为何不同版本certifi的cacert.pem有效期相同?2028年后会自动更新吗?
关于certifi模块cacert.pem有效期的疑问与解答
疑问1:为何不同版本的certifi,其cacert.pem的有效期完全相同?
你观察到certifi 2018.4.16和2024.2.2版本的cacert.pem显示的有效期一致,核心原因是:
- certifi的cacert.pem是Mozilla根证书bundle的副本,这个文件包含多个根证书的集合。
- 你使用的
openssl x509 -enddate命令默认只会读取并显示文件中第一个证书的有效期。两个版本的bundle里,排在首位的恰好是同一张有效期到2028年1月28日的根证书,所以输出结果一致。 - 不同版本的certifi更新的是bundle内的证书列表(比如新增可信根证书、移除过期/不合规的证书),并非替换所有证书,因此首位证书未变时,单条命令的输出就会相同。
可以通过以下命令验证bundle内所有证书的有效期差异:
# 将cacert.pem拆分单个证书文件 awk 'BEGIN {c=0;} /BEGIN CERTIFICATE/ {c++} {print > "cert" c ".pem"}' < /usr/local/lib/python3.3/site-packages/certifi/cacert.pem # 遍历所有拆分后的证书,查看各自有效期 for cert in cert*.pem; do echo "--- $cert ---"; openssl x509 -enddate -noout -in $cert; done
你提供的两个版本验证结果:
certifi 2018.4.16版本信息及验证结果
[root@8a63ff0c0dba /]# python3.3 -m pip show certifi Name: certifi Version: 2018.4.16 Summary: Python package for providing Mozillas CA Bundle. Home-page: http://certifi.io/ Author: Kenneth Reitz Author-email: me@kennethreitz.com License: MPL-2.0 Location: /usr/local/lib/python3.3/site-packages Requires: Required-by: requests [root@8a63ff0c0dba /]# openssl x509 -enddate -noout -in /usr/local/lib/python3.3/site-packages/certifi/cacert.pem notAfter=Jan 28 12:00:00 2028 GMT
certifi 2024.2.2版本信息及验证结果
[root@1e6dfr05dhd /]# python3.11 -m pip show certifi Name: certifi Version: 2024.2.2 Summary: Python package for providing Mozillas CA Bundle. Home-page: https://github.com/certifi/python-certifi Author: Kenneth Reitz Author-email: me@kennethreitz.com License: MPL-2.0 Location: /usr/local/lib/python3.11/site-packages Requires: Required-by: requests [root@1e6dfr05dhd /]# openssl x509 -enddate -noout -in /usr/local/lib/python3.11/site-packages/certifi/cacert.pem notAfter=Jan 28 12:00:00 2028 GMT
疑问2:2028年1月28日之后,cacert.pem的有效期会自动更新吗?
不会自动更新。certifi是静态的Python包,安装到本地后,cacert.pem文件就固定下来了。要获取更新后的根证书bundle,你需要手动执行升级命令更新certifi到最新版本:
pip install --upgrade certifi
新版本的certifi会同步Mozilla最新的根证书集合,替换掉过期证书,确保你的证书bundle始终包含有效的可信根证书。
内容的提问来源于stack exchange,提问作者Kavin Kumar
相关产品推荐
相关产品推荐

