 83 message = str(exc) ---> 84 raise mapped_exc(message) from exc ConnectError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006) During handling of the above exception, another exception occurred: SSLCertVerificationError Traceback (most recent call last) File /opt/anaconda3/lib/python3.11/site-packages/httpcore/_exceptions.py:10, in map_exceptions(map) 9 try: ---> 10 yield 11 except Exception as exc: # noqa: PIE786 File /opt/anaconda3/lib/python3.11/ssl.py:1108, in SSLSocket._create(cls, sock, server_side, do_handshake_on_connect, suppress_ragged_eofs, server_hostname, context, session) 1107 raise ValueError("do_handshake_on_connect should not be specified for non-blocking sockets") -> 1108 self.do_handshake() 1109 except (OSError, ValueError): File /opt/anaconda3/lib/python3.11/ssl.py:1383, in SSLSocket.do_handshake(self, block) 1382 self.settimeout(None) -> 1383 self._sslobj.do_handshake() 1384 finally: SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006) The above exception was the direct cause of the following exception: ConnectError Traceback (most recent call last) File /opt/anaconda3/lib/python3.11/site-packages/httpx/_transports/default.py:67, in map_httpcore_exceptions() 66 try: ---> 67 yield 68 except Exception as exc:
问题仅出现在Anaconda的Jupyter Notebook和VSCode本地环境,在线Lightning AI编辑器可正常运行,怀疑是Mac钥匙串证书问题,需排查修复。
修复方法
1. 手动安装Anaconda环境的SSL证书
Mac自带Python与Anaconda Python的证书存储路径不同,执行以下步骤:
- 终端激活目标Anaconda环境:
conda activate your_env_name - 运行certifi证书安装脚本(路径需匹配你的Anaconda和Python版本):
/opt/anaconda3/bin/python3.11 /opt/anaconda3/lib/python3.11/site-packages/certifi/__main__.py
2. 临时禁用SSL验证(应急方案)
仅用于验证问题根源,不推荐长期使用:
修改OpenAI客户端初始化代码,添加verify=False参数:
from openai import OpenAI client = OpenAI( api_key="your_api_key", verify=False )
若使用CrewAI,需确保其调用的OpenAI客户端配置了该参数。
3. 更新Mac钥匙串根证书
- 打开「钥匙串访问」应用,切换到「系统」钥匙串的「证书」分类。
- 检查是否缺失常见根证书(如DigiCert Global Root CA),若缺失,下载官方证书后双击导入到「系统」钥匙串,设置「信任」为「始终信任」。
4. 重置Anaconda SSL配置
- 重置conda ssl验证配置:
conda config --remove-key ssl_verify conda config --add ssl_verify True - 或直接指定certifi证书路径:
conda config --add ssl_verify /opt/anaconda3/lib/python3.11/site-packages/certifi/cacert.pem
5. 检查代理设置
若使用网络代理,可能导致证书验证失败:
- 临时关闭系统代理后测试代码。
- 需使用代理时,配置环境变量:
export HTTP_PROXY=http://your_proxy:port export HTTPS_PROXY=http://your_proxy:port export REQUESTS_CA_BUNDLE=/path/to/proxy/certificate.pem
内容的提问来源于stack exchange,提问作者Sri
相关产品推荐
相关产品推荐

